Skip to content
/ desktop Public
  • Notifications You must be signed in to change notification settings
  • Fork 752
  • Star 2.8k
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

Sign up for GitHub

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Jump to bottom

[Bug]: Desktop client identifying all 2FA recovery code backup files as Ransomware #5512

Closed
4 of 8 tasks
oucil opened this issue Mar 10, 2023 · 3 comments
Closed
4 of 8 tasks

[Bug]: Desktop client identifying all 2FA recovery code backup files as Ransomware #5512

oucil opened this issue Mar 10, 2023 · 3 comments
Labels
0. Needs triage

Comments

@oucil
Copy link

oucil commented Mar 10, 2023

鈿狅笍 Before submitting, please verify the following: 鈿狅笍

  • This is a bug, not a question or a configuration issue.
  • This issue is not already reported on Github (I've searched it).
  • Nextcloud Server and Desktop Client are up to date. See Server Maintenance and Release Schedule and Desktop Releases for supported versions.
  • I agree to follow Nextcloud's Code of Conduct

Bug description

After updating to the latest client, the latest sync has identified all (4) of my 2FA recovery code backup files as "Ransomware" and is refusing to sync them.

Steps to reproduce

I can't provide my 2FA backups for testing, but I would suspect that any standard 2FA backup file will do.

Expected behavior

The client should sync these files normally.

Which files are affected by this bug

Firefox Recovery Codes.txt

Operating system

Windows

Which version of the operating system you are running.

Windows 10

Package

Other

Nextcloud Server version

25.0.4

Nextcloud Desktop Client version

3.7.4

Is this bug present after an update or on a fresh install?

Updated from a minor version (ex. 3.4.2 to 3.4.4)

Are you using the Nextcloud Server Encryption module?

Encryption is Disabled

Are you using an external user-backend?

  • Default internal user-backend
  • LDAP/ Active Directory
  • SSO - SAML
  • Other

Nextcloud Server logs

No response

Additional info

No response

@oucil oucil added the 0. Needs triage label Mar 10, 2023
@oucil
Copy link
Author

oucil commented Mar 10, 2023

NC Client.zip
Client debug log file attached.

@Alkl58
Copy link
Contributor

Alkl58 commented Mar 10, 2023

Ransomware protection is done server side, the desktop client is showing the error message from the server in this case.

The protection is done by regex (filename matching) to a configurable list in the settings of the protection.

An example from your logs: Backblaze Recovery Codes.txt
This matches with: Recovery(.{6})\.txt$ from https://github.com/nextcloud/ransomware_protection/blob/master/resources/notes.txt#L264

Test:
grafik

You have two options now:

  1. Change the filename, maybe Backblaze Recovery.txt would work
  2. Modify the "Exclude note file patterns" list (should be configurable over the Nextcloud Admin Panel)

@oucil
Copy link
Author

oucil commented Mar 10, 2023

@Alkl58 Thanks for the explanation, that makes a lot more sense, and I'd forgotten about the Ransomware plugin altogether, which I guess is a good thing, set it and forget it. This seems like a pretty aggressive regex that's going to catch a fair bit of false positives, but at least there are solutions to get around it. Appreciate the help!

@oucil oucil closed this as completed Mar 10, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
0. Needs triage
Projects
None yet
Development

No branches or pull requests

2 participants
@oucil @Alkl58

Footer

© 2024 GitHub, Inc.

深圳SEO优化公司拉萨网站制作茂名网站优化按天扣费报价湖州设计网站价格兴安盟seo价格毕节企业网站建设多少钱潜江企业网站建设桂林模板推广酒泉推广网站鄂州网站关键词优化多少钱盐田网站推广系统报价坪地网络推广推荐广州百度关键词包年推广仙桃网站关键词优化眉山高端网站设计报价巢湖SEO按效果付费哪家好岳阳网站推广推荐滨州网站优化推广多少钱安康SEO按天计费多少钱张掖企业网站设计怀化网站优化排名多少钱和县模板推广报价醴陵seo网站优化推荐塔城百搜标王哪家好晋城网站建设报价南昌网站优化按天收费公司辽源优秀网站设计阜新网络营销多少钱景德镇关键词排名包年推广公司临汾网站seo优化公司商洛百度标王报价歼20紧急升空逼退外机英媒称团队夜以继日筹划王妃复出草木蔓发 春山在望成都发生巨响 当地回应60岁老人炒菠菜未焯水致肾病恶化男子涉嫌走私被判11年却一天牢没坐劳斯莱斯右转逼停直行车网传落水者说“没让你救”系谣言广东通报13岁男孩性侵女童不予立案贵州小伙回应在美国卖三蹦子火了淀粉肠小王子日销售额涨超10倍有个姐真把千机伞做出来了近3万元金手镯仅含足金十克呼北高速交通事故已致14人死亡杨洋拄拐现身医院国产伟哥去年销售近13亿男子给前妻转账 现任妻子起诉要回新基金只募集到26元还是员工自购男孩疑遭霸凌 家长讨说法被踢出群充个话费竟沦为间接洗钱工具新的一天从800个哈欠开始单亲妈妈陷入热恋 14岁儿子报警#春分立蛋大挑战#中国投资客涌入日本东京买房两大学生合买彩票中奖一人不认账新加坡主帅:唯一目标击败中国队月嫂回应掌掴婴儿是在赶虫子19岁小伙救下5人后溺亡 多方发声清明节放假3天调休1天张家界的山上“长”满了韩国人?开封王婆为何火了主播靠辱骂母亲走红被批捕封号代拍被何赛飞拿着魔杖追着打阿根廷将发行1万与2万面值的纸币库克现身上海为江西彩礼“减负”的“试婚人”因自嘲式简历走红的教授更新简介殡仪馆花卉高于市场价3倍还重复用网友称在豆瓣酱里吃出老鼠头315晚会后胖东来又人满为患了网友建议重庆地铁不准乘客携带菜筐特朗普谈“凯特王妃P图照”罗斯否认插足凯特王妃婚姻青海通报栏杆断裂小学生跌落住进ICU恒大被罚41.75亿到底怎么缴湖南一县政协主席疑涉刑案被控制茶百道就改标签日期致歉王树国3次鞠躬告别西交大师生张立群任西安交通大学校长杨倩无缘巴黎奥运

深圳SEO优化公司 XML地图 TXT地图 虚拟主机 SEO 网站制作 网站优化