Installation Sophos Virenscanner auf Friedolins Linux Servern Überprüfen der Voraussetzungen Alle Aktionen erfolgen als User root! Für die Installation sind folgende Pakete notwendig: nfs utils und Samba Test ob nfs utils in der aktuellen Version installiert ist [chefnutzer]# rpm -qa grep nfs nfs-utils-1.0.9-35z.el5_2 nfs-utils-lib-1.0.8-7.2.z2 Falls nicht (nfs utils devel fehlt), install bzw. update [chefnutzer]# yum install nfs-utils* Loading "kernel-module" plugin sl-security 100% ========================= 1.9 kb 00:00 primary.sqlite.bz2 100% ========================= 2.4 MB 00:01 sl-base 100% ========================= 1.1 kb 00:00 Setting up Install Process Parsing package install arguments Package nfs-utils-lib - 1.0.8-7.2.z2.i386 is already installed. Package nfs-utils - 1:1.0.9-35z.el5_2.i386 is already installed. Resolving Dependencies -- Running transaction check --- Package nfs-utils-lib-devel.i386 0:1.0.8-7.6.el5 set to be updated -- Processing Dependency: pkgconfig for package: nfs-utils-lib-devel --- Package nfs-utils-lib.i386 0:1.0.8-7.6.el5 set to be updated --- Package nfs-utils.i386 1:1.0.9-42.el5 set to be updated -- Running transaction check --- Package pkgconfig.i386 1:0.21-2.el5 set to be updated -- Finished Dependency Resolution Beginning Kernel Module Plugin Finished Kernel Module Plugin Dependencies Resolved Package Arch Version Repository Size Installing: nfs-utils-lib-devel i386 1.0.8-7.6.el5 sl-security 57 k Updating: nfs-utils i386 1:1.0.9-42.el5 sl-security 381 k nfs-utils-lib i386 1.0.8-7.6.el5 sl-security 55 k Installing for dependencies: pkgconfig i386 1:0.21-2.el5 sl-base 58 k Transaction Summary Install 2 Package(s) Update 2 Package(s) Remove 0 Package(s) Total download size: 552 k Is this ok [y/n]: y Downloading Packages: (1/4): nfs-utils-lib-1.0. 100% ========================= 55 kb 00:00 (2/4): nfs-utils-1.0.9-42 100% ========================= 381 kb 00:01 (3/4): nfs-utils-lib-deve 100% ========================= 57 kb 00:00 (4/4): pkgconfig-0.21-2.e 100% ========================= 58 kb 00:00 Running rpm_check_debug Running Transaction Test Finished Transaction Test Transaction Test Succeeded Running Transaction Updating : nfs-utils-lib ######################### [1/6] Installing: pkgconfig ######################### [2/6] Installing: nfs-utils-lib-devel ######################### [3/6] Updating : nfs-utils ######################### [4/6] Cleanup : nfs-utils ######################### [5/6] Cleanup : nfs-utils-lib ######################### [6/6] Installed: nfs-utils-lib-devel.i386 0:1.0.8-7.6.el5 Dependency Installed: pkgconfig.i386 1:0.21-2.el5 Updated: nfs-utils.i386 1:1.0.9-42.el5 nfs-utils-lib.i386 0:1.0.8-7.6.el5 Complete!
Test ob Samba installiert ist rpm -qa grep samba Falls nicht (Ausgabe weicht ggf. je nach bereits installierten Packages ab): yum install samba-* Loaded plugins: kernel-module Setting up Install Process Package samba-common-3.0.33-3.29.el5_6.2.i386 already installed and latest version Package samba-3.0.33-3.29.el5_6.2.i386 already installed and latest version Resolving Dependencies -- Running transaction check --- Package samba-client.i386 0:3.0.33-3.29.el5_6.2 set to be updated --- Package samba-swat.i386 0:3.0.33-3.29.el5_6.2 set to be updated -- Finished Dependency Resolution Beginning Kernel Module Plugin Finished Kernel Module Plugin Dependencies Resolved ============================================================================ == Package Arch Version Repository Size ============================================================================ == Installing: samba-client i386 3.0.33-3.29.el5 6.2 sl-security 5.7 M samba-swat i386 3.0.33-3.29.el5 6.2 sl-security 8.2 M Transaction Summary ============================================================================ == Install 2 Package(s) Update 0 Package(s) Remove 0 Package(s) Total download size: 14 M Is this ok [y/n]: y Downloading Packages: (1/2): samba-client-3.0.33-3.29.el5_6.2.i386.rpm 5.7 MB 00:01 (2/2): samba-swat-3.0.33-3.29.el5_6.2.i386.rpm 8.2 MB 00:00 --------------------------------------------------------------------------------------------------------------------------------------------------------- ------------------------------------------------------------------------------- Total 4.5 MB/s 14 MB 00:03 Running rpm_check_debug Running Transaction Test Finished Transaction Test Transaction Test Succeeded Running Transaction Installing : samba-client 1/2 Installing : samba-swat 2/2 Installed: samba-client.i386 0:3.0.33-3.29.el5_6.2 samba-swat.i386 0:3.0.33-3.29.el5_6.2 Complete! Mount der Installationsbasis [chefnutzer]# mount -t cifs //sophie.ads.uni-jena.de/sophosupdate/ /mnt -vs -o username=<urz-loginkennzeichen mount.cifs kernel mount options: unc=//sophie.ads.uni-jena.de\sophosupdate,ip=141.35.3.15,ver=1,rw,username=urz-login,pass=******** [chefnutzer]# cd /mnt/cids/s000/savlinux/ [chefnutzer savlinux]#
