clamav/docs/html/node43.html

221 lines
7.4 KiB
HTML
Raw Normal View History

2008-03-03 19:11:41 +00:00
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
2008-03-03 19:11:41 +00:00
<!--Converted with LaTeX2HTML 2002-2-1 (1.71)
original version by: Nikos Drakos, CBLU, University of Leeds
* revised and updated by: Marcus Hennecke, Ross Moore, Herb Swan
* with significant contributions from:
Jens Lippmann, Marek Rouchal, Martin Wilck and others -->
<HTML>
<HEAD>
2007-10-08 19:22:34 +00:00
<TITLE>Data scan functions</TITLE>
<META NAME="description" CONTENT="Data scan functions">
<META NAME="keywords" CONTENT="clamdoc">
<META NAME="resource-type" CONTENT="document">
<META NAME="distribution" CONTENT="global">
2008-03-03 19:11:41 +00:00
<META NAME="Generator" CONTENT="LaTeX2HTML v2002-2-1">
<META HTTP-EQUIV="Content-Style-Type" CONTENT="text/css">
<LINK REL="STYLESHEET" HREF="clamdoc.css">
2007-10-08 19:22:34 +00:00
<LINK REL="next" HREF="node44.html">
<LINK REL="previous" HREF="node42.html">
<LINK REL="up" HREF="node42.html">
<LINK REL="next" HREF="node44.html">
</HEAD>
<BODY >
2008-03-03 19:11:41 +00:00
<DIV CLASS="navigation"><!--Navigation Panel-->
2008-06-09 19:14:55 +00:00
<A NAME="tex2html753"
HREF="node44.html">
<IMG WIDTH="37" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="next" SRC="next.png"></A>
2008-06-09 19:14:55 +00:00
<A NAME="tex2html749"
2007-10-08 19:22:34 +00:00
HREF="node42.html">
<IMG WIDTH="26" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="up" SRC="up.png"></A>
2008-06-09 19:14:55 +00:00
<A NAME="tex2html743"
HREF="node42.html">
<IMG WIDTH="63" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="previous" SRC="prev.png"></A>
2008-06-09 19:14:55 +00:00
<A NAME="tex2html751"
HREF="node1.html">
<IMG WIDTH="65" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="contents" SRC="contents.png"></A>
<BR>
2008-06-09 19:14:55 +00:00
<B> Next:</B> <A NAME="tex2html754"
2007-10-08 19:22:34 +00:00
HREF="node44.html">Memory</A>
2008-06-09 19:14:55 +00:00
<B> Up:</B> <A NAME="tex2html750"
2007-10-08 19:22:34 +00:00
HREF="node42.html">Database reloading</A>
2008-06-09 19:14:55 +00:00
<B> Previous:</B> <A NAME="tex2html744"
2007-10-08 19:22:34 +00:00
HREF="node42.html">Database reloading</A>
2008-06-09 19:14:55 +00:00
&nbsp; <B> <A NAME="tex2html752"
HREF="node1.html">Contents</A></B>
<BR>
2008-03-03 19:11:41 +00:00
<BR></DIV>
<!--End of Navigation Panel-->
2007-10-08 19:22:34 +00:00
<H3><A NAME="SECTION00074100000000000000">
Data scan functions</A>
</H3>
It's possible to scan a file or descriptor using:
<PRE>
2007-10-08 19:22:34 +00:00
int cl_scanfile(const char *filename, const char **virname,
unsigned long int *scanned, const struct cl_engine *engine,
const struct cl_limits *limits, unsigned int options);
int cl_scandesc(int desc, const char **virname, unsigned
long int *scanned, const struct cl_engine *engine, const
struct cl_limits *limits, unsigned int options);
</PRE>
2008-03-18 15:40:41 +00:00
Both functions will store a virus name under the pointer <code>virname</code>,
2007-10-08 19:22:34 +00:00
the virus name is part of the engine structure and must not be released
directly. If the third argument (<code>scanned</code>) is not NULL, the
functions will increase its value with the size of scanned data (in
<code>CL_COUNT_PRECISION</code> units). Both functions have support for archive
limits in order to protect against Denial of Service attacks.
<PRE>
2007-10-08 19:22:34 +00:00
struct cl_limits {
2008-03-18 15:40:41 +00:00
unsigned long int maxscansize; /* during the scanning of archives this
* size will never be exceeded
*/
unsigned long int maxfilesize; /* compressed files will only be
* decompressed and scanned up to this size
*/
unsigned int maxreclevel; /* maximum recursion level for archives */
unsigned int maxfiles; /* maximum number of files to be scanned
* within a single archive
*/
unsigned short archivememlim; /* limit memory usage for some unpackers */
2007-10-08 19:22:34 +00:00
};
</PRE>
2007-10-08 19:22:34 +00:00
The last argument (<code>options</code>) configures the scan engine and supports
the following flags (that can be combined using bit operators):
<UL>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_STDOPT</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
This is an alias for a recommended set of scan options. You
should use it to make your software ready for new features
in the future versions of libclamav.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_RAW</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
Use it alone if you want to disable support for special files.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_ARCHIVE</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
This flag enables transparent scanning of various archive formats.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_BLOCKENCRYPTED</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
With this flag the library will mark encrypted archives as viruses
(Encrypted.Zip, Encrypted.RAR).
