-
-
Notifications
You must be signed in to change notification settings - Fork 22
Open
Description
Scanning UPX-compressed executables does not make sense unless they could be unpacked first.
See https://en.wikipedia.org/wiki/UPX
For instance these PostgreSQL installers take a large amount of resources and time to scan.
And there is little to squeeze out of the raw binaries.
- One is a large statically-linked ELf http://get.enterprisedb.com/postgresql/postgresql-9.4.1-1-linux-x64.run for Linux.
- The other a Windows exe from http://get.enterprisedb.com/postgresql/postgresql-9.4.1-1-windows-x64.exe
They are not really archives but exe hence the reason why they are still scanned for now.
We will need to figure out a way to avoid issues when dealing with these large binaries that cannot yield much when scanned.
Both are compressed with UPX which makes their binary completely opaque short of decompressing them assuming they are using a standard UPX compressor.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels