What's new

scMerlin scMerlin 2.5.7 - Service and script control menu for Asuswrt-Merlin, September 23, 2024

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

I've just run it again:
Code:
! Suspicious string found in file /tmp/var/wwwext/scmerlin/top.htm
Shows how random false positives are. I admit it does appear to be scMerlin related, but given that these are custom scripts i'm hardly surprised. These scripts should not be there on Asus firmware, and Asus firmware is what these scanners expect to see.
 
I've just run it again:
Code:
! Suspicious string found in file /tmp/var/wwwext/scmerlin/top.htm
Shows how random false positives are. I admit it does appear to be scMerlin related, but given that these are custom scripts i'm hardly surprised. These scripts should not be there on Asus firmware, and Asus firmware is what these scanners expect to see.
It’s probably finding the top output of a previous file string check from itself in the top.htm file displayed in scMerlin. Checking for vulnerabilities results in false positive vulnerabilities.
 
I have scMerlin installed. I ran the script from /tmp rather than from a FAT32 USB stick. I did not get a false positive.

The list of suspicious file strings is in the script:
Code:
suspicious_strings="8ewMqdWf9K|3deCSCIoaQ|NIwZI3pvmJ|Klq1BtftKC|gSqf7pcEQQ|asi\.sh|31\.170\.22\.195|asi\.ok|asi\.ko|1-arm-le-t|1-mips-le-t|e4DtOMgfOorTPVnvSXm1D|downl_crt.sh"
Quite the comprehensive list of malware there... 🙄
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top