Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to scan pfsense server itself for virus, etc.

    Scheduled Pinned Locked Moved General pfSense Questions
    14 Posts 6 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jahonixJ
      jahonix
      last edited by

      @kpa:

      There are few rootkits and such…

      A rootkit is only an attack vector, not a virus itself, right? It could be used to install a virus/trojan/whathaveyou.

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        If you want to argue semantics a rootkit is not even a attack vector, its normally a toolset used to hide the presence or activity of another application - say a virus or malware, etc.  Could be used to provide someone backdoor to something via this other application, etc.

        If he left his firewall open to say a bruteforce attack against his ssh service, this could be used to install a rootkit, etc.

        If he left some service open to pfsense like ssh or the webgui - its not impossible to think that this could be used to leverage the installation of unwanted software on the machine where a rootkit could be used to make sure that software stays hidden, etc.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • T
          techbee
          last edited by

          Well, I asked because in my suricata log, it detected trojan on my pfsense wan towards outside internet. Correct me if i am wrong, but seems to me that a trojan in my pfsense wan is communicating outside the internet.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            "it detected trojan on my pfsense wan towards outside internet"

            You do understand that all your clients send traffic out your wan ;)  Its way more likely that one of the clients behind pfsense is sending the traffic - or its a false alarm completely.

            How about some actual details and we can help look into what is causing the alert.  What is the actual sig hit in suicata?  And your saying its not seeing this same hit on your lan side?  What is the details - where is it going, what is in the packet?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • T
              techbee
              last edited by

              Yes I do understand that.

              But it crossed my mind, what if the cache objects of squid contained malware or any posibility that the malware were in the network and infected the pfsense server since it is part of the network as well.  something like those.  so I wonder if I can schedule cleaning on the server as well.

              1 Reply Last reply Reply Quote 0
              • T
                techbee
                last edited by

                @techbee:

                Yes I do understand that.

                But it crossed my mind, what if the cache objects of squid contained malware or any posibility that the malware were in the network and infected the pfsense server since it is part of the network as well.  something like those.  so I wonder if I can schedule cleaning on the server as well.

                I dont remember the exact sig but its not appearing in my lan logs, it is going outside to some ip address.

                1 Reply Last reply Reply Quote 0
                • K
                  kpa
                  last edited by

                  How the heck you think the proxy would suddenly start running the cached objects in an execution context? If such thing was possible nobody would trust that proxy software because it would be too dangerous to use. You have to try a lot harder if you want to convince anyone here that such infection is even remotely possible on pfSense.

                  1 Reply Last reply Reply Quote 0
                  • T
                    techbee
                    last edited by

                    kpa, firstly, I am not trying to convince. It was only my idea.

                    the fact is, my concern is the subject of this thread.

                    so, if i got an answer to my question, the topic ends.  its not even a case if infection in server is possible or not. but my only after is the answer to the question.

                    1 Reply Last reply Reply Quote 0
                    • M
                      marvosa
                      last edited by

                      At a high level, you'd have to figure out how to install an antivirus product on a highly customized version of FreeBSD (PFsense).

                      There are some commercial titles on this list -> https://www.freebsd.org/commercial/software.html

                      On the free side, all I can think of is CLAMAV off the top of my head.

                      1 Reply Last reply Reply Quote 1
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        "infected the pfsense server since it is part of the network as well."

                        Via what service??  What virus/worm are you aware of that can infect freebsd via what service?  Pfsense only listens on a couple ports. Say ntp, ssh, http(s) what other applications are running and listening on the network that some sort of worm could exploit and infect freebsd?

                        If you are seeing some sort of flag from your ips that something is bad - then investigate where its coming from.  You have not shown this traffic is coming from pfsense itself, nor have you even validated that its not some false positive..

                        I agree you should investigate such traffic - but jumping to think that something infected pfsense vs looking to what else it might be is jumping the gun a bit..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.