-
Notifications
You must be signed in to change notification settings - Fork 16
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Virustotal gives hits for misp-2.4.139-1.el7.rpm #45
Comments
There are a set of malicious files to test viper. It's most probably what it is triggering VT detection.
|
Maybe the test_files could be removed just before the final build of the RPM. @amuehlem what do you think? |
Great Idea, I'm excluding these files during the RPM build process |
Thank you for the hint and the tip to remove this files. The 2.4.140 does not contain the viper-test-files. |
Just checked the new version 2.4.140 and it is better, there is still files called mail_1.msg, mail_1_bom.eml and mail_1.eml in folder email_testfiles which are detected Trojan-Downloader:JS/Kavala.V. Can you build one more version? |
I've excluded this files as well, new RPM misp-2.4.140-2.el7.noarch.rpm @adulau is it a good idea to exclude all files from /PyMISP/tests/? |
Sure. The tests are not used for MISP in production. We can safely remove those. Thanks a lot. |
misp-2.4.140-3.el7.noarch.rpm is uploaded to the repository |
Thank you, there is no issues anymore. |
Hi All, I had a similar issue with Defender detecting the test files and other files as malware which I raised here: Can someone please confirm if this is expected and if the installation of MISP via docker is safe? Many thanks |
It is maybe false positive:
https://www.virustotal.com/gui/file/86d06c191d1943831dd567bc03c0f5a0220efa88ef7a641e03e802898019fc12/detection
CVE is 2013-5331
Regards,
Ville
The text was updated successfully, but these errors were encountered: