Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

hitname missing from quarantine history when automatic quarantine is disabled #319

Closed
Gazoo opened this issue Dec 20, 2018 · 1 comment
Closed
Assignees
Labels

Comments

@Gazoo
Copy link
Contributor

Gazoo commented Dec 20, 2018

When running maldet --quarantine SCANID the hitname is missing from the quarantine history /usr/local/maldetect/sess/quarantine.hist file even though it is present in the scan report.

Looking at the code the hitname is supposed to be the second item logged but you can see that its missing with the ::

With automatic quarantine disabled:

1545044380::/var/www/vhosts/example.com/httpdocs/eicar.com.txt:example:psacln:44d88612fea8a8f36de82e1278abb02f:68:/usr/local/maldetect/quarantine/eicar.com.txt.2531921261

With automatic quarantine enabled:

1545313335:{CAV}Eicar-Test-Signature:/var/www/vhosts/example.com/httpdocs/eicar.com.txt:example:psacln:44d88612fea8a8f36de82e1278abb02f:68:/usr/local/maldetect/quarantine/eicar.com.txt.963129744

This only happens when when automatic quarantine is disabled. It is correctly logged if auto quarantine is enabled.

@rfxn rfxn self-assigned this Dec 28, 2018
@rfxn rfxn added the bug label Dec 28, 2018
rfxn added a commit that referenced this issue Mar 16, 2019
@rfxn
Copy link
Owner

rfxn commented Mar 16, 2019

Thanks for the feedback Gazoo. This has been fixed in master, ready to ship as 1.6.4.

@rfxn rfxn closed this as completed Mar 16, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants