pikhq / bootstrap-linux

A Linux system which is just barely capable of building itself.
123 stars 14 forks source link

Yahoo! Mail detects virus in bzip2'd filesystem.img #2

Open lpsantil opened 13 years ago

lpsantil commented 13 years ago

I tend to move small files between my various VirtualBox VMs via my various email accounts. So after building bootstrap-linux in ArchBang Linux, I bzip2'd it so that it can be dl'd by my host machine. However, when I attach it to the email, Yahoo! reports the 13.7MB filesystem.img.bz2 file to contain file that has a virus. It recommends that I remove the one infected file and then re-attach. Any idea what Yahoo! is talking about?

rofl0r commented 13 years ago

which file is that ?

lpsantil commented 13 years ago

I wish I could tell you. Yahoo doesn't say which "file". I don't think yahoo actually parses the ext2fs image. My guess is, however, that it recognizes the mbr in the image as one of its signatures.

rofl0r commented 13 years ago

well, you should inform yahoo about the false positive so that they can fix their scanner. optimally, they also should provide a more detailed report.

lpsantil commented 13 years ago

I believe they outsource their scanner to mcafee. Odd thing is, once I scp'd the image to my host box, I then emailed it from gmail to yahoo successfully. I'll report it to yahoo.