الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

البداية : برنامج مكافحة الفيروسات -مكيانيكية العمل

مغلق
بدأه xdata في 18 سبتمبر 2007 · 31 رد · 4,159 مشاهدة · في لغة C و ++C
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

:D السلام عليكم ورحمة الله

والصلاة و السلام علي رسول الله سيدنا محمد علية وعلي آلة وصحبة أجمعين

أما بعد دون الدخول في مقدمات فلن أعيد صياغة موضوع قد كتبنا مقدمه له مسبقاً

فإذا أردت قراة الموضوع من البداية إذهب إلي الربط التالي

حسناً هذة هي البدية "هذا هو التحدي لكم معشر المبرمجين " وقد أتسع الحديث والنقاش إلي كل لغات البرمجة

ماذا نفعل إذا أردنا أن نقوم بصناعة برنامجة يقوم بكشف الفيروسات وفحص الملفات في جهازك

كانت هذة المشكلة في بداية عصر الفيروسات "سهلة الحل نسبيا فقد كانت الفيروسات مجموعة من الملفات التنفيذية تقوم بمسح وتعديل بعض الملفات "

وكان علي المبرمج أن يكتشف أسمها ويصنع برنامج يقوم بمسحها من الجهاز

وحتي أن البعض وجد أن الحل هو مسح جميع البيانات

حسناً ،،، فمال العمل مع فيروسات هذا العصر التي هتي في الواقع برامج تحتوي علي أوامر قوية في بعض الاحيان ""؟؟ ماذا يفعل مع التروجنات مثلا

والديدان

أصبح الامر في شدة الصعوبة ...... نعم

لقد بحثت كثرا في الانترنت علي مراجع أو دوال أو أي شيئ يفيد في هذا الموضوع بالذات فكانت النتيجة = 0

ربما لم يحالفني الحظ في البداية .. حسنا سوف أحاول مجددا ولكن معكم هذة المرة ..

و الان وجدت بعض النتائج المشجعة

وإليكم موقع يهتم بهذا الشئن

http://www.openantivirus.org/

وحتي تقوم بتصفح هذا الموقع سوف أعود إليكم ريثما أقومم ببعض التجارب النووية الصغير

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#2

حسنا بعد البحث بأستخدمات تقنيات متقدمة في البحث " سرية جدأ وبعيداً عن جوجل و يا هو " وجدت بعد المصادر والاكواد المفية المفتوحة المصدر أرجو أن تكون مفيدة لكم

http://www.koders.com/cpp/fid79B3FDC680013...=antivirus+code

http://www.koders.com/cpp/fid82BD5756013C7...=antivirus+code

http://www.koders.com/default.aspx?s=antiv...la=Cpp&li=*

ونلتقي بعد الفاصل

...........

كونوا معانا لاننا مصرين علي فعل شئ جاد جداً

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#3

عدنا ...........

سوف أكتب لكم كود بلغة الـ pril الهدف منهة التوضيح لا أكثر

# <@LICENSE>
# Licensed to the Apache Software Foundation (ASF) under one or more
# contributor license agreements.  See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to you under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License.  You may obtain a copy of the License at:
# 
#	 http://www.apache.org/licenses/LICENSE-2.0
# 
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# </@LICENSE>

=head1 NAME

AntiVirus - simple anti-virus tests

=head1 SYNOPSIS

  loadplugin	 Mail::SpamAssassin::Plugin::AntiVirus

  body MICROSOFT_EXECUTABLE eval:check_microsoft_executable()
  body MIME_SUSPECT_NAME	eval:check_suspect_name()

=head1 DESCRIPTION

The MICROSOFT_EXECUTABLE rule works by checking for 3 possibilities in
the message in any application/* or text/* part in the message:

=over 4

=item - in text parts, look for a uuencoded executable start string

=item - in application parts, look for filenames ending in an executable extension

=item - in application parts, look for a base64 encoded executable start string

=back

=cut

package Mail::SpamAssassin::Plugin::AntiVirus;

use Mail::SpamAssassin::Plugin;
use Mail::SpamAssassin::Util;
use strict;
use warnings;
use bytes;

use vars qw(@ISA);
@ISA = qw(Mail::SpamAssassin::Plugin);

# constructor: register the eval rule
sub new {
  my $class = shift;
  my $mailsaobject = shift;

  # some boilerplate...
  $class = ref($class) || $class;
  my $self = $class->SUPER::new($mailsaobject);
  bless ($self, $class);

  $self->register_eval_rule("check_microsoft_executable");
  $self->register_eval_rule("check_suspect_name");

  return $self;
}

sub check_microsoft_executable {
  my ($self, $pms) = @_;

  _check_attachments(@_) unless exists $pms->{antivirus_microsoft_exe};

  return $pms->{antivirus_microsoft_exe};
}

sub check_suspect_name {
  my ($self, $pms) = @_;

  _check_attachments(@_) unless exists $pms->{antivirus_suspect_name};

  return $pms->{antivirus_suspect_name};
}

sub _check_attachments {
  my ($self, $pms) = @_;

  $pms->{antivirus_microsoft_exe} = 0;
  $pms->{antivirus_suspect_name} = 0;

  # MICROSOFT_EXECUTABLE triggered here
  foreach my $p ($pms->{msg}->find_parts(qr/./, 1)) {
	my ($ctype, $boundary, $charset, $name) =
	  Mail::SpamAssassin::Util::parse_content_type($p->get_header('content-type'));

	$name = lc $name || '';

	my $cte = lc $p->get_header('content-transfer-encoding') || '';
	$ctype = lc $ctype;

	if ($name && $name =~ /\.(?:ade|adp|asx|bas|bat|chm|cmd|com|cpl|crt|dll|exe|hlp|hta|inf|ins|isp|js|jse|l
k|mda|mdb|mde|mdt|mdw|mdz|msc|msi|msp|mst|nws|ops|pcd|pif|prf|reg|scf|scr\??|sct|shb|shs|shm|swf|url|vb|vbe|vbs|vbx|vxd|wsc|wsf|wsh)$/)
	{
	  # file extension indicates an executable
	  $pms->{antivirus_microsoft_exe} = 1;
	}
	elsif ($cte =~ /base64/ && defined $p->raw()->[0] &&
	   $p->raw()->[0] =~ /^TV[opqr].A..[AB].[AQgw][A-H].A/)
	{
	  # base64-encoded executable
	  $pms->{antivirus_microsoft_exe} = 1;
	}
	elsif ($ctype =~ /^text\b/) {
	  # uuencoded executable
	  for (@{$p->raw()}) {
	if (/^M35[GHIJK].`..`..*````/) {
	  # uuencoded executable
	  $pms->{antivirus_microsoft_exe} = 1;
	}
	  }
	}

	# MIME_SUSPECT_NAME triggered here
	if ($name && $ctype ne "application/octet-stream") {
	  $name =~ s/.*\.//;
	  $ctype =~ s@/(x-|vnd\.)@/@;

	  if (
	  # text
	  (($name =~ /^(?:txt|[px]?html?|xml)$/) &&
	   ($ctype !~ m@^(?:text/(?:plain|[px]?html?|english|sgml|xml|enriched|richtext)|message/external-body)@)) ||

	  # image
	  (($name =~ /^(?:jpe?g|tiff?|gif|png)$/) &&
	   ($ctype !~ m@^(?:image/|application/mac-binhex)@)) ||

	  # vcard
	  (($name eq "vcf") && $ctype ne "text/vcard") ||

	  # application
	  (($name =~ /^(?:bat|com|exe|pif|scr|swf|vbs)$/) &&
	   ($ctype !~ m@^application/@)) ||

	  # msword
	  (($name eq "doc") && ($ctype !~ m@^application/.*word$@)) ||

	  # powerpoint
	  (($name eq "ppt") &&
	   ($ctype !~ m@^application/.*(?:powerpoint|ppt)$@)) ||

	  # excel
	  (($name eq "xls") && ($ctype !~ m@^application/.*excel$@))
	  )
	  {
	$pms->{antivirus_suspect_name} = 1;
	  }
	}
  }
}

