<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=6043&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / malware on devuan repos or false positives?]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=6043</link>
		<description><![CDATA[The most recent posts in malware on devuan repos or false positives?.]]></description>
		<lastBuildDate>Mon, 23 Oct 2023 09:02:00 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=45022#p45022</link>
			<description><![CDATA[<div class="quotebox"><cite>xinomilo wrote:</cite><blockquote><div><p>yes, you&#039;re missing something, &quot;1st message on devuan mirror files&quot; is more accurate.</p></div></blockquote></div><p> Understood thanks.</p><p>PS. You are needlessly offended.<br /> From my own experience, I accept the skepticism of my colleagues. I stopped checking my home desktop with all sorts of сheckroot, etc. because over the years I have never seen any suspicious programs. As I understand it, home users have little interest in hackers, and if something gets into the distribution, there are more qualified people who will make a fuss.<br />&#160; <br /> Devuan is more of a distribution for enthusiasts than for cooperative or business use, security requirements and the risk of hacking are probably lower.<br />But that&#039;s just my opinion.</p><p> Regards.</p>]]></description>
			<author><![CDATA[dummy@example.com (aluma)]]></author>
			<pubDate>Mon, 23 Oct 2023 09:02:00 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=45022#p45022</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=45021#p45021</link>
			<description><![CDATA[<div class="quotebox"><cite>xinomilo wrote:</cite><blockquote><div><p>not sure, what i expected in the 1st place, from a <strong>nazi friendly</strong> environment</p></div></blockquote></div><p>Wait... What?</p><p>If I can gauge the political talks on here over the years, I would say there&#039;s a lot more clamoring support for Antifa/BLM, mask and vaccine mandates, and anti-capitalism/pro-socialism. In fact, it&#039;s very common to refer to a user as &quot;they/them&quot;, which means the individual probably believes in the &quot;gender&quot; fallacy. If these folks are &quot;Nazis&quot; to you, then I&#039;m your worst nightmare. <img src="https://dev1galaxy.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><p>Anyway, you are not helping your situation by getting defensive here. Others have tried to explain to you that everything you&#039;ve described is fairly normal and not any evidence for concern. You&#039;re also not doing it right by using ClamAV, which is for finding <em>Windows</em> viruses (not so much GNU/Linux or even another Unix/Unix-like OS). In all reality, if you are that paranoid about security, you should probably start looking into using OpenBSD, as it is a much smaller attack target compared to GNU/Linux or macOS (and these two are less of a risk compared to Windows).</p>]]></description>
			<author><![CDATA[dummy@example.com (brocashelm)]]></author>
			<pubDate>Mon, 23 Oct 2023 08:59:08 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=45021#p45021</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=45019#p45019</link>
			<description><![CDATA[<p>in general, <br />if everyone thinks these should questions be silently ignored (even if false positives), then ... i give up, maybe i shouldn&#039;t use the forums either.. community toxicity seems to be an issue not solvable... (not sure, what i expected in the 1st place, from a nazi friendly environment.)</p><p>i read all sorts of BS, like trying to blame me or Clamav or LMD for not being responsible or spending devuan devs precious time, while they are doing their fine job and not need to hear this..<br />well, that&#039;s how communities work. communicate issues, no matter how stupid they might seem to you (...elitists).. <br />so someone(...) who checked this, is going to communicate this false positive to another foss (clamav) to help make it better, and not just whine about it in whatever forums. </p><p>---<br />anyway, some moderator, please lock this thread... <br />not solved imho, got no help/assurances from pkgmaster admin, so lock it up anyway.<br />tired of all the spam and bs on this thread.</p>]]></description>
			<author><![CDATA[dummy@example.com (xinomilo)]]></author>
			<pubDate>Mon, 23 Oct 2023 08:13:28 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=45019#p45019</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=45018#p45018</link>
			<description><![CDATA[<div class="quotebox"><cite>czeekaj wrote:</cite><blockquote><div><p>Ideally if you had a rsync of a mirror locally you could update systems through a lan connection much more securely without having to go through internet hoops.</p></div></blockquote></div><p>to clear something : this is not a local mirror, it&#039;s a mirror in Devuan RR, rsynced directly from pkgmaster - which changed ip once again recently without any official notification... <br />mirror is used daily by many people.</p>]]></description>
