Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Feature Requests
  3. ClamAV installation that scans the local storage for malware and notifies the admin

ClamAV installation that scans the local storage for malware and notifies the admin

Scheduled Pinned Locked Moved Feature Requests
clamav
20 Posts 11 Posters 3.0k Views 12 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • jdaviescoatesJ Offline
    jdaviescoatesJ Offline
    jdaviescoates
    wrote on last edited by
    #4

    @msbt in the meantime install WordFence (if you haven't already)? Does a really great job of blocking and detecting most stuff.

    I use Cloudron with Gandi & Hetzner

    M W 2 Replies Last reply
    2
    • girishG girish

      I like the idea. I guess a periodic scan of the files in application's data directory is all we need to do? Since code is read-only anyway.

      murgeroM Offline
      murgeroM Offline
      murgero
      App Dev
      wrote on last edited by
      #5

      @girish Sounds about right to me.

      --
      https://urgero.org
      ~ Professional Nerd. Freelance Programmer. ~

      1 Reply Last reply
      1
      • jdaviescoatesJ jdaviescoates

        @msbt in the meantime install WordFence (if you haven't already)? Does a really great job of blocking and detecting most stuff.

        M Offline
        M Offline
        msbt
        App Dev
        wrote on last edited by
        #6

        @jdaviescoates said in Feature Request: (Optional) ClamAV installation that scans the local storage for malware and notifies the admin:

        @msbt in the meantime install WordFence (if you haven't already)? Does a really great job of blocking and detecting most stuff.

        thanks for the suggestion, but I tried that, doesn't work with the wordpress app because it can't write into the root directory

        jdaviescoatesJ 1 Reply Last reply
        2
        • girishG girish

          I like the idea. I guess a periodic scan of the files in application's data directory is all we need to do? Since code is read-only anyway.

          M Offline
          M Offline
          msbt
          App Dev
          wrote on last edited by
          #7

          @girish said in Feature Request: (Optional) ClamAV installation that scans the local storage for malware and notifies the admin:

          I like the idea. I guess a periodic scan of the files in application's data directory is all we need to do? Since code is read-only anyway.

          that's what I'm thinking, yea 😄 maybe a daily scan before/after backups might be good

          1 Reply Last reply
          3
          • jdaviescoatesJ jdaviescoates

            @msbt in the meantime install WordFence (if you haven't already)? Does a really great job of blocking and detecting most stuff.

            W Offline
            W Offline
            will
            wrote on last edited by
            #8

            @jdaviescoates Wordfence is great, I've used it professionally

            1 Reply Last reply
            1
            • LonkleL Offline
              LonkleL Offline
              Lonkle
              wrote on last edited by
              #9

              Did this end up as a feature or still just in the idea phase?

              1 Reply Last reply
              1
              • nebulonN Offline
                nebulonN Offline
                nebulon
                Staff
                wrote on last edited by
                #10

                Nothing has been implemented yet as far as I am aware of. However it is still a nice idea and we should consider it in the future.

                1 Reply Last reply
                3
                • M msbt

                  @jdaviescoates said in Feature Request: (Optional) ClamAV installation that scans the local storage for malware and notifies the admin:

                  @msbt in the meantime install WordFence (if you haven't already)? Does a really great job of blocking and detecting most stuff.

                  thanks for the suggestion, but I tried that, doesn't work with the wordpress app because it can't write into the root directory

                  jdaviescoatesJ Offline
                  jdaviescoatesJ Offline
                  jdaviescoates
                  wrote on last edited by
                  #11

                  @msbt said in Feature Request: (Optional) ClamAV installation that scans the local storage for malware and notifies the admin:

                  thanks for the suggestion, but I tried that, doesn't work with the wordpress app because it can't write into the root directory

                  That is true of the WordPress (Managed) app on Cloudron, yeah.

                  TBH I'm increasingly wondering what the point of the WordPress (Managed) app is. The only pro seems to be locked down core WordPress files. As far as I can tell you still have to keep plugins and themes updated manaully anyway (and that's there security holes are more likely to be). But with WordPress security updates now automated anyway, and with Wordfence installed the WordPress core files (and the rest) are pretty locked down anyway. And there loads of pros for the WordPress (Unmanaged) app: LDAP integration, SFTP access, ability to install plugins like Wordfence. Probably more I've missed too.

                  Think I'll copy this into a thread in WordPress (Managed)... 🙂

                  I use Cloudron with Gandi & Hetzner

                  1 Reply Last reply
                  1
                  • M Offline
                    M Offline
                    msbt
                    App Dev
                    wrote on last edited by
                    #12

                    @jdaviescoates said in Feature Request: (Optional) ClamAV installation that scans the local storage for malware and notifies the admin:

                    That is true of the WordPress (Managed) app on Cloudron, yeah.