1;

الشطارة أذاي نتعلم من الكود دة ولحد ما نتعلم أنا لسة في حالة بحث عن المصادر

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#4

ولما دورت أكتر وأكتر

لقيت أكتر وأكتر

لقيت الكسبرسكي بنفسة واقف في سكتي بيقول "أنت كنتم نايمين ولة أية أنا هنا من زمان "

http://www.koders.com/c/fidED1A00454E2D83B...spx?s=antivirus

وكمان هكتب كود نواة البرنامج الرهيب دة

/*
 * Core Interface for Kaspersky AntiVirus
 *
 * Copyright (C) Ries van Twisk, vscan@rvt.dds.nl, 2002
 * Copyright (C) Rainer Link, rainer@openantivirus.org, 2002-2003
 * Various fixes by Kevin Wang <kjw@rightsock.com>, 2003
 *
 * This software is licensed under the GNU General Public License (GPL)
 * See: http://www.gnu.org/copyleft/gpl.html
 *
*/

#include "vscan-global.h"
#include "vscan-kavp.h"
#include "vscan-kavp_core.h"

extern BOOL verbose_file_logging;
extern BOOL send_warning_message;
extern fstring avpctl;


/*
  If virus is found, logs the filename/virusname into syslog
*/
void vscan_kavp_log_virus(char *infected_file, char *client_ip)
{
	// there seems no way to get the virus name :(		
	static char virusName[] = "UNKNOWN";

	vscan_syslog_alert("ALERT - Scan result: '%s' infected with virus '%s', client: '%s'", infected_file, virusName, client_ip);
	if ( send_warning_message )
		vscan_send_warning_message(infected_file, virusName, client_ip);

	return;
}

/* returns -1 if some error occurred
 * returns 1 if	 infected; deny access to file
 * returns 0 if not infected; allow access to file
*/
int vscan_kavp_scanfile(char *scan_file, char* client_ip)
{
	int result;
	char* response;
	int exit_code;

	/* Check the socket */
	if (kavp_socket < 0) {
		vscan_syslog("ERROR: connection to kavpdaemon was not open!\n");
			return -1;
	}

	/* Send scan request to kavdaeon */
	if ( verbose_file_logging )
		vscan_syslog("INFO: KAVRequestPath() scanning file [%s]\n", scan_file);

	if ( (result=KAVRequestPath(kavp_socket, scan_file, SILENT )) < 0) {
		vscan_syslog("ERROR: KAVRequestMulti() failed (return code: [%d])\n", result);
		return -1;
	}

	/* Receive status back about this file */	
	if ( (response=KAVResponse(kavp_socket, &exit_code, SILENT, 0)) ==0 ) {
		vscan_syslog("ERROR: KAVResponse() failed (return code: [0])\n");
		return -1;
	}

	if ((exit_code & 0xff) - 0x30) {
		vscan_kavp_log_virus(scan_file, client_ip);
		return 1;	// Found a virus; deny
	} 
	/* else no virus found */
	if ( verbose_file_logging )
		vscan_syslog("INFO: file %s is clean", scan_file);

	return 0;	// Everything seems to be ok
}

/* Initialize VSAPI */
void vscan_kavp_init(void)
{
	kavp_socket = KAVConnect(avpctl, SILENT);
	if ( kavp_socket < 0 ) {
	vscan_syslog("ERROR: KAVConnect() to socket %s failed (return code: [%d])\n", avpctl, kavp_socket);
	}
	if ( verbose_file_logging )
		vscan_syslog("INFO: KAVConnect() returned fd %d \n", kavp_socket);
}

/* Bye, bye */
void vscan_kavp_end(void)
{
	int result;
	if ( kavp_socket>=0 ) {
	if ( (result=KAVClose(kavp_socket, SILENT)) == 0 ) {
		if ( verbose_file_logging )
			   vscan_syslog("INFO: Disconnected from kavdaemon; fd %d.\n", kavp_socket);	

	} else {
			vscan_syslog("ERROR: KAVClose() on fd %d failed (return code: [%d])\n", kavp_socket, result);	
		}
		close(kavp_socket);
	kavp_socket = -1;
	} else {
	vscan_syslog("INFO: Not closing a closed connection\n");
	}
}

وكمان هتلاقي في الرابط أعلاة كل الفنكشن والهيدر فايل علي " جمب كدة في الصفحة "

وكل دة وأنا قاعد أكلم نفسي محدش بيرد..................؟؟؟؟؟؟؟؟؟؟؟

علي العموم أنا لسة مستني المشتركين و إلا من الافضل أن يغلق أو تغلق جميع أقسام البرمجة في جميع المنتديات العربية

و أنتظرونا بعد الفاصل................

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#5

عدنا ............

وفي عودتنا أحب أكتب " أهداء الي بابا وما وكل الاسرة والمقيمين وأهل طنطا وعلي المقيمين خارج القاهرة مراعاة فرق التوفيت " طبعا بهرج عشان أنتو بتهرجو

في عودتنا أحب أكتب الكود الاساسي للبرنامج

أسعد

3

2

1

أضرببببببببببببببببببببب

/* 
 * $Id: vscan-kavp.c,v 1.44 2003/06/25 10:19:15 mx2002 Exp $
 *
 * virusscanning VFS module for samba.  Log infected files via syslog
 * facility and block access using Kaspersky AntiVirus.
 *
 * Copyright (C) Rainer Link, 2001-2003
 *			   OpenAntiVirus.org <rainer@openantivirus.org>
 * Copyright (C) Stefan (metze) Metzmacher, 2003
 *			   <metze@metzemix.de>
 *
 * based on vscan-kavp by
 * Copyright (C) Ries van Twisk (vscan@rvt.dds.nl), 2002
 *
 * based on the audit VFS module by
 * Copyright (C) Tim Potter, 1999-2000
 * Copyright (C) Alexander Bokovoy, 2002
 *
 * based on the sample KAVP client sources by
 * Copyright (C) Kaspersky Labs, 2001
 *
 * 
 * includes some fixes by Kevin Wang <kjw@rightsock.com>, 2003
 *
 * Credits to
 * - Dave Collier-Brown for his VFS tutorial (http://www.geocities.com/orville_torpid/papers/vfs_tutorial.html)
 * - REYNAUD Jean-Samuel for helping me to solve some general Samba VFS issues at the first place
 * - Simon Harrison for his solution without Samba VFS (http://www.smh.uklinux.net/linux/sophos.html)
 * - the whole Samba Team :)
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 2 of the License, or
 * (at your option) any later version.
 *  
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *  
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
 */


#include "vscan-global.h"
#include "vscan-kavp.h"

#include "vscan-vfs.h"

#define VSCAN_MODULE_STR "vscan-kavp"

fstring config_file;			/* location of config file, either
								   PARAMCONF or as set via vfs options
								*/

ssize_t max_size;			  /* do not scan files greater than max_size
								   if max_size = 0, scan any file
								*/

BOOL verbose_file_logging;	  /* log ever file access */

BOOL scan_on_open;		 	/* scan a file before it is opened
								   Defaults to True
								*/

BOOL scan_on_close;			/* scan a new file put on share or
								   if file was modified
								   Defaults to False
								*/

BOOL deny_access_on_error;	  /* if connection to daemon fails,  should access to any
								   file be denied? Defaults to True 
				*/


BOOL deny_access_on_minor_error; /* if daemon returns non-critical error,
									should access to the file be denied? */

BOOL send_warning_message;	/* send a warning message using the windows
				   messenger service? */

fstring avpctl;			/* socket name for kavdaemon */

fstring quarantine_dir;	/* directory for infected files */
fstring quarantine_prefix;	/* prefix	for infected files */

enum infected_file_action_enum infected_file_action; /* what to do with infected files;
														defaults to quarantine */

int max_lrufiles;			   /* specified the maximum entries in lrufiles list */
time_t lrufiles_invalidate_time; /* specified the time in seconds after the lifetime
									of an entry is expired and entry will be invalidated */

/* module version */
static const char module_id[]=VSCAN_MODULE_STR" "SAMBA_VSCAN_VERSION_STR;


static BOOL do_parameter(const char *param, const char *value)
{
		if ( StrCaseCmp("max file size", param) == 0 ) {
		/* FIXME: sanity check missing! what, if value is out of range?
		   atoi returns int - what about LFS? atoi should be avoided!
		*/
				max_size = atoi(value);
				DEBUG(3, ("max file size is: %d\n", max_size));
		} else if ( StrCaseCmp("verbose file logging", param) == 0 ) {
				set_boolean(&verbose_file_logging, value);
				DEBUG(3, ("verbose file logging is: %d\n", verbose_file_logging));
		} else if ( StrCaseCmp("scan on open", param) == 0 ) {
				set_boolean(&scan_on_open, value);
				DEBUG(3, ("scan on open: %d\n", scan_on_open));
		} else if ( StrCaseCmp("scan on close", param) == 0 ) {
				set_boolean(&scan_on_close, value);
				DEBUG(3, ("scan on close is: %d\n", scan_on_close));
		} else if ( StrCaseCmp("deny access on error", param) == 0 ) {
				set_boolean(&deny_access_on_error, value);
				DEBUG(3, ("deny access on error is: %d\n", deny_access_on_error));
		} else if ( StrCaseCmp("deny access on minor error", param) == 0 ) {
				set_boolean(&deny_access_on_minor_error, value);
				DEBUG(3, ("deny access on minor error is: %d\n", deny_access_on_minor_error));
		} else if ( StrCaseCmp("send warning message", param) == 0 ) {
				set_boolean(&send_warning_message, value);
				DEBUG(3, ("send warning message is: %d\n", send_warning_message));
		} else if ( StrCaseCmp("infected file action", param) == 0 ) {
		if (StrCaseCmp("quarantine", value) == 0) {
			infected_file_action = INFECTED_QUARANTINE;
		} else if (StrCaseCmp("delete", value) == 0) {
			infected_file_action = INFECTED_DELETE;
		} else if (StrCaseCmp("nothing", value) == 0) {
			infected_file_action = INFECTED_DO_NOTHING;
		} else {
			DEBUG(2, ("samba-vscan: badly formed infected file action in configuration file, parameter %s\n", value));
		}
				DEBUG(3, ("infected file action is: %d\n", infected_file_action));
		} else if ( StrCaseCmp("quarantine directory", param) == 0 ) {
				fstrcpy(quarantine_dir, value);
				DEBUG(3, ("quarantine directory is: %s\n", quarantine_dir));
		} else if ( StrCaseCmp("quarantine prefix", param) == 0 ) {
				fstrcpy(quarantine_prefix, value);
				DEBUG(3, ("quarantine prefix is: %s\n", quarantine_prefix));
		} else if ( StrCaseCmp("max lru files entries", param) == 0 ) {
				max_lrufiles = atoi(value);
				DEBUG(3, ("max lru files entries is: %d\n", max_lrufiles));
		} else if ( StrCaseCmp("lru file entry lifetime", param) == 0 ) {
				lrufiles_invalidate_time = atol(value);
				DEBUG(3, ("lru file entry lifetime is: %li\n", (long)lrufiles_invalidate_time));
	} else if ( StrCaseCmp("avp socket file", param) == 0 ) {
		fstrcpy(avpctl, value);
		DEBUG(3, ("avp socket file is: %s\n", avpctl));
		} else
				DEBUG(3, ("unknown parameter: %s\n", param));

		return True;
}

static BOOL do_section(const char *section)
{
		/* simply return true, there's only one section :-) */
		return True;
}




/* Implementation of vfs_ops.  */

#if (SMB_VFS_INTERFACE_VERSION >= 6)
static int vscan_connect(vfs_handle_struct *handle, connection_struct *conn, const char *svc, const char *user)
#else
static int vscan_connect(struct connection_struct *conn, PROTOTYPE_CONST char *svc, PROTOTYPE_CONST char *user)
#endif
{
	#if (SAMBA_VERSION_MAJOR==2 && SAMBA_VERSION_RELEASE>=4) || SAMBA_VERSION_MAJOR==3
	 #if !(SMB_VFS_INTERFACE_VERSION >= 6)
		  pstring opts_str;
		  PROTOTYPE_CONST char *p;
	 #endif
	#endif
		int retval;

#if (SMB_VFS_INTERFACE_VERSION >= 6)
		vscan_syslog("samba-vscan (%s) connected (Samba 3.0), (c) by Rainer Link, OpenAntiVirus.org", module_id);
#endif

		/* set default value for configuration files */
		fstrcpy(config_file, PARAMCONF);

		/* set default value for max file size */
		max_size = VSCAN_MAX_SIZE;

		/* set default value for file logging */
		verbose_file_logging = VSCAN_VERBOSE_FILE_LOGGING;

		/* set default value for scan on open() */
		scan_on_open = VSCAN_SCAN_ON_OPEN;

		/* set default value for scan on close() */
		scan_on_close = VSCAN_SCAN_ON_CLOSE;

		/* set default value for deny access on error */
		deny_access_on_error = VSCAN_DENY_ACCESS_ON_ERROR;

	/* set default value for deny access on minor error */
	deny_access_on_minor_error = VSCAN_DENY_ACCESS_ON_MINOR_ERROR;

	/* set default value for send warning message */
	send_warning_message = VSCAN_SEND_WARNING_MESSAGE;

		/* set default value for infected file action */
		infected_file_action = VSCAN_INFECTED_FILE_ACTION;

		/* set default value for quarantine directory */
		fstrcpy(quarantine_dir, VSCAN_QUARANTINE_DIRECTORY);

		/* set default value for quarantine prefix */
		fstrcpy(quarantine_prefix, VSCAN_QUARANTINE_PREFIX);

	/* set default value for kavdaemon socket file (AVPCTL) */
	fstrcpy(avpctl, AVPCTL);

		/* set default value for maximum lrufile entries */
		max_lrufiles = VSCAN_MAX_LRUFILES;

		/* time after an entry is considered as expired */
		lrufiles_invalidate_time = VSCAN_LRUFILES_INVALIDATE_TIME;


	vscan_syslog("INFO: connect to service %s by user %s", 
		   svc, user);

	#if (SAMBA_VERSION_MAJOR==2 && SAMBA_VERSION_RELEASE>=4) || SAMBA_VERSION_MAJOR==3
	 #if (SMB_VFS_INTERFACE_VERSION >= 6)
	  fstrcpy(config_file, lp_parm_const_string(SNUM(conn),VSCAN_MODULE_STR,"config-file",PARAMCONF));
	 #else
		  pstrcpy(opts_str, (const char*) lp_vfs_options(SNUM(conn)));
		  if( !*opts_str ) {
				DEBUG(3, ("samba-vscan: no configuration file set - using default value (%s).\n", lp_vfs_options(SNUM(conn))));
		  } else {
				p = opts_str;
				if ( next_token(&p, config_file, "=", sizeof(config_file)) ) {
						trim_string(config_file, " ", " ");
						if ( !strequal("config-file", config_file) ) {
								DEBUG(3, ("samba-vscan - connect: options %s is not config-file\n", config_file));
								/* setting default value */
								fstrcpy(config_file, PARAMCONF);

						} else {
								if ( !next_token(&p, config_file," \n",sizeof(config_file)) ) {
										DEBUG(3, ("samba-vscan - connect: no option after config-file=\n"));
										/* setting default value */
										fstrcpy(config_file, PARAMCONF);
								} else {
										trim_string(config_file, " ", " ");
										DEBUG(3, ("samba-vscan - connect: config file name is %s\n", config_file));
								}
						}
				}
		  }
	  #endif /*  #if (SMB_VFS_INTERFACE_VERSION >= 6)*/
		  retval = pm_process(config_file, do_section, do_parameter);
		  DEBUG(10, ("pm_process returned %d\n", retval));
	  if (!retval) vscan_syslog("ERROR: could not parse configuration file '%s'. File not found or not read-able. Using compiled-in defaults", config_file);
	#endif


/*	vscan_kavp_init(); 
 * 	persistent connection causes trouble, when kavdaemon is sig-HUP'ed, as then
 *	we get an connection error for every file being accessed 
 * 	do _init and _close on the open() / close() call now
*/

		/* initialise lrufiles list */
		DEBUG(5, ("init lrufiles list\n"));
		lrufiles_init(max_lrufiles, lrufiles_invalidate_time);



	 #if (SMB_VFS_INTERFACE_VERSION >= 6)
	 return SMB_VFS_NEXT_CONNECT(handle, conn, svc, user);
	 #else
	 return default_vfs_ops.connect(conn, svc, user);
	 #endif

}

#if (SMB_VFS_INTERFACE_VERSION >= 6)
static void vscan_disconnect(vfs_handle_struct *handle, connection_struct *conn)
#else/* Samba 3.0 alphaX */
static void vscan_disconnect(struct connection_struct *conn)
#endif
{
	/* vscan_kavp_end(); */

	vscan_syslog("INFO: disconnected");

		lrufiles_destroy_all();

#if (SMB_VFS_INTERFACE_VERSION >= 6)
	SMB_VFS_NEXT_DISCONNECT(handle, conn);
#else
	default_vfs_ops.disconnect(conn);
#endif
}


#if (SMB_VFS_INTERFACE_VERSION >= 6)
static int vscan_open(vfs_handle_struct *handle, connection_struct *conn, const char *fname, int flags, mode_t mode)
#else
static int vscan_open(struct connection_struct *conn, PROTOTYPE_CONST char *fname, int flags, mode_t mode)
#endif
{
	int retval, must_be_checked;
	SMB_STRUCT_STAT stat_buf;
	pstring filepath;
	char client_ip[CLIENT_IP_SIZE];

	int rc;


		/* scan files while opening? */
		if ( !scan_on_open ) {
				DEBUG(3, ("samba-vscan - open: File '%s' not scanned as scan_on_open is not set\n", fname));
#if (SMB_VFS_INTERFACE_VERSION >= 6)
		return SMB_VFS_NEXT_OPEN(handle, conn, fname, flags, mode);
#else
				return default_vfs_ops.open(conn, fname, flags, mode);
#endif				
		}

	vscan_kavp_init();
	if ( kavp_socket < 0 && deny_access_on_error ) {

						/* an error occured - can not communicate to daemon - deny access */
						vscan_syslog("ERROR: can not communicate to daemon - access denied");
						errno = EACCES;
			vscan_kavp_end();
						return -1;
	} else {
#if (SMB_VFS_INTERFACE_VERSION >= 6)
			if ( (SMB_VFS_NEXT_STAT(handle, conn, fname, &stat_buf)) != 0 ) {	/* an error occured */ 
			vscan_kavp_end();
			return SMB_VFS_NEXT_OPEN(handle, conn, fname, flags, mode);
			}
#else
			if ( (default_vfs_ops.stat(conn, fname, &stat_buf)) != 0 ) {   /* an error occured */ 
			vscan_kavp_end();
			return default_vfs_ops.open(conn, fname, flags, mode);
			}
#endif
		else if ( S_ISDIR(stat_buf.st_mode) ) { 	/* is it a directory? */
			vscan_kavp_end();
#if (SMB_VFS_INTERFACE_VERSION >= 6)
			return SMB_VFS_NEXT_OPEN(handle, conn, fname, flags, mode);
#else
			return default_vfs_ops.open(conn, fname, flags, mode);
#endif
			}
		else if ( ( stat_buf.st_size > max_size ) && ( max_size > 0 ) ) { /* file is too large */
			vscan_syslog("INFO: File %s is larger than specified maximum file size! Not scanned!", fname);
			}
		else if ( stat_buf.st_size == 0 ) { /* do not scan empty files */
			vscan_kavp_end();
#if (SMB_VFS_INTERFACE_VERSION >= 6)
			return SMB_VFS_NEXT_OPEN(handle, conn, fname, flags, mode);
#else
			return default_vfs_ops.open(conn, fname, flags, mode);
#endif
			}
		else {
			/* Assemble complete file path */	   
			pstrcpy(filepath, conn->connectpath);
			pstrcat(filepath, "/");  /* is "/" correct? */
			pstrcat(filepath, fname);	   

			/* get client IP */
			safe_strcpy(client_ip, conn->client_address, CLIENT_IP_SIZE -1);

						/* must file actually be scanned? */
						must_be_checked = lrufiles_must_be_checked(filepath, stat_buf.st_mtime);
						if ( must_be_checked == -1 ) {
								/* file has already been checked and marked as infected */
								/* deny access */
								if ( verbose_file_logging )
										vscan_syslog("File '%s' has already been scanned and marked as infected. Not scanned any more. Access denied", filepath);

				/* close socket */
				vscan_kavp_end();

				/* deny access */
								errno = EACCES;
								return -1;
						} else if ( must_be_checked == 0 )  {
								/* file has already been checked, not marked as infected and not modified */
								if ( verbose_file_logging )
										vscan_syslog("File '%s' has already been scanned, not marked as infected and not modified. Not scanned anymore. Access granted", filepath);

				/* close socket */
				vscan_kavp_end();

				/* grant access */
#if (SMB_VFS_INTERFACE_VERSION >= 6)
				return SMB_VFS_NEXT_OPEN(handle, conn, fname, flags, mode);
#else
				return default_vfs_ops.open(conn, fname, flags, mode);
#endif
						}
						/* ok, we must check the file */

			/* scan file */
			retval = vscan_kavp_scanfile(filepath, client_ip);
			if ( retval == -2 && deny_access_on_minor_error ) {
				/* a minor error occured - deny access */
				vscan_syslog("ERROR: daemon failed with a minor error - access to file %s denied", fname);
				vscan_kavp_end();

								/* to be safe, remove file from lrufiles */
								lrufiles_delete(filepath);

								/* deny access */
				errno = EACCES;
				return -1;
						} else if ( retval == -1 && deny_access_on_error ) {
								/* an error occured - can not communicate to daemon - deny access */
								vscan_syslog("ERROR: can not communicate to daemon - access to file %s denied", fname);
				vscan_kavp_end();

				/* to be safe, remove file from lrufiles */
								lrufiles_delete(filepath);

								/* deny access */

								errno = EACCES;
								return -1;
			} else if ( retval == 1 ) {
				/* virus was found */
				/* close socket */
				vscan_kavp_end();
				/* do action ... */

#if (SMB_VFS_INTERFACE_VERSION >= 6)
				rc = vscan_do_infected_file_action(handle, conn, filepath, quarantine_dir, quarantine_prefix, infected_file_action);
#else
				rc = vscan_do_infected_file_action(&default_vfs_ops, conn, filepath, quarantine_dir, quarantine_prefix, infected_file_action);
#endif

								/* add/update file. mark file as infected! */
								lrufiles_add(filepath, stat_buf.st_mtime, True);

				/* virus found, deny acces */
				errno = EACCES; 
				return -1;
						} else if ( retval == 0 ) {
								/* file is clean, add to lrufiles */
								lrufiles_add(filepath, stat_buf.st_mtime, False);
						}
		}

		/* close socket */
		vscan_kavp_end();

	}
#if (SMB_VFS_INTERFACE_VERSION >= 6)
	return SMB_VFS_NEXT_OPEN(handle, conn, fname, flags, mode);
#else
	return default_vfs_ops.open(conn, fname, flags, mode);
#endif
}

#if (SMB_VFS_INTERFACE_VERSION >= 6)
static int vscan_close(vfs_handle_struct *handle, files_struct *fsp, int fd)
#else
static int vscan_close(struct files_struct *fsp, int fd)
#endif
{
	pstring filepath;
		int retval, rv, rc;
	char client_ip[CLIENT_IP_SIZE];

		/* First close the file */
#if (SMB_VFS_INTERFACE_VERSION >= 6)
		retval = SMB_VFS_NEXT_CLOSE(handle, fsp, fd);
#else
		retval = default_vfs_ops.close(fsp, fd);
#endif

		if ( !scan_on_close ) {
				DEBUG(3, ("samba-vscan - close: File '%s' not scanned as scan_on_close is not set\n", fsp->fsp_name));
				return retval;
		}


	/* get the file name */
		pstrcpy(filepath, fsp->conn->connectpath);
		pstrcat(filepath, "/"); 
		pstrcat(filepath, fsp->fsp_name);		

		/* Don't scan directorys */
		if ( fsp->is_directory )
			return retval;


	if ( !fsp->modified ) {
				if ( verbose_file_logging ) 
						vscan_syslog("INFO: file %s was not modified - not scanned", filepath);

		return retval;
	}

	/* scan only file, do nothing */	

	vscan_kavp_init();
	if ( kavp_socket >= 0 ) {
		safe_strcpy(client_ip, fsp->conn->client_address, CLIENT_IP_SIZE -1);
		rv = vscan_kavp_scanfile(filepath, client_ip);
		vscan_kavp_end();
		if ( rv == 1 ) {
			/* virus was found */
#if (SMB_VFS_INTERFACE_VERSION >= 6)
			rc = vscan_do_infected_file_action(handle, fsp->conn, filepath, quarantine_dir, quarantine_prefix, infected_file_action);
#else
			rc = vscan_do_infected_file_action(&default_vfs_ops, fsp->conn, filepath, quarantine_dir, quarantine_prefix, infected_file_action);
#endif
		}

	}
	return retval;
}


#if (SMB_VFS_INTERFACE_VERSION >= 6)
/* Samba 3.0 */
NTSTATUS init_module(void)
{
	NTSTATUS ret;

	ret = smb_register_vfs(SMB_VFS_INTERFACE_VERSION, VSCAN_MODULE_STR, vscan_ops);
	DEBUG(5,("samba-vscan (%s) registered (Samba 3.0), (c) by Rainer Link, OpenAntiVirus.org\n", module_id));
	openlog("smbd_"VSCAN_MODULE_STR, LOG_PID, SYSLOG_FACILITY);

	return ret;	
}
#else
/* VFS initialisation function.  Return initialised vfs_ops structure
   back to SAMBA. */
#if SAMBA_VERSION_MAJOR==3
 /* Samba 3.0 alphaX */
 vfs_op_tuple *vfs_init(int *vfs_version, struct vfs_ops *def_vfs_ops,
			struct smb_vfs_handle_struct *vfs_handle)
#else
 /* Samba 2.2.x */
 #if SAMBA_VERSION_RELEASE>=4   
  /* Samba 2.2.4 */
  struct vfs_ops *vfs_init(int *vfs_version, struct vfs_ops *def_vfs_ops)
 #elif SAMBA_VERSION_RELEASE==2
  /* Samba 2.2.2 / Samba 2.2.3 !!! */
  struct vfs_ops *vfs_init(int* Version, struct vfs_ops *ops)
 #elif SAMBA_VERSION_RELEASE==1
  /* Samba 2.2.1 */
  struct vfs_ops *vfs_module_init(int *vfs_version)
 #else
  /* Samba 2.2.0 */
  struct vfs_ops *vfs_init(int *vfs_version)
 #endif
#endif
{
	#if SAMBA_VERSION_MAJOR!=3
 	 #if SAMBA_VERSION_RELEASE>=4
	  /* Samba 2.2.4 */
	  struct vfs_ops tmp_ops;
	 #endif
	#endif

		openlog("smbd_"VSCAN_MODULE_STR, LOG_PID, SYSLOG_FACILITY);

		#if SAMBA_VERSION_MAJOR==3
		 /* Samba 3.0 alphaX */
		 *vfs_version = SMB_VFS_INTERFACE_VERSION;
		 vscan_syslog("samba-vscan (%s) loaded (Samba 3.x), (c) by Rainer Link, OpenAntiVirus.org", module_id);
		#else
		 /* Samba 2.2.x */
		 #if SAMBA_VERSION_RELEASE>=4
		  /* Samba 2.2.4 */
		  *vfs_version = SMB_VFS_INTERFACE_VERSION;
		  vscan_syslog("samba-vscan (%s) loaded (Samba >=2.2.4), (c) by Rainer Link, OpenAntiVirus.org", module_id);
		 #elif SAMBA_VERSION_RELEASE==2
		  /* Samba 2.2.2 / Samba 2.2.3 !!! */
		  *Version = SMB_VFS_INTERFACE_VERSION;
		  vscan_syslog("samba-vscan (%s) loaded (Samba 2.2.2/2.2.3), (c) by Rainer Link, OpenAntiVirus.org", module_id);
		 #else
		  /* Samba 2.2.1 / Samba 2.2.0 */
		  *vfs_version = SMB_VFS_INTERFACE_VERSION;
		  vscan_syslog("samba-vscan (%s) loaded (Samba 2.2.0/2.2.1), (c) by Rainer Link, OpenAntiVirus.org",
			   module_id);
		 #endif
		#endif


	#if SAMBA_VERSION_MAJOR==3
		 /* Samba 3.0 alphaX */
	 DEBUG(3, ("Initialising default vfs hooks\n"));
		 memcpy(&default_vfs_ops, def_vfs_ops, sizeof(struct vfs_ops));

		 /* Remember vfs_handle for further allocation and referencing of 
		private information in vfs_handle->data
		 */
	 vscan_handle = vfs_handle;
	 return vscan_ops;
		#else
		 /* Samba 2.2.x */
	 #if SAMBA_VERSION_RELEASE>=4
	  /* Samba 2.2.4 */

	  *vfs_version = SMB_VFS_INTERFACE_VERSION;
	  memcpy(&tmp_ops, def_vfs_ops, sizeof(struct vfs_ops));
	  tmp_ops.connect = vscan_connect;
	  tmp_ops.disconnect = vscan_disconnect;
	  tmp_ops.open = vscan_open;
	  tmp_ops.close = vscan_close;
	  memcpy(&vscan_ops, &tmp_ops, sizeof(struct vfs_ops));
	  return(&vscan_ops);

	 #else
		  /* Samba 2.2.3-2.2.0 */
		  return(&vscan_ops);
	 #endif
	#endif
}


#if SAMBA_VERSION_MAJOR==3
/* VFS finalization function */
void vfs_done(connection_struct *conn)
{
		DEBUG(3, ("Finalizing default vfs hooks\n"));
}
#endif

#endif /* #if (SMB_VFS_INTERFACE_VERSION >= 6) */

كفاية كدة النهاردة كما عشان أن عاوز أنام بجد أنا زعلان منكم ..........مفيش حد يقولي حته أية الكلام الفارغ الي أنتي بتقولة دة

ماشي

ونلتقي بعد الفاصل وأبقوا قابلوني لو عدنا...........