			<author><![CDATA[dummy@example.com (xinomilo)]]></author>
			<pubDate>Mon, 23 Oct 2023 08:06:23 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=45018#p45018</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=45017#p45017</link>
			<description><![CDATA[<div class="quotebox"><cite>pcalvert wrote:</cite><blockquote><div><p>Is LMD still alerting on those package digest files? I downloaded those files today, and then installed clamav and LMD. I ran <strong>maldet</strong> manually and had it analyze those files. It didn&#039;t find anything.</p></div></blockquote></div><p>did you install clamav-unofficial-sigs as well? that&#039;s what&#039;s giving the false positive. not default clamav signatures. and that&#039;s why virustotal doesn&#039;t report it either (they don&#039;t use unofficial sigs).</p><p>in my case, i put those files on ignore list, after examining them. don&#039;t know if lmd would report those again.</p>]]></description>
			<author><![CDATA[dummy@example.com (xinomilo)]]></author>
			<pubDate>Mon, 23 Oct 2023 07:58:21 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=45017#p45017</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=45016#p45016</link>
			<description><![CDATA[<div class="quotebox"><cite>aluma wrote:</cite><blockquote><div><p> Why is it needed if after years of use this is its first message and it’s false? Or am I missing something?</p></div></blockquote></div><p>yes, you&#039;re missing something, &quot;1st message on devuan mirror files&quot; is more accurate.</p>]]></description>
			<author><![CDATA[dummy@example.com (xinomilo)]]></author>
			<pubDate>Mon, 23 Oct 2023 07:43:43 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=45016#p45016</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=45008#p45008</link>
			<description><![CDATA[<div class="quotebox"><cite>xinomilo wrote:</cite><blockquote><div><p>that tool (clamav really) was running for years scanning all server files. this is the 1st time i got notifications and though i immediately thought of it as false positives, i guessed it&#039;d be better to get official confirmation... <br />and not all &quot;digests&quot; give false positives notifications.</p></div></blockquote></div><p>In retrospect, I think it would have been better to contact the developer of LMD and ask him or her why LMD thinks that there is malicious PHP code in those files. That way, you would have a better chance of receiving an answer, and from the person most qualified to answer the question. And you would more than likely give the developer an opportunity to improve his software. It appears that someone else may have done that since the problem now seems to be gone (according to my testing).</p>]]></description>
			<author><![CDATA[dummy@example.com (pcalvert)]]></author>
			<pubDate>Sun, 22 Oct 2023 20:33:17 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=45008#p45008</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44999#p44999</link>
			<description><![CDATA[<p>TOR is not a &quot;MitM&quot; defence, it&#039;s an anonymous routing network. Thrashing said network with generic bulk traffic that has no need for anonymisation achieves nothing but making the network slower for everyone.<br />Since I&#039;m running a TOR node, that means your &quot;good idea&quot; is potentially wasting my bandwidth.</p><p>APT already has release signing and package checksums, specifically to combat MitM attacks. If you want in-transit encryption as well, use an HTTPS mirror, that&#039;s what they&#039;re for. <br />If you&#039;re extra paranoid you can always verify packages certificates and signing keys manually, but unless you&#039;re inside a network that blocks normal access to the repository mirrors or have a pressing need to hide the fact that you are running Devuan, using TOR is just stupid.</p><p>Seriously, the amount of ridiculous tinfoil-hat &quot;security&quot; misadvice floating about these days is just tiring. Stop already.</p>]]></description>
			<author><![CDATA[dummy@example.com (steve_v)]]></author>
			<pubDate>Sun, 22 Oct 2023 12:55:36 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44999#p44999</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44997#p44997</link>
			<description><![CDATA[<div class="quotebox"><cite>czeekaj wrote:</cite><blockquote><div><p>I&#039;d be careful with some git repos or even possible for spoofing to MitM attack package distribution.</p></div></blockquote></div><p>Some Debian derivatives (e.g., Kicksecure) run apt through Tor to help prevent such attacks. It seems like a good idea, but I imagine that some people will find that it is painfully slow, especially if they are accustomed to very fast internet access. A good VPN would almost certainly be faster.</p>]]></description>
			<author><![CDATA[dummy@example.com (pcalvert)]]></author>
			<pubDate>Sun, 22 Oct 2023 09:24:17 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44997#p44997</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44992#p44992</link>
			<description><![CDATA[<p>I&#039;d be careful with some git repos or even possible for spoofing to MitM attack package distribution. </p><p>Ideally if you had a rsync of a mirror locally you could update systems through a lan connection much more securely without having to go through internet hoops.</p>]]></description>
			<author><![CDATA[dummy@example.com (czeekaj)]]></author>
			<pubDate>Sun, 22 Oct 2023 07:30:16 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44992#p44992</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44975#p44975</link>
			<description><![CDATA[<p>Is LMD still alerting on those package digest files? I downloaded those files today, and then installed clamav and LMD. I ran <strong>maldet</strong> manually and had it analyze those files. It didn&#039;t find anything.</p>]]></description>
			<author><![CDATA[dummy@example.com (pcalvert)]]></author>
			<pubDate>Sat, 21 Oct 2023 03:04:13 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44975#p44975</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44969#p44969</link>
			<description><![CDATA[<div class="quotebox"><cite>xinomilo wrote:</cite><blockquote><div><p>that tool (clamav really) was running for years scanning all server files. this is the 1st time i got notifications and though i immediately thought of it as false positives, i guessed it&#039;d be better to get official confirmation... <br />and not all &quot;digests&quot; give false positives notifications.</p></div></blockquote></div><p>Why is it needed if after years of use this is its first message and it’s false? Or am I missing something?</p><p> Regards.</p>]]></description>
			<author><![CDATA[dummy@example.com (aluma)]]></author>
			<pubDate>Fri, 20 Oct 2023 15:27:25 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44969#p44969</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44967#p44967</link>
			<description><![CDATA[<div class="quotebox"><cite>ralph.ronnquist wrote:</cite><blockquote><div><p>The paths</p><div class="codebox"><pre><code>/path/to/mirror/devuan/merged/dists/chimaera-backports/main/by-hash/SHA256/e8b658bc0b30120109470ac5b20c8be088f56b9024a49285c76d41d8694e2ce2</code></pre></div><p> et al are all compressed Packages files, i.e. so called &quot;digests&quot;, and evidently that &quot;tool&quot; can&#039;t handle them.</p></div></blockquote></div><p>that tool (clamav really) was running for years scanning all server files. this is the 1st time i got notifications and though i immediately thought of it as false positives, i guessed it&#039;d be better to get official confirmation... <br />and not all &quot;digests&quot; give false positives notifications.</p>]]></description>
			<author><![CDATA[dummy@example.com (xinomilo)]]></author>
			<pubDate>Fri, 20 Oct 2023 08:12:51 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44967#p44967</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44966#p44966</link>
			<description><![CDATA[<div class="quotebox"><cite>EDX-0 wrote:</cite><blockquote><div><p>i mean, php is not great but calling it malware isn&#039;t a bit too much?</p></div></blockquote></div><p>where did you read that php is malware? maybe in another post, there was no such reference here. (?)</p>]]></description>
			<author><![CDATA[dummy@example.com (xinomilo)]]></author>
			<pubDate>Fri, 20 Oct 2023 08:10:52 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44966#p44966</guid>
		</item>
		<item>
			<title><![CDATA[Re: malware on devuan repos or false positives?]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44965#p44965</link>
			<description><![CDATA[<div class="quotebox"><cite>pcalvert wrote:</cite><blockquote><div><p>If you haven&#039;t done so already, try the mailing list:</p><p><a href="https://mailinglists.dyne.org/cgi-bin/mailman/listinfo/dng" rel="nofollow">https://mailinglists.dyne.org/cgi-bin/m … stinfo/dng</a></p></div></blockquote></div><p>dng is just a users general list, and toxic. unsubscribed years ago. <br />but there was another list for mirror operators. not currently working for reasons unknown.</p>]]></description>
			<author><![CDATA[dummy@example.com (xinomilo)]]></author>
			<pubDate>Fri, 20 Oct 2023 08:10:02 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44965#p44965</guid>
		</item>
	</channel>
</rss>
