Repository navigation
Fix ScanMalware attribution to subdomain tenants - #953
Open
Jonas Lejon (jonaslejon) wants to merge 1 commit into
Open
Jonas Lejon (jonaslejon) wants to merge 1 commit into
Jonas Lejon (jonaslejon) wants to merge 1 commit into
Conversation
The scan list for a host also holds its subdomains. On a shared platform a subdomain is an unrelated tenant, so a lookup of netlify.app or workers.dev took a tenant phishing page's verdict (Severity high), and -quick attached the tenant's scan as LastScanUrl. A scan is now selected only when its own host is the observable's host or its www name, in addition to matched_on containing "url". URL lookups already required the exact URL and are unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this fixes
For a
dnsorhostnamelookup, the ScanMalware provider picks the newest completed scan whosematched_oncontainsurl. The scan list for a host also holds its subdomains, and on a shared platform a subdomain is an unrelated tenant. So in v3.1.0 a lookup ofnetlify.apporworkers.devreturns Severity high, Verdict Malicious, taken from a tenant's phishing page, and-quickattaches that tenant's scan asLastScanUrl.A scan is now selected only when its own host is the observable's host, or its
www.name, as well asmatched_oncontainingurl. This builds on cd856f7, which movedLastScan/LastScanUrl/LastTitleonto the selected scan; this change narrows which scan is selected. URL lookups already required the exact URL and are unchanged, as are IP lookups.Disclosure: I run ScanMalware and wrote this provider (#938).
Before and after, live against scanmalware.com
Through
ScanMalware().lookup_ioc(...), v3.1.0 against this branch:netlify.appLastScanUrla tenantworkers.devLastScanUrla tenantgithub.iohttps://excelformulabot.github.ionetlify.app(-quick)LastScanUrla tenantexample.comhttps://gilded-macaron-79e0e2.netlify.app/(url)ResultstaysTrueandScanskeeps the full count; only the scan the details and verdict come from is stricter.Tests
tests/context/test_scanmalware.pygains 8 test cases (22 to 30). Five fail onmain: a subdomain tenant (with and without-quick), the platform's own scan behind a newer tenant scan, a lookalike host (example.com.ruunderexample.com), and a deeper subdomain under ahostname. Three guard against over-tightening: thewww.name, letter case and an explicit port still count.pytest tests/context/test_tiproviders.py tests/context/test_scanmalware.py: 71 passedruff check msticpy --ignore PLW0603: cleanpylintwith the CI flags: 10.00/10mypywith the CI flags: no issuesThe same rule is in the MISP expansion module (MISP/misp-modules#916, released in v3.0.11).