badfiles
A malicious file detection engine written with Python and Yara.
- Free software: Apache-2.0
- Documentation: https://jeffallan.github.io/badfiles/
Introduction
At some point most applications need to accept files from a third party. Since we do not have absolute control over these files they can present a serious threat vector.
The aim of this project is to provide a flexible and expandable solution to triage these files so they can be handled accordingly.
Features
Currently, this project focuses on detecting the following:
Generally Suspicious Files:
✔️ Mime type confusion.
🔲 Files with a root UID or GID (*NIX only).
🔲 Sticky, setuid, or setgit bit (*NIX only).
CSV Files
✔️ CSV Injection.
🔲 Files with a root UID or GID (*NIX only).
🔲 Sticky, setuid, or setgit bit (*NIX only).
Office Documents
✔️ DDE injection.
✔️ Files with a root UID or GID (*NIX only).
✔️ Sticky, setuid, or setgit bit (*NIX only).
Zip Files
✔️ Symlink attacks.
✔️ Zip slips.
✔️ Nested zip bombs.
✔️ Flat zip bombs.
✔️ Sticky, setuid, or setgit bit (*NIX only).
✔️ Files with a root UID or GID (*NIX only).
Tar Files
✔️ Files with a root UID or GID (*NIX only).
✔️ Sticky, setuid, or setgit bit (*NIX only).
🔲 Files with absolute paths (*Nix only).
Additional Features
Please file an issue or a pull request especially if you have found or created malicious files that bypass these detection mechanisms. Please see the contributing guidelines for more details.
Getting Started
Usage
Credits
This package was created with This Cookiecutter template.
This project uses zip-bomb to create the nested and flat zip bombs for unit testing and detection rules.
This project uses a custom Yara rule from Reversing Labs to detect obfuscated CSV injection payloads.
Contributors
Metadata
Release files for badfiles 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| badfiles-0.3.0.tar.gz | 36.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| badfiles-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 47.4 kB
Release files / badfiles-0.3.0.tar.gz
| Download URL | badfiles-0.3.0.tar.gz |
|---|---|
| Size | 36.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
424faedfcd10a98489b332844b968b7ddc186cce9bd39d0d996b37d5e069a7b7
|
|
BLAKE2b-256 checksum How to use checksums |
613fb7a459677b2343503c0634c8994c7a230ab4f499e5a6fe35b272eae9905b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.6.0 importlib_metadata/4.8.2 pkginfo/1.8.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.9
|
Release files / badfiles-0.3.0-py3-none-any.whl
| Download URL | badfiles-0.3.0-py3-none-any.whl |
|---|---|
| Size | 11.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9f922d2f010433638b8351c4f3607f80f74a933e5e1b6af630d27a45426b7481
|
|
BLAKE2b-256 checksum How to use checksums |
b295fe5472c4d061d77de84c1940b4fb9bad51d49f6e0001a5e139eaa1a42ee2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.6.0 importlib_metadata/4.8.2 pkginfo/1.8.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.9
|