Possible to skip checking file extention? Tommy
    Possible to skip checking file extention? Synametrics Support
        Possible to skip checking file extention? Tommy

From: Tommy
Date: 4/11/23 5:31 AM
Topic: Possible to skip checking file extention?
Type: General Discussions
Post a follow up

Attached RAR file contains malicious files (A0010A0C2022072710/all_A0010A0C2022072710_fac.bin)

 

Is it possible without check the file extention .bin in rar ?

Top

From: Synametrics Support
Date: 4/11/23 10:09 AM
Topic: Possible to skip checking file extention?
Type: General Discussions
Post a follow up

Try the following steps:

  • Create a new file called badExtensions.txt in $INSTALL_DIR\config folder
  • Add comma-separated extensions that you want to block. The default value is set to:

    .scr,.pif,.js,.html,.htm,.bin,.com,.vbs,.wsf,.hta,.jse,.bat,.cmd,.jar,.exe

  • You can add/remove any extension you like
  • Save the file and restart Xeams
Top

From: Tommy
Date: 4/12/23 12:52 AM
Topic: Possible to skip checking file extention?
Type: General Discussions
Post a follow up

That's good,i update the list as below:

 

.bat,.cmd,.com,.exe,.hta,.jar,.job,.js,.jse,.pif,.ps1,.reg,.scr,.sct,.vbe,.vbs,.wsc,.wsf,.wsh

Top