ConfigServer Services HelpDesk
Server Management Services from Way to The Web Ltd
ConfigServer Home Page

Temporary Closure

We are taking a short break and will close the store, helpdesk and email from 17:00 GMT on Tuesday, 16h April to 09:00 Thursday, 25th April 2024.

If you purchase a license or Service Package before the closing date and require installation, please be sure to leave at least 24-48 hours before then for the work to be done. Otherwise, any work will be scheduled for after this period. We will reopen on Thursday, 25th April 2024.


How can I add a file so that cxs will detect it?

Support Portal  »  Knowledgebase  »  Viewing Article

  Print
First you should run cxs directly against the file and ensure that it is NOT detected by either the fingerprint or virus option:

cxs /path/to/file
If it is not detected and you believe it is an exploit, you can submit the files to us using the --wttw option and we will examine them to determine whether they should be added to the fingerprint database.

Please do NOT:
1. Send exploits that are detected by cxs using the default options
2. Send exploits that are detected by ClamAV
3. Send excessive numbers of exploit examples
4. Send HTML defacement injections (e.g. iframe injections)
5. Send files unless you are sure they are exploits

Alternatively or in the meantime, you can create your own fingerprints for them - information is in the cxs documentation under the option --MD5.

For example, if you have a file called exploit.php that you want to add to the fingerprints, do the following:

md5sum exploit.php
You'll get something like this:

28f2623f836e5376bbd81782fda1be29 exploit.php
Add the following to /etc/cxs/cxs.xtra:

md5sum:28f2623f836e5376bbd81782fda1be29
And make sure that you add this to your command line in the cxs script files that you are using for scanning (cxsftp.sh, cxscgi.sh, cxswatch.sh):

--xtra /etc/cxs/cxs.xtra
For instance, if your cxs command line in cxscgi.sh is this:

/usr/sbin/cxs --quiet --cgi --smtp --mail root -Q /home/quarantine --qoptions Mv "$1"
You should change it to:

/usr/sbin/cxs --quiet --cgi --smtp --mail root -Q /home/quarantine --qoptions Mv --xtra /etc/cxs/cxs.xtra "$1"
If you are running cxswatch it is best to restart it when you make changes to cxs.xtra or cxs.ignore.

Share via

Related Articles


Self-Hosted Help Desk Software by SupportPal
© ConfigServer Services