[Avcheck] AvpUpdate.pl and checking the downloaded files

Ralf Hildebrandt Ralf.Hildebrandt@charite.de
Wed, 23 Jan 2002 19:45:06 +0100


On Wed, Jan 23, 2002 at 09:32:37PM +0300, Michael Tokarev wrote:

> > a) Linking the AvpUnix.key doesn't work -- bad code?
> > b) AvpUnix.ini needs to be changed, due to the fact that the real
> >    AvpUnix.ini works only for the chroot jail!
> 
> It is better to have additional ini file specially for non-chrooted
> version.  It may point to the same key file as used by chrooted
> daemon, using KeyPath (if memory serves me right) statement.

I use another .ini file. OK, I can change the path.

> As I pointed several times already, avp treats all errors as success.

:)

> What will be wrong from kav's point of view if you delete one virusbase
> file?  Well, this depends on a file you deleted -- if you'll delete
> the main file, perhaps it is an error, but not necessary for other
> files, especially for "addons".  Ah, yes, them all listed in one
> of it's files too -- ...let me check... avp.klb and avp.set, but
> I don't know how those files handled by avp.

OK, maybe I should check with a corrupted file :) instead of a missing
one!

>  1 download all updates to a separate directory.  Abort on any error
>  2 execute kavscanner or kavdaemon with those updated bases, giving
>    it a file with known virus to check.  Both should return known
>    exit code.  If something goes wrong, abort.

Good idea. I use an EICAR file! Exit code must be what? OK, I can check.

>    scanner/daemon should be executed as a separate user in this
>    case, to avoid possible further damage.
>  3 rename current working bases to `old' directory (erasing it's
>    content if `old' already exists)
>  4 rename new bases directory to be current
>  5 reload (or restart) running daemon

OK.

-- 
Ralf Hildebrandt (Im Auftrag des Referat V A)   Ralf.Hildebrandt@charite.de
Charite Campus Virchow-Klinikum                 Tel.  +49 (0)30-450 570-155
Referat V A - Kommunikationsnetze -             Fax.  +49 (0)30-450 570-916
Most people use Windows. Is this a reason to run Windows?
Flies love shit. A million flies can't be wrong, can they?