Questions tagged [false-alarm]

6 questions
4
votes
2 answers

False positive SQL Injection by ZAP with adding new parameter query

I have a spring MVC web application and am running ZAP Active scan on it. I noticed that ZAP will modify URL , and add additional parameter named query and value query+AND+1%3D1+--+ to test SQL Injection. And in my case, it raise HIGH MEDIUM SQL…
Hima
  • 41
  • 4
3
votes
3 answers

How to prove a false positive

I was notified by my university's infosec team that one of my lab's computers had been infected by ransomware. They shut down the computer's network connections using Crowdstrike and are insisting that the hard drive needs to be reimaged. The…
matt2103
  • 35
  • 5
2
votes
1 answer

CVE-2019-0903 detected by just one anti-virus service

On my Windows 8.1 computer I created an MS Word document containing a couple images I downloaded from the internet, and exported it as PDF. The MS Word version is 14.0.7232.5000, 64 bit. I sent that PDF to a number of recipients by email. One email…
1
vote
6 answers

How common is it for an antivirus program to give false positive?

Often antivirus programs trigger a false alarm that a certain file is corrupted or infected. How common is that and if it is too common, can we really rely on them? Along with that, how easy it is to corrupt an antivirus?
Irfan
  • 11
  • 2
1
vote
1 answer

Is OSX/MaMi a real malware or a simple filtering software?

Recently a lot of communications spread starting from this analysis: OSX/MaMi analysis When I read this analysis, I found that 2 DNS servers are defined as default ones for the IP configuration: 82.163.143.135 82.163.142.137 I discovered that these…
dan
  • 3,033
  • 14
  • 34
0
votes
0 answers

Are there some viruses that write assembly code instead of machine code, and use an external assembler?

Like the question says, I am wondering if there are some viruses that do not write machine code themselves, but instead output assembly code and invoke an external assembler? That sounds like a plausible attack on Linux systems, where as (GNU…