-
-
Notifications
You must be signed in to change notification settings - Fork 429
Closed
Description
lfi-os-files.data contains an amalgamation of different filenames and paths. Dot files in particular are prone to FPs. Unfortunately, it is not trivial to check whether a match from @pmFromFile (see 930120) came from a dot file, since the match can be a substring. For example, .docker would be found in [email protected], but the the match would be the full e-mail address.
I propose we move dot files out of lfi-os-files.data to make our lives easier, and create a new rule to cover dot files specifically.
Below is the comment from @aryehb that initiated this issue.
@theseion
.envis not the only FP for this rule.We just came across an email with the form
[email protected], where it was being flagged because it matched.docker.
Metadata
Metadata
Assignees
Labels
No labels