chainguard-dev / bincapz

detect malicious program behaviors
Apache License 2.0
404 stars 26 forks source link

high false positive: combo/backdoor/iptables with buildkitd, calico, cilium #139

Closed tstromberg closed 4 months ago

tstromberg commented 4 months ago

These all should be using iptables, but we probably shouldn't categorize it as a backdoor:

## packages/x86_64/buildkitd-0.13/usr/bin/buildkitd
## packages/x86_64/calico-apiserver-3.27/usr/bin/calico-apiserver
## packages/x86_64/calico-felix-3.27/usr/bin/calico-bpf
## packages/x86_64/calico-felix-3.27/usr/bin/felix
## packages/x86_64/calico-kube-controllers-3.27/usr/bin/calico-kube-controllers
## packages/x86_64/calico-node-3.27/bin/calico-node
## packages/x86_64/calicoctl-3.27/usr/bin/calicoctl
## packages/x86_64/cilium-1.15-1/opt/cni/bin/cilium-cni
## packages/x86_64/cilium-1.15-1/usr/bin/cilium
## packages/x86_64/cilium-1.15-1/usr/bin/cilium-dbg
## packages/x86_64/cilium-1.15-hubble-relay-1/usr/bin/hubble-relay
## packages/x86_64/cilium-cli-0.16/usr/bin/cilium