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#6

أخوى عن جد رائع والله ربنا يكرمك ويوفقك ويا رب تستمر فيه بجد موضوع رائع ومهم

أتمنى انك تكمله

واتمنى لك التوفيق والتقدم الدائم باذن الله

السلام عليكم

[وسط][يمين] [وسط]الأسم :أحمد فوزى أحمد حسن النجار

المؤهل الدراسى بكالريوس

حاصل على الشهادات دولية التالية من ميكروسوفت : MCP MCAD MCSD MCTS

اعمل على Vb.net & asp.net & asp

2005 & 2003

وعلى ال Java and vb scripts

الموبايل من خارج مصر: 0020128031164

من داخلها فقط دون كود الدولة:0128031164

الأيميل: ahmed_elnagar32@hotmail.com

الموقع الرسمى: http://www.alzahaby.com

الموقع مغلق مؤقتا للنقل لسرفر افضل

[/يمين][/وسط][/وسط]

#7

عدنا .............. عشان الاستاذ أحمد فوزي

شكرا لك أخي أحمد علي ردك

وأرجو أن نستمر معا لا أستمر وحدي

وبمناسبة أننا عدنا

إليكم هذا الكود والوصلة والهدف من هذة الاكواد هو الاستعانة بها وليس لصقها ولذقها

هنا الرابط

وهنا الكود وأظن أننا كدة محتاج حد يشجعني ويقولي إية الشفرات دي بتقول أية و أذاي نحلها مع بعض ونعمل علي تسهيليا

مستني رددكم

/* 
 * $Id: vscan-fprotd_core.c,v 1.27 2003/06/18 10:19:52 mx2002 Exp $
 *
 * Core Interface for F-Prot Antivirus Daemon			
 *
 * Copyright (C) Rainer Link, 2001-2003
 *			   OpenAntiVirus.org <rainer@openantivirus.org>
 *
 * Credits to W. Richard Stevens - RIP
 * 
 * This software is licensed under the GNU General Public License (GPL)
 * See: http://www.gnu.org/copyleft/gpl.html
 *
*/

#include "vscan-global.h" 
#include "vscan-fprotd_core.h"

/* hum, global vars ... */
extern BOOL verbose_file_logging;
extern BOOL send_warning_message;
extern fstring fprotd_ip;
extern pstring fprotd_port;
extern fstring fprotd_args; 



/* initialise socket to F-Prot Daemon 
   returns -1 on error or the socket descriptor */
int vscan_fprotd_init(void)
{

	int sockfd;
	struct sockaddr_in servaddr;
	static pstring ports;
	fstring port;
	const char *p;

	/* create socket */
		if (( sockfd = socket(AF_INET, SOCK_STREAM, 0)) < 0 ) {
			   vscan_syslog("ERROR: can not create socket!");
			   return -1; 
		}

	bzero(&servaddr, sizeof(servaddr));
		servaddr.sin_family = AF_INET;

	/* hm, inet_pton may not exist on all systems - FIXME ! */
		if ( inet_pton(AF_INET, fprotd_ip, &servaddr.sin_addr) <= 0 ) {
				vscan_syslog("ERROR: inet_pton failed!");
				return -1;
	}

	/* next_token modifies input, so make a copy */
	pstrcpy(ports, fprotd_port);
	/* hum, needed to avoid compiler warning ... */
	p = ports;
	while ( next_token(&p, port, ";", sizeof(port)) ) {
		servaddr.sin_port = htons(atoi(port));
		/* connect to socket */
		if ( connect(sockfd, (struct sockaddr *) &servaddr, sizeof(servaddr)) < 0 )
			{
					vscan_syslog("ERROR: can not connect to F-Prot Daemon (IP: '%s', port: '%s')!", fprotd_ip, port);
			/* let's go sleeping for 1 second */
			/* sleeping causes too much slowdown */
			/* sleep(1); */
			} else {
			/* OK, we got a connection. */
			return sockfd;
		}
	}

	/* Uh, no connection was possible */
	return -1;
}

/*
  If virus is found, logs the filename/virusname into syslog
*/
void vscan_fprotd_log_virus(char *infected_file, char *result, char* client_ip)
{
	char *str;
	size_t len;

	/* remove "<name>" and "</name>"from the result string to get only the virus name - hack alert;) */

	/* some sanity checks ... */
	len = strlen(result);
	if ( len < 8 ) {
		/* hum, sth went wrong */
		vscan_syslog_alert("ALERT - Scan result: '%s' infected with virus 'UNKNOWN', client: '%s'", infected_file, client_ip);
		if ( send_warning_message )
			vscan_send_warning_message(infected_file, "UNKNOWN", client_ip);

	} else {
		str = result;
		str+= 6;
		str[strlen(str)-8] = '';

			vscan_syslog_alert("ALERT - Scan result: '%s' infected with virus '%s', client: '%s'", infected_file, str, client_ip);
		if ( send_warning_message )
			vscan_send_warning_message(infected_file, str, client_ip);

	}

}



/*
  Scans a file (*FILE*, not a directory - keep that in mind) for a virus
  Expects socket descriptor and file name to scan for
  Returns -2 on minor error,  -1 on error, 0 if no virus was found, 
  1 if a virus was found 
*/
int vscan_fprotd_scanfile(int sockfd, char *scan_file, char* client_ip)
{
	char recvline[MAXLINE + 1];
	pstring fprotdCommand;	/* the command line to be send to daemon */
	char *str;
	FILE *fpin, *fpout;
	BOOL received_data = False; /* indicates, if any response from deamon was received */

	/* open stream sockets */
		fpin = fdopen(sockfd, "r");
		if ( fpin == NULL ) {
				vscan_syslog("ERROR: Can not open stream for reading - %s", strerror(errno));
				return -1;
		}

		fpout = fdopen(sockfd, "w");
		if ( fpout == NULL ) {
				vscan_syslog("ERROR: Can not open stream for writing - %s", strerror(errno));
				return -1;
		}


	if ( verbose_file_logging )
			vscan_syslog("INFO: Scanning file : '%s'", scan_file);

	/* F-Prot Daemon expects "GET <filename>[?<arguments>] HTTP/1.0\r\n\r\n" */
	/* what about if the <filename> itself contains '\n'? */
		pstrcpy(fprotdCommand, "GET ");
		pstrcat(fprotdCommand, encode_string(scan_file));
	pstrcat(fprotdCommand, "?");
	pstrcat(fprotdCommand, fprotd_args);
		pstrcat(fprotdCommand, " HTTP/1.0\r\n\r\n");

	/* write to socket */
	/* NOTE: what happens if scan_file is very long? */

	if ( fputs(fprotdCommand, fpout) == EOF ) {
		vscan_syslog("ERROR: can not send file name to F-Prot Daemon!");
		return -1;
	}

	/* hum, instead of flush()ing, use setvbuf to set to line-buffering? */
		if ( fflush(fpout) == EOF ) {
				vscan_syslog("ERROR: can not flush output stream - %s", strerror(errno));
		/* better safe than sorry ... */
		return -1;
		}


	/* read from socket, line by line */
	setvbuf(fpin, (char *)NULL, _IOLBF, 0);
	/* setlinebuf(fpin); */

	while ( (fgets(recvline, MAXLINE, fpin)) != NULL ) {

		received_data = True;

		/* ignore the HTTP response header, remove any leading 
		   white spaces */
		str = NULL;
		str = strchr(recvline, '<');
		if ( str != NULL ) {
			if ( strncmp(str, "<name>", 6) == 0 ) {
				/* virus found */
				vscan_fprotd_log_virus(scan_file, str, client_ip);
				return 1;
			} else if ( strncmp(str, "<error>", 7) == 0 ) {
				/* ERROR */
				if ( verbose_file_logging )
					vscan_syslog("ERROR: file %s not found, not readable or an error occured", scan_file);
				return -2;
			}
		}
	}

	/* did we receive any data from daemon? */
	if ( !received_data ) {
		vscan_syslog("ERROR: can not get result from F-Prot Daemon!");
		return -1;
		 } else {

	 	/* OK */
		if ( verbose_file_logging )
				vscan_syslog("INFO: file %s is clean", scan_file);
	}

	return 0;
}


/*
  close socket
*/
void vscan_fprotd_end(int sockfd)
{
	/* sockfd == -1 indicates an error while connecting to socket */
	if ( sockfd >= 0 ) {
		close(sockfd);
	}

}

نعود بعد الفاصل ............

