I wrote a script for Cpanel + Pure FTP + Clamav installed servers.
Anti-Gumblar Protection Documentation
I wrote a script for Cpanel + Pure FTP + Clamav installed servers.
Anti-Gumblar Protection Documentation
Looks nice, but does clamscan really do any good detecting javascript/iframe inserts? Probably not. They can change by the minute. I'm even doubtful that clamscan is very good at catching rogue php shellcode pages.
I'd be interested in hearing what others think about clamAV's abilities to discover these things.
Mike
I'm using over 1 week and no negative point about clamav. Catched every infection...
Does it catch up .cgi scripts (dark mailer etc.), who are a able to send out spam?
System scanning all files while upload.
Pls send me sample files. I cant test and write here..
hidonet@gmail.com
Last edited by hidonet; 08-08-2009 at 07:40 AM.
Doesn't this solution cause the server to have a high load and is there a chance normal ftp uploads will fail/corrupt?
Thanks
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlablog.nl - Nederlands Weblog Over Joomla!
A little bit slows down ftp uploads. Waits 1 or 2 second after all uploaded files.
I have ~500 sites in one server and there is no complaint from customers.
http://www.oxio.net/anti_gumblar/ftp_clamscan.phps
Script is much more clever.
1 ) Moves infected file to the quarantine directory
2 ) If antivirus answers as NOT INFECTED for file, scans it with word scanner and scans file for gumblar like addresses ( .cn:808x/tx.cgi... etc.). Yo can add your patterns.
3 ) Changes account's password with random password
4 ) Sends you a mail about all that actions and new password
5 ) Blocks Attacker ip with firewall ( CSF, APF etc )
6 ) Kills live FTP connection of attacker
![]()
Anyone using this Gumblar Script beside the maker ? Please give us a review here.
It's me ...... It's me ......
What is this mean ?Code:$GLOBALS["whmhash"] ="511e....2c"; // whm remote access key for root user
Can I install this script under /usr folder not /root folder ? I know that some configuration on ftp_clamscan.php has to be change to /usr. But is there any downside not using root folder ?
It's me ...... It's me ......
Tried on 64-bit OS, not working.
Well working fine on my cPanel 11.24.5-R37946 - WHM 11.24.2 - X 3.9, CENTOS 5.3 x86_64 standard as far as catching the attack, it quarantines the files and sends the mail, but no other actions, does not log IP, IP blocking, password change is not working.
I am running it at a different location than /root and edited the script a bit to save log at /var/log/ftp_clamscan.log
This script need PHP function shell_exec to be enabled.
Though I must say its a good job and can be made better.
Vinayak Sharma
Vinsar.Net - Quality WebHosting Services at Economical Price USA & UK Servers
Book Your Domain with Confidence Reliable Domain Reseller Account