Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No documentation re: gh0stRAT emulation #178

Open
Mezzle opened this issue Sep 7, 2023 · 4 comments
Open

No documentation re: gh0stRAT emulation #178

Mezzle opened this issue Sep 7, 2023 · 4 comments

Comments

@Mezzle
Copy link

Mezzle commented Sep 7, 2023

I'm experimenting with using masscanned, and we've had an abuse report come through as it was detected that we are "associated with an ongoing malware attack"

It would probably be useful to add a warning that this false positive might be detected (and potentially an option to turn this off?) so that this doesn't mistakenly have people responding as if it's an actual security incident. (Always good to practice these things, I guess?!)

@p-l-
Copy link
Member

p-l- commented Sep 7, 2023

The goal of Masscanned is to answer to requests "as deeply as we can". The actors that send abuse reports based on their scan results (to be clear: they scan your machine, then send you an abuse because of what you answered) should be silently ignored.
But to answer your request:

  • I don't see where we could / should display a warning
  • we could provide an option to selectively enable or disable each protocol. If you feel like providing a PR for that, we'd be glad to review & accept it.

@Mezzle
Copy link
Author

Mezzle commented Sep 7, 2023

I don't see where we could / should display a warning

Just a note in the readme or something saying that it emulates it would be useful, I had to dig into the code to realise that it did (and that it might cause a report)

Our cloud provider contacted us re: a potential issue because it thought we'd been infected, and i didn't realise straight away that it was actually masscanned, and started to look into it as if it was gh0stRAT :) (on my day off, too!)

I'll need to learn a bit more rust before i can provide that PR. I'm just about getting to grips with reading it :)

@p-l-
Copy link
Member

p-l- commented Sep 8, 2023

Just a note in the readme or something saying that it emulates it would be useful, I had to dig into the code to realise that it did (and that it might cause a report)

Sounds sensible. Feel free to propose a PR to add something in the README.

BTW, sorry about your day off!

@Mezzle
Copy link
Author

Mezzle commented Sep 8, 2023

Don't worry about it

I'll throw a PR up later

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants