Skip to main content

badfiles

Release Status CI Status

A malicious file detection engine written with Python and Yara.

Introduction

At some point most applications need to accept files from a third party. Since we do not have absolute control over these files they can present a serious threat vector.

The aim of this project is to provide a flexible and expandable solution to triage these files so they can be handled accordingly.

Features

Currently, this project focuses on detecting the following:

Generally Suspicious Files:

✔️ Mime type confusion.

🔲 Files with a root UID or GID (*NIX only).

🔲 Sticky, setuid, or setgit bit (*NIX only).

CSV Files

✔️ CSV Injection.

🔲 Files with a root UID or GID (*NIX only).

🔲 Sticky, setuid, or setgit bit (*NIX only).

Office Documents

✔️ DDE injection.

✔️ Files with a root UID or GID (*NIX only).

✔️ Sticky, setuid, or setgit bit (*NIX only).

Zip Files

✔️ Symlink attacks.

✔️ Zip slips.

✔️ Nested zip bombs.

✔️ Flat zip bombs.

✔️ Sticky, setuid, or setgit bit (*NIX only).

✔️ Files with a root UID or GID (*NIX only).

Tar Files

✔️ Files with a root UID or GID (*NIX only).

✔️ Sticky, setuid, or setgit bit (*NIX only).

🔲 Files with absolute paths (*Nix only).

Additional Features

Please file an issue or a pull request especially if you have found or created malicious files that bypass these detection mechanisms. Please see the contributing guidelines for more details.

Getting Started

Usage

Credits

This package was created with This Cookiecutter template.

This project uses zip-bomb to create the nested and flat zip bombs for unit testing and detection rules.

This project uses a custom Yara rule from Reversing Labs to detect obfuscated CSV injection payloads.

Contributors

Metadata

Release files for badfiles 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for badfiles 0.3.0
File Size Uploaded
badfiles-0.3.0.tar.gz 36.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for badfiles 0.3.0
File Interpreter ABI Platform
badfiles-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 47.4 kB

Release files / badfiles-0.3.0.tar.gz

Download URL badfiles-0.3.0.tar.gz
Size 36.5 kB
Tags Source
SHA-256 checksum
How to use checksums
424faedfcd10a98489b332844b968b7ddc186cce9bd39d0d996b37d5e069a7b7
BLAKE2b-256 checksum
How to use checksums
613fb7a459677b2343503c0634c8994c7a230ab4f499e5a6fe35b272eae9905b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.6.0 importlib_metadata/4.8.2 pkginfo/1.8.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.9

Release files / badfiles-0.3.0-py3-none-any.whl

Download URL badfiles-0.3.0-py3-none-any.whl
Size 11.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9f922d2f010433638b8351c4f3607f80f74a933e5e1b6af630d27a45426b7481
BLAKE2b-256 checksum
How to use checksums
b295fe5472c4d061d77de84c1940b4fb9bad51d49f6e0001a5e139eaa1a42ee2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.6.0 importlib_metadata/4.8.2 pkginfo/1.8.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.9

Release history Release notifications | RSS feed

This release

0.3.0 This release

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page