Exe downloading regardless of settings

Report & discuss bugs found in SABnzbd
Forum rules
Help us help you:
  • Are you using the latest stable version of SABnzbd? Downloads page.
  • Tell us what system you run SABnzbd on.
  • Adhere to the forum rules.
  • Do you experience problems during downloading?
    Check your connection in Status and Interface settings window.
    Use Test Server in Config > Servers.
    We will probably ask you to do a test using only basic settings.
  • Do you experience problems during repair or unpacking?
    Enable +Debug logging in the Status and Interface settings window and share the relevant parts of the log here using [ code ] sections.
Post Reply
modem7
Newbie
Newbie
Posts: 2
Joined: June 17th, 2020, 9:44 am

Exe downloading regardless of settings

Post by modem7 »

Hi guys,

I've got an odd one.

I've got Sonarr downloading the anime "Tower of God", even though the file inside contains a (presumably malicious) exe.

My settings include exe in unwanted extensions, and it certainly works with things from app categories, but for some reason it's allowing this one through.

The full file name in this case is: "[HorribleSubs] Tower of God - 12 [1080p].mkv.exe" (there have been others of different episodes, obviously a malicious bot).

Just curious as to what I'd be able to do, or if this is a bug within Sab.

Running Sab on Docker, latest linuxserver version.
User avatar
safihre
Administrator
Administrator
Posts: 5366
Joined: April 30th, 2015, 7:35 am
Contact:

Re: Exe downloading regardless of settings

Post by safihre »

Maybe you can share the NZB here (since it's a fake anyway)?
Put spaces in the URL to avoid the "not allowed to post urls" detection.
If you like our support, check our special newsserver deal or donate at: https://sabnzbd.org/donate
modem7
Newbie
Newbie
Posts: 2
Joined: June 17th, 2020, 9:44 am

Re: Exe downloading regardless of settings

Post by modem7 »

Sure thing!

In case you guys aren't signed up to drunkenslug etc, I've put it on my dropbox for easier access.

https : // www . dropbox . com /s/iwh6ai72c6q35dr/%5BHorribleSubs%5D_Tower_of_God__-__12_%5B1080p%5D .nzb?dl=0

But if you are and feel more comfortable doing so:

https : // drunkenslug .com /details/aa81d86862627e4cc9f49d412abd357aac81404e
User avatar
sander
Release Testers
Release Testers
Posts: 8830
Joined: January 22nd, 2008, 2:22 pm

Re: Exe downloading regardless of settings

Post by sander »

Ah ... https://www.dropbox.com/s/iwh6ai72c6q35 ... D.nzb?dl=0 ... the exe is in plain sight as file in the NZB. Not hidden somewhere in the rar's, for which I once programmed that feature Unwanted Extensions.

This could/should be handled at the moment of importing the NZB, @safihre ... ? Using the same extension list that's already there?
User avatar
safihre
Administrator
Administrator
Posts: 5366
Joined: April 30th, 2015, 7:35 am
Contact:

Re: Exe downloading regardless of settings

Post by safihre »

Agreed!
Created a feature request:
https://github.com/sabnzbd/sabnzbd/issues/1513
If you like our support, check our special newsserver deal or donate at: https://sabnzbd.org/donate
User avatar
sander
Release Testers
Release Testers
Posts: 8830
Joined: January 22nd, 2008, 2:22 pm

Re: Exe downloading regardless of settings

Post by sander »

@modem7 It is fixed now in the SABnzbd github version, see https://github.com/sabnzbd/sabnzbd/pull/1515

The next release of SABnzbd will contain the fix.

Thanks for reporting and providing the NZB.
Post Reply