You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
frpc.exe 0.34.1 detected as security risk by Symantec Endpoint Protection, submitted false positive, but they will not revoke the detection. What to do?
#2166
Closed
2 tasks done
gitercn opened this issue
Dec 25, 2020
· 1 comment
[REQUIRED] What operating system and processor architecture are you using
OS: Windows
CPU architecture: x64
[REQUIRED] description of errors
confile
log file
Steps to reproduce the issue
I have downloaded and used frpc.exe 0.34.1 on a computer with Symantec Endpoint Protection Version 14.3 build 558. It has no issues for a few weeks. Then yesterday it was reported as a security risk. The sha-256 hash is 20B89AFBC2F20A1239FC71CAAAFD861BAF626352BEEBE3B5EE4150273
Why this open source fast reverse proxy frp get identified as security risk? This file is download from Github release: https://github.com/fatedier/frp/releases/download/v0.34.1/frp_0.34.1_windows_amd64.zip It's source code is open on Github: https://github.com/fatedier/frp
Then today I received an email saying they will not revoke the detection:
In relation to submission 238882.
Upon further analysis and investigation we have determined that the file(s) in question meet the necessary criteria to be detected by our products and as such, the detection cannot be revoked.
For additional information on how to configure Symantec products to exclude specific drives, folders, and files from being scanned please see below.
Symantec Enterprise
- Information on exclusions: https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-protection/all/Using-policies-to-manage-security/managing-exceptions-in-v36686987-d51e6/creating-exceptions-for-virus-and-spyware-scans-v39814459-d51e102/excluding-a-file-or-a-folder-from-scans-v39818564-d51e811.html#v39818564
- Support: https://support.broadcom.com/contact-support.html
Norton Consumer
- Information on real time exclusions can be found under the section 'Exclude files or folders from scan': https://support.norton.com/sp/en/us/norton-antivirus/19.0/solutions/kb20100222230832EN_EndUserProfile_en_us
- Support: https://support.norton.com/sp/en/au/home/current/info
Decisions made by Symantec are subject to change if alterations to the Software are made over time or as classification criteria and/or the policy employed by Symantec changes over time to address the evolving landscape.
Sincerely,
Symantec Security Response
https://www.broadcom.com/support/security-center
What to do?
Supplementary information
Can you guess what caused this issue
Checklist:
I included all information required in the sections above
I made sure there are no duplicates of this report (Use Search)
The text was updated successfully, but these errors were encountered:
[REQUIRED] hat version of frp are you using
Version: 0.34.1
[REQUIRED] What operating system and processor architecture are you using
OS: Windows
CPU architecture: x64
[REQUIRED] description of errors
confile
log file
Steps to reproduce the issue
Then I submitted a false positive report to Symantec at here: https://symsubmit.symantec.com/#fp_tab
I wrote:
Then today I received an email saying they will not revoke the detection:
What to do?
Supplementary information
Can you guess what caused this issue
Checklist:
The text was updated successfully, but these errors were encountered: