|
![]() | 作者: cimsxiyang [cimsxiyang]
![]() |
登录 |
postfix 邮件 病毒过滤 综述: 世面上关于邮件病毒的软件很多,其中以perl的居多。我之所以选择amavis和clamav是因为这些都是c写,首先在性能上就具备了优势。同时,amavis具有很好的扩展性。可以把他理解为一个扫描框架,clamav是一个扫描引擎。当然,也可以使用其他扫描引擎。:) 软件准备: amavis-0.3.12.tar.gz unarj-2.65-3.9.i386.rpm zoo-2.10-11.9.i386.rpm unrar-3.2.3-2.9.i386.rpm clamav-0.65.tar.gz arc-5.21e-6.i386.rpm 软件安装: --------install clamav--------- 代码: LogFile /var/log/clamd.log LogFileMaxSize 2M LogVerbose LogTime PidFile /var/run/clamd.pid DataDirectory /usr/local/share/clamav LocalSocket /tmp/clamd MaxDirectoryRecursion 15 User clamav ScanArchive ArchiveMaxFileSize 10M ArchiveMaxRecursion 5 ArchiveMaxFiles 1000 代码: 代码: #!/bin/bash freshclam --quiet -d -c 2 -l /var/log/clam-update.log 代码: --------------------Install amavisd------------------ 代码: $mailfrom_notify_admin ='xiyang@yovole.com' $mailfrom_notify_recip = 'xiyang@yovole.com'; $mailfrom_notify_spamadmin = 'xiyang@yovole.com'; $virus_admin = 'xiyang@yovole.com'; $spam_admin = 'xiyang@yovole.com'; $final_virus_destiny = 0; $final_spam_destiny = -1; $sa_tag_level_deflt = 4; $sa_kill_level_deflt = 6.9; ------------------edit the postfix config files------------- * add to /etc/postfix/main.cf: content_filter = vscan: soft_bounce = yes # For testing purposes it might make sense to use this * add to /etc/postfix/master.cf: vscan unix - n n - 10 pipe user=amavis argv=/usr/sbin/amavis ${sender} ${recipient} localhost:10025 inet n - n - - smtpd -o content_filter= * reload postfix #/etc/init.d/postfix reload ------------test the app----------------------- 代码: -------------------------------------- Scan started: Sun Dec 28 14:48:29 2003 -- summary -- Known viruses: 11964 Scanned directories: 1049 Scanned files: 1657 Infected files: 0 Data scanned: 102.24 MB I/O buffer size: 131072 bytes Time: 33.310 sec (0 m 33 s) -------------------------------------- Scan started: Sun Dec 28 14:52:13 2003 /var/vmail//root/new/1030594139.21504_0.yovole.com,S=165330: Exploit.IFrame.Gen FOUND ...................... 代码: ------------------------------ 作者:xiyang@sharesec.com 欢迎大家交流。并指正错误。 [此贴被 XiYang(cimsxiyang) 在 07月22日09时40分 编辑过] |
地主 发表时间: 03-12-29 13:45 |
![]() | 回复: Garu [syshunter] ![]() |
登录 |
8错,好东西 |
B1层 发表时间: 04-01-05 10:36 |
|
20CN网络安全小组版权所有
Copyright © 2000-2010 20CN Security Group. All Rights Reserved.
论坛程序编写:NetDemon
粤ICP备05087286号