Skip to content

Clam 2585 ole check encrypted 3#1295

Merged
val-ms merged 1 commit into
Cisco-Talos:mainfrom
ragusaa:CLAM-2585-OleCheckEncrypted_3
Sep 11, 2024
Merged

Clam 2585 ole check encrypted 3#1295
val-ms merged 1 commit into
Cisco-Talos:mainfrom
ragusaa:CLAM-2585-OleCheckEncrypted_3

Conversation

@ragusaa
Copy link
Copy Markdown
Contributor

@ragusaa ragusaa commented Jun 28, 2024

For OLE2 office documents, determine if it is encrypted.

Store this in JSON metadata/properties.

Also check the "alert-encrypted" option and alert if necessary.

@ragusaa ragusaa force-pushed the CLAM-2585-OleCheckEncrypted_3 branch from 95feff1 to 903eb07 Compare June 28, 2024 15:31
@val-ms
Copy link
Copy Markdown
Contributor

val-ms commented Jun 28, 2024

Replaced by #1279

@val-ms val-ms closed this Jun 28, 2024
@val-ms val-ms reopened this Jun 28, 2024
@val-ms
Copy link
Copy Markdown
Contributor

val-ms commented Jun 28, 2024

My mistake, this one replaces the other.

Copy link
Copy Markdown
Contributor

@val-ms val-ms left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Other the formatting, I don't have any other concerns.

Comment thread libclamav/ole2_extract.c Outdated
Comment thread libclamav/ole2_extract.c Outdated
@ragusaa ragusaa force-pushed the CLAM-2585-OleCheckEncrypted_3 branch 2 times, most recently from 74aa9b5 to 2057326 Compare July 18, 2024 14:37
@ragusaa
Copy link
Copy Markdown
Contributor Author

ragusaa commented Jul 18, 2024

I ran clam-format to clean up the formatting, so I think this one is good to go.

@ragusaa ragusaa requested a review from val-ms July 18, 2024 17:15
@val-ms val-ms force-pushed the CLAM-2585-OleCheckEncrypted_3 branch from 2057326 to 481a8b6 Compare July 22, 2024 16:27
@val-ms
Copy link
Copy Markdown
Contributor

val-ms commented Jul 22, 2024

Just rebased with upstream main to get the CI fixes and other clang-format fixes.

Add keys to the metadata.json file that informs the user that a scanned
ole2 file is encrypted.  Information about the type of encryption is
provided when the information is available.  This feature co-authored by
Micah Snyder.
@val-ms val-ms force-pushed the CLAM-2585-OleCheckEncrypted_3 branch from 481a8b6 to 6d50a60 Compare September 10, 2024 15:51
@val-ms
Copy link
Copy Markdown
Contributor

val-ms commented Sep 10, 2024

Rebased again

@val-ms val-ms merged commit 8ae19ec into Cisco-Talos:main Sep 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants