README file for SquidClamav Version 1.0

SquidClamav - A Clamav Antivirus Redirector for Squid -
		http://www.samse.fr/GPL/squidclamav/


Please see INSTALL file file for installation instructions

Configuration :
---------------

By default, the configuration file is located at:
  /usr/local/squidclamv/etc/squidclamav.conf
You need to create this file from scratch with the aids of
the following instructions:

Squidclamav Patterns:

The syntax of lines in the squidclamav.conf file are of the form:

	regex|regexi pattern
or
	abort|aborti pattern
or
	content|contenti pattern
or
	redirect cgi_url_redirection
or
	maxsize integer

Full regex matching is made available by the use of the GNU Regex libary.
It also supports pattern buffers.

Let's say you want to check against the ClamAv antivirus files with
extension .exe, .com and .zip. Then here are the line you may include:

	regexi  ^.*\.exe$
	regexi  ^.*\.com$
	regexi  ^.*\.zip$

Now let's say you want don't want to check image and HTML files, then you
should include the following lines in the configuration file:

	aborti ^.*\..gif$
	aborti ^.*\..png$
	aborti ^.*\..jpg$
	abort ^.*\..html$
	abort ^.*\..htm$

If you don't want to check directory listing or default index.html add
the following line :

	abort ^.*\/$

You may want to allow virus scanning based on content type, for example
for all 'application/*' file:

	content ^application\/.*$

will scan all files with this content-type.

Here is the configuration I use:

	abort ^.*/cgi-bin/.*$
	abort ^.*\.gz$
	abort ^.*\.pdf$
	abort ^.*\.js$
	content ^.*application\/.*$

When a virus is found the squidclamav program should redirect the request
to a CGI program. You must specify the URL to this CGI with the redirect
directive as follow:

	redirect http://proxy.domain.com/cgi-bin/clwarn.cgi

Squidclamav will pass to this CGI the following parameters:

	url=ORIGNAL_HTTP_REQUEST
	virus=NAME_OF_THE_VIRUS

Virus scanning can be stop on large files upper than maxsize. Default
is 100 Kb

	maxsize 102400

Has I have experienced a bug with squid-2.5STABLE7+8 regarding request_body_max_size
I have had a configuration directive called sizelimit that block any file upper than
this limit. Default is 0 no limit. Use this only as a workaround

	sizelimit 10485760

will block any file with size upper than 10 Mb.

When the limit is reach, Squidclamav will pass to clwarn.cgi CGI the following
parameters:

	url=ORIGNAL_HTTP_REQUEST
	size=SIZE_OF_THE_FILE
	limit=MAX_BODY_SIZE_LIMIT

If you find it useful, I'd like to know - please send email
to gilles@darold.net


This project is a modified version of the excellent Squirm Redirector for Squid
Maintained by Chris Foote, and copyrighted as follow :

        Copyright (C) 1998 Chris Foote & Wayne Piekarski

The original Squirm version used was squirm-1.0betaB. Some other parts are
cut and paste from the ex1.c program given in the ClamAv distribution and
are copyrighted: Copyright (C) 2002 - 2004 Tomasz Kojm

All other code: Copyright (C) 2005 Gilles Darold - Groupe SAMSE

    This program is free software; you can redistribute it and/or modify
    it under the terms of the GNU General Public License as published by
    the Free Software Foundation; either version 2 of the License, or
    (at your option) any later version.

    This program is distributed in the hope that it will be useful,
    but WITHOUT ANY WARRANTY; without even the implied warranty of
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
    GNU General Public License for more details.

    You should have received a copy of the GNU General Public License
    along with this program; if not, write to the Free Software
    Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.

Please see the file GPL in this directory for full copyright
information.

