[clamav-users] Unable to submit false positive for bug54682.phpt PHP.Exploit.CVE_2011_4153-3

Greg Folkert greg at donor.com
Fri May 9 18:48:05 UTC 2014


On Fri, 2014-05-09 at 14:17 -0400, Bill Bennert wrote:
> Hi Alain,
>   I greatly appreciate your time in confirming this. In response, I did
> some additional research and understand that it is a true positive since
> the file runs a test for that exact condition. Would white-listing it
> using a file signature hash be valid measure, or would that a bad idea?
> This is the first time I've encountered a true positive on a file I
> would normally keep and want to make sure I handle it appropriately.

Why would you do this in the first place. You are unquestionably
guaranteeing a True-Positive to get through. That could be exploited...
or not.

Just make sure you realize what you are doing, not having blinders on.
-- 
greg folkert - systems administration and support
web:    donor.com
email:  greg at donor.com
phone:  877-751-3300 x416
direct: 616-328-6449 (direct dial and fax)
"It is quality rather than quantity that matters."
    -- Lucius Annaeus Seneca




More information about the clamav-users mailing list