3 ms·
You should quarantine them until you’ve analyzed them. Like you stated, an async process using a function would suffice. Previously used ClamAV for this in a p
by junto 2y ago
You should quarantine them until you’ve analyzed them.
Like you stated, an async process using a function would suffice. Previously used ClamAV for this in a private cloud solution, I’ve also used the built in anti-virus support on Azure Blob Storage if you don’t mind multi-cloud, plus an Azure Function has the ability to support blob triggers, which is a nice feature.
The file types scan is relatively simple. You just need a list of known “magic string” header values to do a comparison, and for that you only need a max of 40 bytes of the beginning of the file to do the check (from memory). Depending on your stack, there are usually some libraries already available to perform the matching.
And it goes without saying, but never trust the client, and always generate your own filenames.
https://en.m.wikipedia.org/wiki/List_of_file_signatures https://en.m.wikipedia.org/wiki/List_of_file_signatures
- dividuum 2y agoI'm pretty sure ClamAv would add more vulnerabilities to your stack than it might prevent from being exploited.
- junto 2y agoIt’s an old stack. Can you suggest an alternative self hosted option?
- dividuum 2y agoI consider the approach of using virus scanning inherently flawed: They rely on heuristics and rules to essentially create a blacklist. And they add a ton of complexity (more code -> usually more bugs) which is not something you want if you work with untrustworthy data. What you instead want is a whitelist: Only allow properly formatted images and videos and ruthlessly reject anything else. I wrote about how I implemented this for my service in another response.