-
Notifications
You must be signed in to change notification settings - Fork 37
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
yara addfile third_party/yara-rules-full.yar: invalid field name "imphash" #63
Comments
That's really interesting! I haven't tested it in OpenSUSE, but have in Arch Linux, which appears to be on yara 4.3.2-1. I'll see about installing a Tumbleweed VM to see what might be going on: my going theory is that 4.5.0 is incompatible with one of these two dependencies: In the meantime, if you want to try
That will disable the YaraFORGE 3rd party rules. |
I'm successfully using bincapz w/ yara v4.5.0 on macOS. I tried to start a Tumbleweed VM but it's not coming up for some reason, so I haven't yet been able to replicate this issue. |
I haven't been able to duplicate this yet - but I wonder if this may be due to a missing OpenSSL dependency: VirusTotal/yara-python#179 |
I do have OpenSSL, the library, installed, perhaps not the However, you can close this issue if you want. OpenSUSE Tumbleweed is a rolling release, thus it is a moving target. Running the tool with the third-party flag did make it work. (Sorry for closing and re-opening the issue... I've touched by mistake the touchpad, which had the mouse just over the "close with comment".) :) |
I don't think it will work, but can you try installing the My theory is that yara may only enable the One workaround I thought about is to change this from a fatal error to a warning, but it could mask a loss an unexpected loss in functionality. |
FWIW, I ran into this when testing #181 inside of a Wolfi container. Installing For anyone searching around on how to resolve the error, installing |
Cross-posting from the closed PROpenSSL's libraries are required for Yara (depending on the platform being used). A non-exhaustive list of Linux distributions and their respectie package names can be found below:
|
I've just compiled the tool as suggested in the README:
When running it on
/bin/true
it fails with:I am running OpenSUSE Tumbleweed, with the following packages:
The text was updated successfully, but these errors were encountered: