PHP ClamAV Lib
jekillen at prodigy.net
Mon Dec 3 16:44:29 PST 2007
On Dec 3, 2007, at 6:21 AM, Attos wrote:
> You can execute ClamAV from PHP and parse the result.
> The exec() function can do the job. This is the description from the
> PHP manual:
> (PHP 3, PHP 4, PHP 5)
> exec -- Execute an external program
> string exec ( string command [, array &output [, int &return_var]] )
> exec() executes the given command.
> The command that will be executed.
> If the output argument is present, then the specified array will be
> filled with every line of output from the command. Trailing
> whitespace, such as \n, is not included in this array. Note that if
> the array already contains some elements, exec() will append to the
> end of the array. If you do not want the function to append elements,
> call unset() on the array before passing it to exec().
> If the return_var argument is present along with the output argument,
> then the return status of the executed command will be written to this
> Return Values
> The last line from the result of the command. If you need to execute a
> command and have all the data from the command passed directly back
> without any interference, use the passthru() function.
> To get the output of the executed command, be sure to set and use the
> output parameter.
> Example 1. An exec() example
> // outputs the username that owns the running php/httpd process
> // (on a system with the "whoami" executable in the path)
> echo exec('whoami');
Yes, I could use exec(); accept I would have to be vary careful to code
script so it could not be exploited by a client. I would be a little
scanning an uploaded file with a script that is run in a shell rather
run under the auspices of the web server. More than viruses, an image
file could contain embedded php scripts. Or any other file for that
True it would have to have a recognized file name suffix for the file
executed as php. but a call to gd functions can be made by specifying
a php file rather than an image file in an image tag. Anyhow, I suspect
I would have to rebuild php to include the Clamav module anyhow.
And porting the php-clamav module, if it only builds the code, would
leave the user having to do a rebuild of php to use it. And if there is
no means of rebuilding a package to add or remove a feature, or use
special configuration items, why not just by pass the port? I have been
using ports and in some cases have been left wondering just how much
configuration needs to be done after a port is installed, what and where
was installed. But I probably am still missing something.
Thanks for the suggestion.
> On Dec 1, 2007 1:30 PM, Matthew Seaman
> <m.seaman at infracaninophile.co.uk> wrote:
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA256
>> jekillen wrote:
>>> I am looking for PHP ClamAV Lib
>>> in ports and I do not know of hand
>>> where to find it. I did not find it in
>>> /usr/ports/security. And if it exists in
>>> ports, what would it be called for a
>>> find command?
>>> My aim is to use it for scanning files
>>> uploaded to web sites in php scripts.
>>> I installed ClamAV, Amavisd-new,
>>> and Cyrus-sasl-saslauthd
>>> from /usr/ports/security.
>>> FreeBSD v 6.2
>>> Thanks in advance
>>> Jeff K
More information about the freebsd-ports