Installation Ausführen des Scriptes install.sh [chefnutzer savlinux]#./install.sh --acceptlicence Sophos Anti-Virus ================= Copyright (c) 1989-2011 Sophos Group. All rights reserved. Welcome to the Sophos Anti-Virus installer. Sophos Anti-Virus contains an on-access scanner, an on-demand command-line scanner, the Sophos Anti-Virus daemon, and the Sophos Anti-Virus GUI. On-access scanner Scans files as they are accessed, and grants access to only those that are virus-free. On-demand scanner Scans the computer, or parts of the computer, immediately. Sophos Anti-Virus daemon Background process that provides control, logging, and email alerting for Sophos Anti-Virus. Sophos Anti-Virus GUI User interface accessed through a web browser. Where do you want to install Sophos Anti-Virus? [/opt/sophos-av] Do you want to enable on-access scanning? Yes(Y)/No(N) [Y] N On-access scanning disabled. Use savscan for on-demand scanning. Do you want to enable remote management? Yes(Y)/No(N) [Y] Y Sophos Anti-Virus GUI is accessible at http://localhost:8081/ from your web browser. You must now enter a username/password for Sophos Anti-Virus GUI. If you enter a blank password, the Sophos Anti-Virus GUI will be disabled. Username for Sophos Anti-Virus GUI? [admin] Password for Sophos Anti-Virus GUI? Re-enter the same password. Installing Sophos Anti-Virus... Selecting appropriate kernel support... Starting Sophos Anti-Virus daemon: [ OK ] Starting Sophos Management Agent: [ OK ] Starting Sophos Anti-Virus GUI daemon: [ OK ] Installation completed. NOTE: You are running Sophos Anti-Virus on a kernel for which Sophos provides the Sophos kernel interface module only as source. Therefore this module has been locally compiled. In most cases this module will work. However, Sophos reserves the right not to provide support where any such compilation has taken place. Sophos will use reasonable endeavours to provide first line support. Should issues arise that require second line support, or any other escalation process, Sophos cannot guarantee that such issues will be resolved. Sophos Anti-Virus GUI is available for configuration at http://localhost:8081/ [chefnutzer savlinux]#
Nachträgliche Installation autom. Update Die Eingabe der Updatesite kann hier schon erfolgen, kann aber auch über das RM erfolgen: [chefnutzer savlinux]# cd /opt/sophos-av/bin/ [chefnutzer bin]#./savsetup Welcome to Sophos Anti-Virus interactive configuration [1] Auto-updating configuration [2] Sophos Anti-Virus GUI configuration 1 [1] Display update configuration Configure primary update source: [2] From Sophos [3] From own server Configure secondary update source: [4] From Sophos [5] From own server 3 Configuring primary update source to be own server. Website or directory from which to update? [] http://sophos.uni-jena.de/cids/s000/savlinux/ Username for update source on your own server? (blank username indicates no authentication is required) [] Do you need a proxy to access update source on your own server? Yes(Y)/No(N) [N] [1] Display update configuration Configure primary update source: [2] From Sophos [3] From own server Configure secondary update source: [4] From Sophos [5] From own server q Freigabe der Ports Edit der Firewallregeln [chefnutzer bin]# cd /etc/sysconfig/ [chefnutzer sysconfig]# vi iptables Hinzufügen der Zeilen zu iptables -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp -s 141.35.3.15 --dport 8192 -j ACCEPT -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp -s 141.35.3.15 --dport 8193 -j ACCEPT -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp -s 141.35.3.15 --dport 8194 -j ACCEPT Update der Angepassten Config ins SVN svn ci iptables -m "Anpassung der Firewallregel an Sophos Virenscanner, Ports fuer RemoteManagement via EnterpriseConsole PC Hr. Hendrich freigegeben" Stop Firewall [chefnutzer sysconfig]# /etc/init.d/iptables stop Flushing firewall rules: [ OK ] Setting chains to policy ACCEPT: filter [ OK ] Unloading iptables modules: [ OK ] Start Firewall [chefnutzer sysconfig]# /etc/init.d/iptables start Applying iptables firewall rules: [ OK ] Loading additional iptables modules: ip_conntrack_netbios_n[ OK ]
Initialer On Demand Scan Erster Scan mögliche Viren, folgende Scans erfolgen dann automatisch via Policy über Console [chefnutzer bin]#./savscan / SAVScan virus detection utility Version 4.67.0 [Linux/Intel] Virus data version 4.67, July 2011 Includes detection for 2703423 viruses, Trojans and worms Copyright (c) 1989-2011 Sophos Group. All rights reserved. System time 03:54:50 PM, System date 13 July 2011 IDE directory is: /opt/sophos-av/lib/sav Using IDE file dropr-dt.ide Using IDE file gibi-gen.ide Using IDE file fake-dye.ide Using IDE file javad-cq.ide Using IDE file dorkbo-c.ide Using IDE file zbotda-a.ide Using IDE file swizz-rf.ide Using IDE file zacces-b.ide Using IDE file fake-dyv.ide Using IDE file fake-dyy.ide Using IDE file pws-bsh.ide... Using IDE file mdro-dpa.ide Using IDE file dwnl-jew.ide Using IDE file agen-smy.ide Using IDE file neeris-f.ide Using IDE file ranso-ay.ide Using IDE file fake-egc.ide Using IDE file agen-snv.ide Using IDE file bredo-eb.ide Using IDE file fake-egd.ide Quick Scanning 21290 files scanned in 3 minutes and 9 seconds. No viruses were discovered. End of Scan.