I was reading on the web that clamav is not an “endpoint antivirus solution” but at the same time its called the best antivirus for gnu/linux and gnu/linux servers. Is worth for a home server?

  • PragmaticOne@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    31 minutes ago

    If you are on Windows then there is no reason to use it. Windows Defender is excellent and MS put A LOT of effort in making sure it’s that way.

    If you’e on Unix/Linux it’s pointless other than to scan stuff thats come from a Windows network.

  • Matt The Horwood@lemmy.horwood.cloud
    link
    fedilink
    English
    arrow-up
    1
    ·
    39 minutes ago

    Clamav is a full antivirus, but is missing on access scanning. It’s used a lot as a plugin to server software as you can feed it files and get a yes or no back.

    I would not recommend using it as endpoint protection, for that I would look at bitdefender. I use at work and it does the job

  • frongt@lemmy.zip
    link
    fedilink
    arrow-up
    6
    ·
    5 hours ago

    Not really. I mean it does the job, it’s a real AV that will catch malware, but it’s not a modern product. Its primary use is for corporations needing to meet a “you must have antivirus” compliance requirement.

    The best defense against Linux malware is reviewing stuff before you run it. And not running random stuff as root. And not piping curl/wget to bash, especially not sudo bash.

    And of course don’t expose stuff to the Internet unless you have to. And if you do, isolate each service, so that an attacker can’t pivot once they’re in your network.

      • ☂️-@lemmy.ml
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        edit-2
        4 hours ago

        yes like that. you set up your network and permissions and access in a whitelist so that your service can strictly only manipulate what’s needed.

        as in if it only needs access to these directories, or these endpoints that’s all it’s gonna get.

      • frongt@lemmy.zip
        link
        fedilink
        arrow-up
        1
        ·
        4 hours ago

        Network isolation. Internet-facing services should be in a DMZ, and unable to talk to each other unless specifically allowed.

        Containerization is good too, but not a substitute.