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#8

عدنا ...................

وطبعا هتدورو علي ال vscan-global.h

أن هقولكم هي فين

هنا هذا الرابط

#ifndef __VSCAN_GLOBAL_H_
#define __VSCAN_GLOBAL_H_

#include <includes.h>

#include "vscan-config.h"

#include "vscan-functions.h"
#include "vscan-fileaccesslog.h"
#include "vscan-message.h"
#include "vscan-quarantine.h"
#include "vscan-filetype.h"
#include "vscan-parameter.h"
#include "vscan-scan.h"
#include "vscan-fileregexp.h"

#define CLIENT_IP_SIZE 18

#ifndef HAVE_ATOLL
# ifdef HAVE_LONG_LONG
#  ifdef HAVE_STRTOLL
#   define HAVE_ATOLL_REPLACEMENT
long long	   atoll (const char *str);
#  else
#   ifdef HAVE_ATOQ
#	define HAVE_ATOLL_REPLACEMENT
long long	   atoll (const char *str);
#   endif
#  endif
# endif
# ifndef HAVE_ATOLL_REPLACEMENT
#  ifdef HAVE_LONG_LONG
long long	   atoll (const char *str);
#  else
long	atoll (const char *str);
#  endif
# endif
#endif

/* Configuration Section :-) */

#ifndef SYSLOG_FACILITY
#define SYSLOG_FACILITY   LOG_USER
#endif

#ifndef SYSLOG_PRIORITY
#define SYSLOG_PRIORITY   LOG_NOTICE
#endif

/* virus messages will be logged as SYSLOG_PRIORITY_ALERT */
#ifndef SYSLOG_PRIORITY_ALERT
#define SYSLOG_PRIORITY_ALERT   LOG_ERR
#endif

/* end configuration section */

#endif /* __VSCAN_GLOBAL_H */

ونلتقي غدا أن شاء الله

وأن لم أستطع فموعدنا الثابت سوف يصبح يوم الجمعة

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#9

انا اقرا ا لموضوع ولا فهمت ولا شي

#10

المهم أخي أنك تتحمس مش تفهم الاكواد دي كلها ولكن يبدون أن هذة الاكواد ليست بالصعوبة التي تجعلنا منفهمهاش

علي العموم الموضوع لسة مابتداش لو كنت عاوز تفهم أو تتفهم تواصل معنا في الموضوع

وشكرا لك أخي

بعد الفصال ""شرح فكرة عمل البرنامج المقترحة --- أنتظرونا

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#11

حنسا لقد عدنا بعد أن قرات موضوع "وداعا للسي + + " قلت وداعا للمشروع

ولكن بعد النقاش الذي دار حول هذا الموضوع

قلت "أعتذر للغة الجميلة "السي / سي بلس بلس "

ولما كنت بفكر في أليات عمل البرنامج المضاد للفيروسات

، ولمل ملقيتش حد يرض عليا

بدأت أفكر لوحدي تاني ،، بس لو كل وأحد فكر لوحدة تفتكروا هيكون فية نتيجة

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#12

أصابني الاحباط من عدم المشاركة

لذلك

وعندا فيكم "لهجة مصرية "

سوف أستمر بتقديم هذا الموضوع

أبقوا معن في الموضوع بعنوان

المرحلة الاول في برنامج مضاد الفيروسات - آلية العمل و المشاكل المقترحة

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#14

السلام عليكم ورحمة الله و بركاته

سادلي بدلوى دون تحفظ

اقتباس
لقد بحثت كثرا في الانترنت علي مراجع أو دوال أو أي شيئ يفيد في هذا الموضوع بالذات فكانت النتيجة = 0

لست جيدا في البحث، تعلم كيف تبحث اولا

اقتباس
أستخدمات تقنيات متقدمة في البحث " سرية جدأ وبعيداً عن جوجل و يا هو " وجدت بعد المصادر والاكواد المفية المفتوحة المصدر أرجو أن تكون مفيدة لكم

http://www.koders.com

بحث ووجدت موقع kODERS !!! كنت تبحث عن اكواد جاهزة

البحث يكون عن افكار، عن DOC وليس اكواد

اقتباس
سوف أكتب لكم كود بلغة الـ pril الهدف منهة التوضيح لا أكثر

ماهي pril هذه ؟ انسيت انك في قسم C

اقتباس
ولما دورت أكتر وأكتر

لقيت أكتر وأكتر

لقيت الكسبرسكي بنفسة واقف في سكتي بيقول "أنت كنتم نايمين ولة أية أنا هنا من زمان "

http://www.koders.com

لا زلت في موقع kODERS ؟؟؟

ثم لماذا لم ترفق الكون في ملف بدلا من تنشرها هاكذا

ياخذ مساحة كبيرة من الموضوع...

اقتباس
وفي عودتنا أحب أكتب " أهداء الي بابا وما وكل الاسرة والمقيمين وأهل طنطا وعلي المقيمين خارج

واعلمكم ان عباس خرج من الجيش و...

{
	#if (SAMBA_VERSION_MAJOR==2 && SAMBA_VERSION_RELEASE>=4) || SAMBA_VERSION_MAJOR==3
	 #if !(SMB_VFS_INTERFACE_VERSION >= 6)

عن اي نظان تتحدث ؟؟؟؟ هذا الكود خاص ب Linux

اقتباس
أصابني الاحباط من عدم المشاركة

مشاركة في ماذا ؟ الموضوع اكواد مثناشرة هنا وهناك، اتسائل ان كنت اننت اصلا فاهم محتواها، عن جد

انظر من حولك يا اخي

اكتب شيئ جاد وواضح وابعد ان اكواد غيرك

d4baa0.gif
#15

أحب "عدم التحفظ" منك :)

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#16

وبدو أي تحفظات

أرحب بكلامك أخي بشدة

ولكن هلي الحقيقة هي ما تراة عينيك أم أن عينك تخدعك

نعم لقد خدعتك عينك مرتين

فقبل أن أكون أو كما أعتبر نفسي "متعلم وباحث في لغات البرمجة " أنا كاتب صحفي و أدبي

وأستطيع أن أتشكل بالقلم كما أتخيل فأنا لا أضع حاجز لنفسي

ثانيا : وحيث أني أعتبر كل الحياه أمور شخصية

لا أتفق معك

في أمرين الاول : أني في بداية طرحي لموضوع "مشروع البرنامج " كانت هناك بدية محبطة

وأير إلي هذة البداية لا لكي أشير الي الاحباط ولكن لكي أشير إلي

أمر مهم هو أني ركزت في الموضوع أن يكون من تفكيرانا لا تكون من أكواد جاهزة

ثانيا : أني طرحت الموضوع في 3 موضوعات أنت الان في موضوع المنتصف

فلو قرأت موضوع المرحلة الاولي الذي يلي هذا الموضوع

ستجد أني بدأت أطرح الافكار النظرية في خطوات عمل البرنامج بطرق لم يتم تطبقها علي أي برنامج في هذا المجال من قبل "أنصح بقرأة الموضوع من البداية إلي النهاية قبل التعليق

وأرجو أن تلاحظ أني كنت أستخدم اسلوب التسجيل المعملي لكل لحظة من لحظات العمل ففي البدية

قلت أني لم أجد نتيجة

ففعلا عندما تسخدم محركي البحث Google and yahoo لن تجد نتيجة فأسخدمت غيرهما فوجدت نتيجة ولم أيأس

وكن الهدف من هذا الامر أن أحث القارء علي عدم اليائس

ثانيا :"لاحظ ستجد كل النقاط تندرج تحت بند ثانيا فانا لا أعرف العدد لاكثر من ذلك "

بدأت أذكر الاكواد لكي أحث كل من أعتقد في المستحيل أن المستحيل ليس موجود أصلا إلا أذا أراد الانسان وجودة

فلم تكن منظمة فأردت أقول بها "أن كان هناك أنسان يفكر بهذه الطرقة ونحن بالطبع بشر لماذا لا نكون أفضل من هذا الانسان

وكان هذا الاسلوب كلة في أعطاء المعلوات بسبب حماستي الشدية

ولكن بعد عدة أيام من المشاركات غير الفعالة "وأريد أن أذكر المستخدم العربي أن المدونات والمنتديات وجدت أصلا لمشاركة الافكار والاقتراحات "

وليست لتبادل النقد فالنقد بدون تقويم وتصحيح يكون نقدا للنقد لا أكثر

فماذا يحدث لو قلت لي مثلا :

"""""""""""""

أخي أعتقد أنك تسير في الطريق الخاطئ والصحيح هو كذا وكذا ....

"""""""""""""""

أرجو قراة باقي الموضوع وأن تتسع دائرة النقاش علي أن يكون نقاشا لا يكون تعليقا علي الوضوع

ثم أني في بدية هذة المبادرة دعوت كل من يريد أن يقدم للمجتمع التقني العربي ولم أقدمه للمتخصصين فقط

فالهدف تعليمي من الدرجة الاول

تعاوني من الدرجة الثانية

وبالمناسبة لقد كان كو الـ pirl ذلك من أجل التوضيح وأيضا كان هذا أول نتيجة عثرت عليها أولا

أرجو أن تكون قد فهمت ما أبغي

وأن أكون واضحاً

فقد كانت البدية أنتاج برمجية عربية

أقرا البداية والنهاية ثم أقترح حلاً

المقدمة

المرحلة الاولي

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#17
اقتباس
فقبل أن أكون أو كما أعتبر نفسي "متعلم وباحث في لغات البرمجة " أنا كاتب صحفي و أدبي

هذا لايعني لي شيئ،

فلو كنت جيدا لكتبت Perl ولم تكتب Pirl

اقتباس
ا أتفق معك

في أمرين الاول : أني في بداية طرحي لموضوع "مشروع البرنامج " كانت هناك بدية محبطة

قلت لك: اكتب شيئ جدي وواضح تجد تجاوب، وليس انشاء دون مغزى...

اقتباس
ثانيا : أني طرحت الموضوع في 3 موضوعات أنت الان في موضوع المنتصف

فلو قرأت

يا حبيبي انا اطلعت على المواضيع الثلاث قبل ان اكتب رد

والنتيجة صفر على الشمال

اقتباس
ستجد أني بدأت أطرح الافكار النظرية في خطوات عمل البرنامج بطرق لم يتم تطبقها علي أي برنامج في هذا المجال من قبل

اخطبوط وعنكبوت! يا حبيبي اطلع على مؤلفات LUDWIG قبل ان تتحدث

اقتباس
ففعلا عندما تسخدم محركي البحث Google and yahoo لن تجد نتيجة فأسخدمت غيرهما فوجدت نتيجة

باستخدام google فقط يمكنك ايجاد اي شيئ، وان لم تجد فتعلم كيف تبحث

اخي بدون اي ثرثرة وكلام فقط

اختر اي فيروس تريد وسابرمج لك مضاد له كهدية عيد الفطر ان شاء الله

d4baa0.gif
#18

كل عام وانت بخير

بمنصبة رمضان شهر الرحمة والمغفرة والعتق من النار

كل عام وانت مبرمج قادر علي أنت تفيد المسلمين

كل عام وانت في أحن حال والامة المسلمة ........ آمين يارب العالمين

:o أحب أعن أعبر لك عن ذهولي من ردك فقد ذكرت في آخر الرد أنك تستطيع أن تقدم مضاد قبل نهاية الشهر الكريم

حسنا وأنا مستمتع جدا من هذا الكلام وسوف أعتبرة وعد من عضو كبير في هذا المنتدي بتقديم هذا العمل والجهد في سبيل الاسلام "نعم أخي ما سوف تقوم بة نوع من الجهاد " أرجو من الله أن يثيبك علي عملك

وعلي العموم نحن في أنظار هذة النتائج بعد 21 يوم فقط

وأرجو أن ترفق لنا الكود وأيضا بعض المراجع التيأستفدت منها وأرجو أن تشرح لنا طريقة عمل البرنامج وفكرة بنائة

وأعتذر عن perl وشكراً لك أخي وفي أنتظار ردك الكريم

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#19

xdata لا تفهمني خطأ

لم اقل مضاد لكل الفيروسات

فالفيروسات الحالية بكل عائلاتها ومتغيراتها اكثر من نصف مليون

انا قلت مضاد لفيروس واحد فقط، وانت تختاره

d4baa0.gif
#20

حسننا أخي ا يهمني أسم الفيروس أختر أنت الفيرس وأصنع المضاد علي

أن توثق الطريقة التي سوف تعمل بها من البداية

وسوف نقوم برفعها علي المنتدي كموضوع مثبت

وسوف أقوم بوضعا بأسمك علي موقع ع الانتر نت

بهدف النشر بين العرب

وشكراً أخي وعلي العموم أنا في أنتظار ردك

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#21

افظل ان تختار انت

حتى لا ياتي احد فيما بعد ويقول : اخترت فيروس سهل

لا يهم الفيروس منتشر او غير منتشر، سهل او صعب

المهم ان احصل على نسخة منه

d4baa0.gif
#22

السلام عليكم مرة أخري

لا أعرف ما أقول "لسنا في حالة تحدي " و أنت تصر علي ذلك

أنا أريد العلم

وعلي كل حال أعتقد أن الديدان بشكل عام تشكل خطرا علي الحواسيب ما رأيك أن تكون هدفك

worm

وفقق الله الي ما يحبه ويرضاه

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#23

worm ينتشر عبر الشبكة والبريد و...

اريد Virus حتى اكتب له مضاد Removal tool

d4baa0.gif
#24

حقيقة لا أفهم ما تريد أن تقول أتريد أن أذكر لك أسم فيروس بعينة أم نوع من الفيروسات

ومن المواضح أنك سوف تتعامل معة كملف تبحث عنة وتقوم بتدميرة

ولكن أخي ما أنت بصددة ليس مضاد حتي لاي شيئ أنة لا يتعي برنامج عضير بهدف معين

علي العموم حدد أهدافك وأصنع برنامجك وأن شاء الله نستفيد جميعاً

قال رسول الله صلى الله علية وسلم ( خير الناس من طال عمره وحسن عمله ) صدق رسول الله صلي الله علية وسلم

http://freelive.freehostia.com

#25

ساشرح

لديك فيروس Virus دخل جهازك

المضاد هو برنامج يعمل عكس الفيروس

اي يقوم بعكس تغييرات الفيروس

ليس بالبحص عنه وحذفه فقط بل باستئصاله من الملفات المصابة

قلت فيروس واحد لان تحليل وبرمجة مضاد لكل الفيروسات يتطلب وقت كبير

d4baa0.gif

هذا الموضوع مغلق.

مواضيع مشابهة