Skip to content

fix: FPs with lastLogin keyword - #52

Closed
azurit wants to merge 8 commits into
coreruleset:masterfrom
azurit:FP
Closed

fix: FPs with lastLogin keyword#52
azurit wants to merge 8 commits into
coreruleset:masterfrom
azurit:FP

Conversation

@azurit

@azurit azurit commented Jul 17, 2026

Copy link
Copy Markdown
Member

No description provided.

@azurit
azurit requested a review from EsadCetiner July 17, 2026 14:24

@EsadCetiner EsadCetiner left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Based on the tests, couldn't this false positive be fixed by adding @ to lastlogin?

@azurit

azurit commented Jul 18, 2026

Copy link
Copy Markdown
Member Author

Based on the tests, couldn't this false positive be fixed by adding @ to lastlogin?

@EsadCetiner Yes, probably, but I don't think the lastlogin keyword (without a space) is likely to cause many false positives, so I'd prefer to handle this with an exclusion rule rather than in core rules.

@EsadCetiner

Copy link
Copy Markdown
Member

@azurit The command based unix rules are generally known to be a bit noisy, so I think it's worth it to fight even the less-common false positives.

I can still merge this PR though as it'll fix the false positive for LTS users.

@EsadCetiner

Copy link
Copy Markdown
Member

Related to: coreruleset/coreruleset#4593

@azurit

azurit commented Jul 24, 2026

Copy link
Copy Markdown
Member Author

Resolved by coreruleset/coreruleset#4593.

@azurit azurit closed this Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants