-
-
Notifications
You must be signed in to change notification settings - Fork 998
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
1 changed file
with
0 additions
and
9 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
b496aad
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why you deleted the ELF header?? Without it the rule is useless. And this is Linux ELF binary injection. I am proposing a revoke for your changes: master...unixfreaxjp:patch-1
@jovimon
Cc @mmorenog @Xyl2k
b496aad
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
https://github.com/Yara-Rules/rules/blob/master/malware/000_common_rules.yar#L10 It is still here, they just moved it to a more generic location so it can be used for more than your rules ;)
b496aad
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
At least. commenting something is expected on deletion, we don’t do telepathic communication in gitland..
b496aad
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You are right, should have explained it better but was quite in a hurry.
Will add a banner later on the affected rules.
Sorry for the inconvenience and thanks @Maijin for answering.
b496aad
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@jovimon was wondering, isn't YARA already able to check for header via the ELF module http://yara.readthedocs.io/en/v3.7.1/modules/elf.html ?