Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

UPX compression may cause false positives with virus scanners #32

Open
mpkorstanje opened this issue Nov 5, 2022 · 2 comments
Open

Comments

@mpkorstanje
Copy link
Contributor

mpkorstanje commented Nov 5, 2022

It seems like the issue is not that it's a go executable but that its additionally with reduced with UPX. At lest my current understanding. And I wonder if it's necessary.

Originally posted by @tobmaster in #23 (comment)

I don't know much about Go or UPX or how this project is build.

If someone can:

  • verify that UPX is the the root cause of the false positives;
  • and remove UPX from the build process

Then I can see it released.

@tobmaster
Copy link

Sorry it took so long but it slipped through my attention.

Problem is that UPX packaged executables are often blocked by company virus scanners and proxies. Its cause its often used by hackers to mask their malicious payloads (its another discussion for sec people if that should be an issue but now it is for companies using the formatter)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants