-
Notifications
You must be signed in to change notification settings - Fork 232
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
maldetect + ClamAV false Positive #87
Comments
We are getting the same alerts from ClamAV after having installed MalDectect 1.5:
Codes found here at github.com/rfxn/linux-malware-detect/ and on github.com/waja/maldetect are both unsettling (and identical):
Why these two repositories and how can we be sure that these are only false positives ? |
I have the same issue: /usr/local/maldetect/clean/gzbase64.inject.unclassed: {HEX}gzbase64.inject.unclassed.15.UNOFFICIAL FOUND |
I have received the same issue on LMD 1.5 and ClamAV .99 (Yum EPEL Repo Install):
I have even excluded the directory in ClamAV Config and the daily ClamAV scan still reports it:
Is this bug report even being followed by LMD? This has been going on for a while now. Thanks, |
Folks, |
Not a good idea to let a scanner do own files when doing scan. Do dis: Result gonna give you only intruders in Linux (Nevertheless a scan is more than just running for "intruders". It gives nature of system files to learn about'em) |
/usr/local/maldetect/clean/gzbase64.inject.unclassed
and
/home/my_username/maldetect-1.5/files/clean/gzbase64.inject.unclassed
http://forum2.aimoo.com/computerhelp/category/Injection-Attack-on-Linux-System-1-1020626.html
and
http://xmodulo.com/how-to-detect-malware-on-linux.html
The text was updated successfully, but these errors were encountered: