aboutcode-org / aboutcode-org/extractcode

Deal properly with large UPX-compressed binaries

Open
#14 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
39
Forks
23
PR merge metrics
No merged PRs in 30d

Description

Scanning UPX-compressed executables does not make sense unless they could be unpacked first.
See https://en.wikipedia.org/wiki/UPX

For instance these PostgreSQL installers take a large amount of resources and time to scan.
And there is little to squeeze out of the raw binaries.
- One is a large statically-linked ELf http://get.enterprisedb.com/postgresql/postgresql-9.4.1-1-linux-x64.run for Linux.
- The other a Windows exe from http://get.enterprisedb.com/postgresql/postgresql-9.4.1-1-windows-x64.exe

They are not really archives but exe hence the reason why they are still scanned for now.
We will need to figure out a way to avoid issues when dealing with these large binaries that cannot yield much when scanned.
Both are compressed with UPX which makes their binary completely opaque short of decompressing them assuming they are using a standard UPX compressor.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.