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_MAIL</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
Enable support for mail files.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_MAILURL</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
The mail scanner will download and scan URLs listed in a mail
body. This flag should not be used on loaded servers. Due to
potential problems please do not enable it by default but make
it optional.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_OLE2</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
Enables support for OLE2 containers (used by MS Office and .msi
files).
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_PDF</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
Enables scanning within PDF files.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_PE</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
This flag enables deep scanning of Portable Executable files and
allows libclamav to unpack executables compressed with run-time
unpackers.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_ELF</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
Enable support for ELF files.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_BLOCKBROKEN</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
libclamav will try to detect broken executables and mark them as
Broken.Executable.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_HTML</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
This flag enables HTML normalisation (including ScrEnc
decryption).
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_ALGORITHMIC</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
Enable algorithmic detection of viruses.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_PHISHING_BLOCKSSL</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
Phishing module: always block SSL mismatches in URLs.
</LI>
2008-03-03 19:11:41 +00:00
<LI><SPAN CLASS="textbf">CL_SCAN_PHISHING_BLOCKCLOAK</SPAN>
2007-10-08 19:22:34 +00:00
<BR>
Phishing module: always block cloaked URLs.
</LI>
</UL>
All functions return 0 (<code>CL_CLEAN</code>) when the file seems clean,
<code>CL_VIRUS</code> when a virus is detected and another value on failure.
<PRE>
2007-10-08 19:22:34 +00:00
...
struct cl_limits limits;
const char *virname;
memset(&amp;limits, 0, sizeof(struct cl_limits));
2008-03-18 15:40:41 +00:00
limits.maxfiles = 10000;
limits.maxscansize = 100 * 1048576; /* 100 MB */
limits.maxfilesize = 10 * 1048576; /* 10 MB */
limits.maxreclevel = 16;
2007-10-08 19:22:34 +00:00
if((ret = cl_scanfile("/tmp/test.exe", &amp;virname, NULL, engine,
&amp;limits, CL_STDOPT)) == CL_VIRUS) {
printf("Virus detected: %s\n", virname);
} else {
printf("No virus detected.\n");
if(ret != CL_CLEAN)
printf("Error: %s\n", cl_strerror(ret));
}
</PRE>
<P>
2008-03-03 19:11:41 +00:00
<DIV CLASS="navigation"><HR>
2007-10-08 19:22:34 +00:00
<!--Navigation Panel-->
2008-06-09 19:14:55 +00:00
<A NAME="tex2html753"
2007-10-08 19:22:34 +00:00
HREF="node44.html">
<IMG WIDTH="37" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="next" SRC="next.png"></A>
2008-06-09 19:14:55 +00:00
<A NAME="tex2html749"
2007-10-08 19:22:34 +00:00
HREF="node42.html">
<IMG WIDTH="26" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="up" SRC="up.png"></A>
2008-06-09 19:14:55 +00:00
<A NAME="tex2html743"
2007-10-08 19:22:34 +00:00
HREF="node42.html">
<IMG WIDTH="63" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="previous" SRC="prev.png"></A>
2008-06-09 19:14:55 +00:00
<A NAME="tex2html751"
2007-10-08 19:22:34 +00:00
HREF="node1.html">
<IMG WIDTH="65" HEIGHT="24" ALIGN="BOTTOM" BORDER="0" ALT="contents" SRC="contents.png"></A>
<BR>
2008-06-09 19:14:55 +00:00
<B> Next:</B> <A NAME="tex2html754"
2007-10-08 19:22:34 +00:00
HREF="node44.html">Memory</A>
2008-06-09 19:14:55 +00:00
<B> Up:</B> <A NAME="tex2html750"
2007-10-08 19:22:34 +00:00
HREF="node42.html">Database reloading</A>
2008-06-09 19:14:55 +00:00
<B> Previous:</B> <A NAME="tex2html744"
2007-10-08 19:22:34 +00:00
HREF="node42.html">Database reloading</A>
2008-06-09 19:14:55 +00:00
&nbsp; <B> <A NAME="tex2html752"
2008-03-03 19:11:41 +00:00
HREF="node1.html">Contents</A></B> </DIV>
2007-10-08 19:22:34 +00:00
<!--End of Navigation Panel-->
<ADDRESS>
Tomasz Kojm
2008-07-08 16:22:31 +00:00
2008-07-07
</ADDRESS>
</BODY>
</HTML>