Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-09 Thread SULLIVAN, BRYAN L (BRYAN L)
inds [mailto:lhi...@redhat.com] Sent: Friday, March 09, 2018 1:52 AM To: SULLIVAN, BRYAN L (BRYAN L) Cc: Aric Gardner ; Fatih Degirmenci ; opnfv-tech-discuss Subject: Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements Sorry for spamming you folks, but the last one was broken: h

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-09 Thread Luke Hinds
resources >>> even via python libraries e.g. for OpenStack clients, so it's not just >>> curl/wget that would be at risk. >>> >>> Thanks, >>> Bryan Sullivan | AT&T >>> >>> -Original Message- >>> From: opnfv-tec

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-09 Thread Luke Hinds
get that would be at risk. >> >> Thanks, >> Bryan Sullivan | AT&T >> >> -Original Message- >> From: opnfv-tech-discuss-boun...@lists.opnfv.org [mailto: >> opnfv-tech-discuss-boun...@lists.opnfv.org] On Behalf Of Aric Gardner >> Sent: Thursday, March

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-09 Thread Luke Hinds
explicitly added to exception list for the > > corresponding project, do you mean that we will stop flagging > changes/files > > that contain wget/curl against unknown IPs if they are not marked as > > malicious on VirusTotal? > > > > We also had plans to make anteater checks voti

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-08 Thread SULLIVAN, BRYAN L (BRYAN L)
From: opnfv-tech-discuss-boun...@lists.opnfv.org [mailto:opnfv-tech-discuss-boun...@lists.opnfv.org] On Behalf Of Aric Gardner Sent: Thursday, March 08, 2018 7:21 AM To: Fatih Degirmenci Cc: opnfv-tech-discuss Subject: Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improve

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-08 Thread Aric Gardner
> From: on behalf of Luke Hinds > > Date: Thursday, 8 March 2018 at 14:02 > To: "opnfv-tech-discuss@lists.opnfv.org" > > Subject: [opnfv-tech-discuss] [releng][security][infra] Anteater > Improvements > > > > Hello, > > I have some changes to improve

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-08 Thread Luke Hinds
ci [mailto:fatih.degirme...@ericsson.com] > *Sent:* Thursday, March 08, 2018 7:01 AM > *To:* SULLIVAN, BRYAN L (BRYAN L) ; Luke > Hinds ; opnfv-tech-discuss opnfv.org> > > *Subject:* Re: [opnfv-tech-discuss] [releng][security][infra] Anteater > Improvements > > > > Hi

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-08 Thread SULLIVAN, BRYAN L (BRYAN L)
irme...@ericsson.com] Sent: Thursday, March 08, 2018 7:01 AM To: SULLIVAN, BRYAN L (BRYAN L) ; Luke Hinds ; opnfv-tech-discuss Subject: Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements Hi Brian, My comment wasn’t about the tools themselves but what they are used for and to

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-08 Thread Fatih Degirmenci
Sent: Thursday, March 08, 2018 6:12 AM To: Luke Hinds ; opnfv-tech-discuss Subject: Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements Hi Luke, I have few comments and followup questions regarding this: “This in turn means we won't raise alarms over curl, git clone and

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-08 Thread SULLIVAN, BRYAN L (BRYAN L)
2018 6:12 AM To: Luke Hinds ; opnfv-tech-discuss Subject: Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements Hi Luke, I have few comments and followup questions regarding this: “This in turn means we won't raise alarms over curl, git clone and wget and will instead

Re: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-08 Thread Fatih Degirmenci
18 at 14:02 To: "opnfv-tech-discuss@lists.opnfv.org" Subject: [opnfv-tech-discuss] [releng][security][infra] Anteater Improvements Hello, I have some changes to improve the reporting ability and hopefully tone down the false positives. Aneater will now interface with the VirusTotal pu

[opnfv-tech-discuss] [releng][security][infra] Anteater Improvements

2018-03-08 Thread Luke Hinds
Hello, I have some changes to improve the reporting ability and hopefully tone down the false positives. Aneater will now interface with the VirusTotal public API: 1. If anteater finds a public IP address, the DNS history will be quiered to see if the IP has past or present associations with mal