是否建议从 Launch4j 签署您的 exe?

发布于 2025-01-14 13:40:03 字数 507 浏览 7 评论 0原文

使用 Launch4j 从 jar 创建 exe 文件后,我注意到以下消息:

警告:对可执行文件进行签名以最大程度地减少防病毒误报或使用启动而不是包装。

所以我开始研究如何签名,并最终让它发挥作用。 但现在我想知道,我现在没有任何误报吗?

我将签名的 exe 文件上传到 VirusTotal,得分为 2/64(Cylance 将其标记为不安全,SecureAge APEX 将其标记为恶意) 当然,我从来没有听说过他们中的任何一个,所以我并没有小题大做。

但我想知道此时原始(未签名)exe 的分数是多少,所以我上传了它并得到了 0/66 的分数(包括 Cylance 和 SecureAge APEX)

是否还有其他原因让您想要签署您的 jar文件?此时,我更倾向于分发未签名的版本,因为与签名的版本相比,它在 VirusTotal 上提供了更高/完美的分数,万一其中一个用户实际上想在某个时候查看它,这会更好地反映我的程序,即使它只是来自相对不知名的提供商的 2/64。

After creating my exe file from my jar using Launch4j, I noticed this message:

WARNING: Sign the executable to minimize antivirus false positives or use launching instead of wrapping.

So I started digging into how to sign it, and finally got that to work as well.
But now I was wondering, do I now not have any false positives?

I uploaded the signed exe file to VirusTotal and got a score of 2/64 (Cylance marked it as Unsafe, and SecureAge APEX marked it as Malicious)
Granted I have never heard of either of them, so I wasn't making a big deal out of it.

But I wondered what the score would be of the original (unsigned) exe at this point, so I uploaded that and got a score of 0/66 (including Cylance and SecureAge APEX)

Is there any other reason you would like to sign your jar file? At this point I am more tempted to distribute the non-signed one as it provided a greater/perfect score on VirusTotal opposed to the signed one, incase one of the users actually wanted to check it out at some point this would reflect much better on my program, even if it was only a 2/64 from a relatively unknown provider.

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文