                    I might have missed a part there, you can install and use wordfence, it just lacks some functionality I believe.

                    jdaviescoatesJ 1 Reply Last reply
                    0
                    • M msbt

                      @jdaviescoates said in Feature Request: (Optional) ClamAV installation that scans the local storage for malware and notifies the admin:

                      That is true of the WordPress (Managed) app on Cloudron, yeah.

                      I might have missed a part there, you can install and use wordfence, it just lacks some functionality I believe.

                      jdaviescoatesJ Offline
                      jdaviescoatesJ Offline
                      jdaviescoates
                      wrote on last edited by
                      #13

                      @msbt said in Feature Request: (Optional) ClamAV installation that scans the local storage for malware and notifies the admin:

                      I might have missed a part there, you can install and use wordfence, it just lacks some functionality I believe.

                      Yeah, you can't set-up the firewall, which one of it's primary and imho most important features.

                      I use Cloudron with Gandi & Hetzner

                      1 Reply Last reply
                      0
                      • robiR Offline
                        robiR Offline
                        robi
                        wrote on last edited by
                        #14

                        The firewall in WP Cerber works just fine in WP Managed.

                        It auto blocks and bans IPs and subnets based on your settings. Really useful.

                        Conscious tech

                        1 Reply Last reply
                        1
                        • robiR Offline
                          robiR Offline
                          robi
                          wrote on last edited by
                          #15

                          Another thought, if anyone is interested in contacting the Wordfence devs to see if they can modify their plugin a bit so it works in WP (Managed), we could have the best of both worlds.

                          Conscious tech

                          LonkleL 1 Reply Last reply
                          1
                          • robiR robi

                            Another thought, if anyone is interested in contacting the Wordfence devs to see if they can modify their plugin a bit so it works in WP (Managed), we could have the best of both worlds.

                            LonkleL Offline
                            LonkleL Offline
                            Lonkle
                            wrote on last edited by
                            #16

                            @robi I have no used Wordpfence but my guess is the plug-in edits the wp-config.php and maybe edits the .htaccess file. Is that why it’s not supported?

                            If so, it’d be a matter of it removing that part of its protection.

                            Tbh, I could probably do it myself with a plug-in. Hook in the right area or overwrite a function to bypass those incompatible security features (which may not even be needed in a read-only environment anyway). If there’s enough support for Wordpress on Managed then I can look into this?

                            robiR 1 Reply Last reply
                            0
                            • LonkleL Lonkle

                              @robi I have no used Wordpfence but my guess is the plug-in edits the wp-config.php and maybe edits the .htaccess file. Is that why it’s not supported?

                              If so, it’d be a matter of it removing that part of its protection.

                              Tbh, I could probably do it myself with a plug-in. Hook in the right area or overwrite a function to bypass those incompatible security features (which may not even be needed in a read-only environment anyway). If there’s enough support for Wordpress on Managed then I can look into this?

                              robiR Offline
                              robiR Offline
                              robi
                              wrote on last edited by
                              #17

                              @Lonk .htaccess modification works fine, as WP Cerber does it.

                              Conscious tech

                              1 Reply Last reply
                              0
                              • T Offline
                                T Offline
                                tamayers
                                wrote on last edited by
                                #18

                                Would be nice to have ClamAV available as an app for custom installations/API use. Looks like there is a docker image now:

                                https://hub.docker.com/r/mkodockx/docker-clamav/

                                A 1 Reply Last reply
                                5
                                • T tamayers

                                  Would be nice to have ClamAV available as an app for custom installations/API use. Looks like there is a docker image now:

                                  https://hub.docker.com/r/mkodockx/docker-clamav/

                                  A Offline
                                  A Offline
                                  ApplegateR
                                  wrote on last edited by
                                  #19

                                  @tamayers yes this should be nice to set scan just only for where is write and read file. Not docker configure.

                                  Richard Applegate
                                  Anthem Coffee and Tea
                                  Joe Coffee
                                  IT/Administrator Server/Network

                                  1 Reply Last reply
                                  1
                                  • girishG girish referenced this topic on
                                  • M msbt referenced this topic on
                                  • M Offline
                                    M Offline
                                    Mamor
                                    wrote last edited by
                                    #20

                                    Running mail-server and nextcloud on cloudron. Clamav would be a fine feature. What's the status of this request?

                                    1 Reply Last reply
                                    1
                                    Reply
                                    • Reply as topic
                                    Log in to reply
                                    • Oldest to Newest
                                    • Newest to Oldest
                                    • Most Votes


                                    • Login

                                    • Don't have an account? Register

                                    • Login or register to search.
                                    • First post
                                      Last post
                                    0
                                    • Categories
                                    • Recent
                                    • Tags
                                    • Popular
                                    • Bookmarks
                                    • Search