store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 11:54 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 37 posts ]  Go to page Previous  1, 2, 3  Next
Author Message
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Fri Oct 14, 2011 12:06 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
Make sure you are running 3.0.13 from the stable channel, not from testing and that you ran the full upgrade procedure.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Fri Oct 14, 2011 6:55 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Mar 10, 2008 9:12 pm
Posts: 475
Location: Southampton, UK
Ugh?

I tried to disable the rule last night, and no it didn't work. Still broke, or at least it is on my install.

_________________
Matt

"Given that God is infinite, and that the universe is also infinite... would you like a toasted teacake?"

about.me/mattauckland
twitter.com/mattauckland


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Sat Oct 15, 2011 1:18 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
How did you upgrade?

And what does your /etc/asl/rules file look like?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Mon Oct 17, 2011 8:44 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
The rule manager in 3.0.13 is still not working for us either.

/etc/asl/rules looks like this:

Code:
60118,no,7


This was set up according to http://www.atomicorp.com/company/blogs/ ... -more.html when ASL 2.2.11 was released.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Mon Oct 17, 2011 9:07 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
you're not allowed to ask questions about that file breun. :P


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Mon Oct 17, 2011 9:08 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
Did you change that manually, or thru the GUI? If the former, keep in mind thats not supported (and thats an interim system, so dont change or use that file it will be going away!)

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Mon Oct 17, 2011 9:20 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
That entry was added manually as explained in your blog post: http://www.atomicorp.com/company/blogs/ ... -more.html

I have removed this entry and changed the owner of /etc/asl/rules to tortix (was root), which is probably why previous changes couldn't be persisted.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Mon Oct 17, 2011 12:02 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Mar 10, 2008 9:12 pm
Posts: 475
Location: Southampton, UK
I made my change via the web GUI, and it is the virus alert rule which I think (off the top of my head) is 52502. I'm just trying to prevent it from emailing me, because at the moment every time a spam email with a virus attached to it comes in for any domain on the server, I get an hourly email to tell me. And as you can imagine, that's a lot of emails.

_________________
Matt

"Given that God is infinite, and that the universe is also infinite... would you like a toasted teacake?"

about.me/mattauckland
twitter.com/mattauckland


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Mon Oct 17, 2011 12:50 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 704
Location: Sweden
My row in /etc/asl/rules for this rule is: G,hids,52502,no,8,yes,yes, and I don't get any mails...


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Mon Oct 17, 2011 1:38 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
I just added in two new rules, 590000 and 590001 that makes qmail-scanner and clapf virus alerts level 0. So out of the box if qmail generates a message like this:

Oct 17 13:36:54 asl-modsec-test clamd[3841]: /var/spool/qscan/tmp/eicar.com: Eicar-Test-Signature FOUND

Or clapf generates a message like this:

Oct 17 13:36:54 asl-modsec-test clamd[3841]: /var/spool/clapf/tmp/eicar.com: Eicar-Test-Signature FOUND

You will never see that in the GUI, or in an email alert. But if clamd catches a virus somewhere else, you will see that alert.

If you want to get the alerts for email, just change the alert level on rule 590000 or 590001 depending on which one you use.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Mon Oct 17, 2011 5:54 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Mar 10, 2008 9:12 pm
Posts: 475
Location: Southampton, UK
Thanks Mike, I'll run an update and see if that clams things down on the email front.

Thanks biggles, I'll give that a go. I am surprised it isn't working in the web GUI like it should though.

_________________
Matt

"Given that God is infinite, and that the universe is also infinite... would you like a toasted teacake?"

about.me/mattauckland
twitter.com/mattauckland


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Mon Oct 17, 2011 8:02 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
And please let us know if ASL is reporting something you think it shouldnt by default. We're very happy to add rules to suppress those kinds of things by default.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Mon Oct 17, 2011 9:18 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1843
It is a shame osssec can't differentiate between a virus found in an email (common, harmless, dealt with, don't want to know about it) and a virus uploaded via FTP (might be an indication of compromised ftp credentials - need to know about it - level 14 at least!)

Or can it?

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Tue Oct 18, 2011 5:33 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
mikeshinn wrote:
We're very happy to add rules to suppress those kinds of things by default.


Bearing in mind the reply from faris (about ftp uploads). I cannot see why anyone would need to know that e-mail spam/virus has been blocked by default? Having said that, ASL is transparent in operation and passes this through to the GUI for end users to decide/disable, but this is definitely one rule I would never want to trigger e-mail notification.


Top
 Profile  
 
 Post subject: Re: Virus Detected Alerts
Unread postPosted: Tue Oct 18, 2011 8:00 am 
Offline
Forum Regular
Forum Regular

Joined: Mon Mar 10, 2008 9:12 pm
Posts: 475
Location: Southampton, UK
faris wrote:
It is a shame osssec can't differentiate between a virus found in an email (common, harmless, dealt with, don't want to know about it) and a virus uploaded via FTP (might be an indication of compromised ftp credentials - need to know about it - level 14 at least!)

Or can it?


Yes I agree faris, it is a shame. I'm concerned about turning off email notification on that rule, if it means not being told about FTP virus alerts.

It is very strange though, because in the pre-version 3 of ASL you didn't, or at least I didn't, get notifications on email viruses.

_________________
Matt

"Given that God is infinite, and that the universe is also infinite... would you like a toasted teacake?"

about.me/mattauckland
twitter.com/mattauckland


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 37 posts ]  Go to page Previous  1, 2, 3  Next

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group