[sanesecurity] Re: Signature download script with "backup" feature?

  • From: Dave Funk <dbfunk@xxxxxxxxxxxxxxxxxxxxx>
  • To: sanesecurity@xxxxxxxxxxxxx
  • Date: Sat, 13 Nov 2010 21:44:07 -0600 (CST)

On Sun, 14 Nov 2010, Wolfgang Zeikat wrote:

We are using several 3rd party signatures for clamav with self-written download scripts.

Today, we are, for the second time within few weeks, having problems with mbl.db: LibClamAV Error: cli_bm_addpatt: Signature for MBL_14252.UNOFFICIAL is too short
LibClamAV Error: cli_parse_add(): Problem adding signature (4).
LibClamAV Error: Problem parsing database at line 521
LibClamAV Error: Can't load /var/clamav/mbl.db: Malformed database
ERROR: Malformed database

Last time, this stopped after less than 24 hours IIRC, nevertheless it is annoying.

So, I would like to use a download script that keeps a backup of the last working copy of all signature files and restores it in case of such problems.

Is there a working community script available that already does that? If so, I would prefer that instead of writing such backup feature for our current scripts.

Thanks and best regards,

wolfgang

Basic concept; download the new sigs to a temporary directory, do a test
load on them with the clamav tools, if pass, move them into the production
dir. (or verify the downloads with GPG, etc).

There are already excellent download scripts written, go to Steve's web site and look at the scripts written by Bill or Gerard.
http://sanesecurity.co.uk/download_scripts_linux.htm




--
Dave Funk                                  University of Iowa
<dbfunk (at) engineering.uiowa.edu>        College of Engineering
319/335-5751   FAX: 319/384-0549           1256 Seamans Center
Sys_admin/Postmaster/cell_admin            Iowa City, IA 52242-1527
#include <std_disclaimer.h>
Better is not better, 'standard' is better. B{

Other related posts: