store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Tue May 21, 2013 4:37 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: proftpd + clamav
Unread postPosted: Sun Jun 05, 2011 6:42 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
I was sending a file using ftp from one box to another. The file is a tar.gz. Size is 836kb. Yes kilobytes !

The ftp sending is stuck for nearly 20 minutes and clamav uses 1 core at 100% all that time.
Any idea why this happens ?
I was watching lately clamav work like crazy but I just found out why !

32582 root 20 0 425m 287m 6704 S 101.2 7.3 20:02.47 clamd

I finally had to kill manually the clamav proccess.

Any ideas ?

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: proftpd + clamav
Unread postPosted: Mon Jun 20, 2011 9:52 am 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
I keep having a great issue even after the update of the clamav a few days ago.

It takes forever to upload a small file through the ftp somethimes.
Example i am trying to send through ftp a 2mbyte .bz2 mysqldump from somewhere else and it gets stuck forever !!!

Generally clamav keeps being a p**n in the **s.

Could we disable the freshclam cron and everything from being scanned through clamav and once in a while manually run it to scan files stored in the hdd ???

Regards

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: proftpd + clamav
Unread postPosted: Mon Jun 20, 2011 12:37 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
I suspect there may be more to it than this.

We regularly upload video files that are 100Mb+ with no problems at all.

Obviously, a tar.gz would need to be unpacked twice before it could be scanned, which would not be the case for a video file.

ALSO, I expect there's a setting somewhere that says don't scan files that are more than X Mb in size, so maybe they aren't getting scanned at all.

But I really don't think a 2Mb ta.rgz file should tax Clamd at all.

Have you tried disabling the Google Safe Browsing rules, in case the increased memory overhead these add to clamd might be a possible cause? Obviously this is not ideal, but it is better than switching it off completely I suppose.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: proftpd + clamav
Unread postPosted: Mon Jun 20, 2011 5:36 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
faris wrote:
I suspect there may be more to it than this.

We regularly upload video files that are 100Mb+ with no problems at all.

Obviously, a tar.gz would need to be unpacked twice before it could be scanned, which would not be the case for a video file.

ALSO, I expect there's a setting somewhere that says don't scan files that are more than X Mb in size, so maybe they aren't getting scanned at all.

But I really don't think a 2Mb ta.rgz file should tax Clamd at all.

Have you tried disabling the Google Safe Browsing rules, in case the increased memory overhead these add to clamd might be a possible cause? Obviously this is not ideal, but it is better than switching it off completely I suppose.


Nope thats not the thing. If I send a 40-50 mbyte tar.gz with normal files it passes through very fast.
But some files such as zipped databses make clamd consume the whole cpu for a heck of a long time !!!!

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: proftpd + clamav
Unread postPosted: Mon Jun 20, 2011 5:41 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
What do you see with clamdtop?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Bing [Bot], copernic2006, Google [Bot] and 5 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group