Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

在CentOS Linux release 7.6.1810 (Core)系统上运行Ubuntu 20.04.4 LTS容器后,运行木马病毒程序,拿到的文件创建时间FileCreated不对 #124

Open
testwill opened this issue Aug 17, 2022 · 8 comments
Assignees
Labels
enhancement New feature or request

Comments

@testwill
Copy link
Contributor

900d3fe1a0e2d407f240e3761714e81

image
这个镜像是8月3号创建的

@testwill testwill added the bug Something isn't working label Aug 17, 2022
@testwill
Copy link
Contributor Author

我看了下 info.Sys().(*syscall.Stat_t),在那个容器里面运行就是这个结果,是不是考虑换个方式获取对应的时间

@d1nfinite
Copy link
Collaborator

没有太懂问题是啥,Linux 里面的文件时间是可以自行设置的,完全可以早于镜像创建时间

@testwill
Copy link
Contributor Author

是的,但是我扫描的那个镜像的是在两周前生成的是,malicious_file_infos表中的file_created字段是不是应该是两周前,现在是获取的是当前扫描的时间。就是这个时间是不准确的。

@d1nfinite
Copy link
Collaborator

这个其实是 Linux 系统里面对于文件创建时间的描述,除此之外可能没有其他太好的方法去获取文件创建时间

@testwill
Copy link
Contributor Author

好的,能不能用最后修改时间? 这个拿到的是正确的

@d1nfinite
Copy link
Collaborator

可以考虑将 mtim 和 atim 带上

@d1nfinite
Copy link
Collaborator

@huzai9527 有空可以支持一下

@d1nfinite d1nfinite added enhancement New feature or request and removed bug Something isn't working labels Aug 17, 2022
@Trc0g
Copy link

Trc0g commented Aug 17, 2022

@testwill 师傅可以添加小助手微信和我们联系,我们考虑为你提供一些功能上的深度支持

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants