Skip to content

Should we move dot files out of lfi-os-files.data? (930120) #4041

@theseion

Description

@theseion

lfi-os-files.data contains an amalgamation of different filenames and paths. Dot files in particular are prone to FPs. Unfortunately, it is not trivial to check whether a match from @pmFromFile (see 930120) came from a dot file, since the match can be a substring. For example, .docker would be found in [email protected], but the the match would be the full e-mail address.

I propose we move dot files out of lfi-os-files.data to make our lives easier, and create a new rule to cover dot files specifically.

Below is the comment from @aryehb that initiated this issue.

@theseion .env is not the only FP for this rule.

We just came across an email with the form [email protected], where it was being flagged because it matched .docker.

Originally posted by @aryehb in #3775

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions