How do I scan a Storage Pool with CLAMAV?

vitorsantoz

Cadet
Joined
Feb 18, 2020
Messages
6
Hi Everyone,
I am using Clamav on FreeNAS and i have a question that i never see anybody responding on internet...
Currently on my work we have a pool named arq01 - Is a windows filesystem.
Also we have a Clamav installed on a jail called clamav.
Basically i need a help with a script that makes Clamav see this arq01 to scan windows files.
Please help me!
 
Joined
Jul 3, 2015
Messages
926
 

vitorsantoz

Cadet
Joined
Feb 18, 2020
Messages
6

Thanks Johnny, but this post does'nt explain exatcly how we do to scan file pools =(
 

sretalla

Powered by Neutrality
Moderator
Joined
Jan 1, 2016
Messages
9,703

sretalla

Powered by Neutrality
Moderator
Joined
Jan 1, 2016
Messages
9,703

vitorsantoz

Cadet
Joined
Feb 18, 2020
Messages
6

RLe

Cadet
Joined
Apr 3, 2020
Messages
2
I can't find the answer, but where do we store the script? Completely clueless as of now.

Somewhere in a self chosen directory of FreeNAS or is it automatically installed via the CLAMAV FreeNAS Plugin? Is it just than a matter of updating the install base of the jail?
 

sretalla

Powered by Neutrality
Moderator
Joined
Jan 1, 2016
Messages
9,703
Somewhere in a self chosen directory of FreeNAS or is it automatically installed via the CLAMAV FreeNAS Plugin? Is it just than a matter of updating the install base of the jail?
Create the script file in the jail since it needs to run there. It's not part of the jail/plugin, so you need to do it yourself if you want to use it. You can just run clamscan if you don't want the script (it's already in the jail).
 

vitorsantoz

Cadet
Joined
Feb 18, 2020
Messages
6
I can't find the answer, but where do we store the script? Completely clueless as of now.

Somewhere in a self chosen directory of FreeNAS or is it automatically installed via the CLAMAV FreeNAS Plugin? Is it just than a matter of updating the install base of the jail?
Inside the jail you store a file ".sh" input your command to scan locations and install a cron job to perform this scan.
 

anodos

Sambassador
iXsystems
Joined
Mar 6, 2014
Messages
9,554
You may want to verify that clamav scans extended attributes. A quick grep through the source doesn't indicate any calls to extattr_list_file(2) and so I assume it probably does not. In this case a malicious actor can simply bypass your AV scanner by writing into a payload into an alternate data stream (although modern Windows clients don't allow executing from an ADS IIRC).
 

D4R4

Cadet
Joined
Aug 21, 2023
Messages
1
I have to ask... What happens if I simply install the ClamAV package directly on the TrueNAS (FreeBSD?) OS and set it up manually like any other box? Is it even possible? What are the downsides?
 

anodos

Sambassador
iXsystems
Joined
Mar 6, 2014
Messages
9,554
I have to ask... What happens if I simply install the ClamAV package directly on the TrueNAS (FreeBSD?) OS and set it up manually like any other box? Is it even possible? What are the downsides?
Not supported. Will possibly break base install if you try to force it.
 

sretalla

Powered by Neutrality
Moderator
Joined
Jan 1, 2016
Messages
9,703
And will disappear on the next appliance upgrade.
 
Top