Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Virustotal says that linux version of youtube-dl needlessly contacts certain ip/domains while .exe version doesn't #22151

Closed
MystesofEternity opened this issue Aug 19, 2019 · 5 comments
Labels

Comments

@MystesofEternity
Copy link

@MystesofEternity MystesofEternity commented Aug 19, 2019

Checklist

  • I've verified that I'm running youtube-dl version 2019.08.13
  • I've checked that all provided URLs are alive and playable in a browser
  • I've checked that all URLs and arguments with special characters are properly quoted or escaped
  • I've searched the bugtracker for similar bug reports including closed ones
  • I've read bugs section in FAQ

Citings and Remarks

Latest youtube-dl binary for Linux. Click Relations tab for reference on what I am saying

https://www.virustotal.com/gui/file/85a15c9c7394147105b3015964f975ca34770038b06e5edd40389413cac44b2d/relations

Malicious domain being contacted by the binary as said by VirusTotal. Note that I haven't personally tested it as I do not have a test lab in place just yet. Click Relations tab for a look at the graphs that include this domain in their analysis.

https://www.virustotal.com/gui/url/1254637991d7e0ef7103662d56a239deb7ac8371edf6ff64e035c35b7f6696ef/relations

Latest youtube-dl binary for Windows. Click Relations tab to see just how clean this is compared to the binary for Linux.

https://www.virustotal.com/gui/file/afc92ad007e8101b73c2dcff8c7d54c0ad75c124d0b9cb07dfddb845b9958dfa/relations

Description

While I know there is a possibility that the connections in the linux binary is just a false positive due to flawed linux binary testing of VirusTotal, I'd prefer to be really sure anyways given the fact that a supply-chain attack is certainly not an impossible feat.

@dstftw
Copy link
Collaborator

@dstftw dstftw commented Aug 19, 2019

Bother to even read what does Execution Parents in Relations does mean.

@dstftw dstftw closed this Aug 19, 2019
@dstftw dstftw added the invalid label Aug 19, 2019
@MystesofEternity
Copy link
Author

@MystesofEternity MystesofEternity commented Aug 19, 2019

@dstftw Execution parents doesn't matter because those are only files that include/execute youtube-dl for their own purposes like say packing an open-source program into a much bigger program.

What do you need from me to make this more "acceptable" for your examination? This is a serious case with a possibility that your linux binaries are poisoned.

@MystesofEternity
Copy link
Author

@MystesofEternity MystesofEternity commented Aug 19, 2019

This portion is the one that matters.
Matters

@dstftw
Copy link
Collaborator

@dstftw dstftw commented Aug 19, 2019

youtube-dl does not connect to these locations on its own. These are standard macOS call homes.

@MystesofEternity
Copy link
Author

@MystesofEternity MystesofEternity commented Aug 19, 2019

Oh I see, upon noticing that I could view the whole report I can see that it was indeed executed in macOS
Thanks for the heads-up, I suppose that means everything's good as it is

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
2 participants
You can’t perform that action at this time.