Eli
Forum Replies Created
-
It looks like your scans are getting stuck on the DB Scan. To verify this you could un-check the Database Injections option under “What to look for”. and run the Complete Scan to see if it finishes.
If your server is having issues only on the DB Scan then it is probably something to do with the settings or limitations on the DB server. Maybe it’s a low memory limit or a query time limit. How many records do you have in your wp_posts table?
Forum: Plugins
In reply to: [Anti-Malware Security and Brute-Force Firewall] FW_TraversalI have not seen any emails from you yet and I look forward to helping you find the solution to this issue. Please let me know if you figure it out or if you need more help.
Forum: Plugins
In reply to: [Anti-Malware Security and Brute-Force Firewall] FW_TraversalMaybe it was something like /etc/ or maybe it was a hidden field.
If this is a consistent and repeatable occurrence then maybe you could provide me with HTML of the completed form that is getting blocked/redirected so that I can check it against the current firewall pattern to see what it causing it to be flagged as a directory transversal?
You can email me with any content examples if you don’t want it to be posted on this public forum:
eli AT gotmls DOT netForum: Plugins
In reply to: [Anti-Malware Security and Brute-Force Firewall] FW_TraversalThis is the Directory Transversal protection in the Firewall Options. This feature prevents the submission of any variable that contains ../ in the value, which protects you against the potential exploitation of some themes and plugins that might otherwise allow a hacker to read or write to an arbitrary file on your server.
You can look into the contents of the form that you posted on your site that got redirected and see if you can spot the usage of ../ in one of that field values, or you can just turn this feature off on the Firewall Options page in your wp-admin (but understand that you may be leaving your site open to a directory transversal attack if you have any vulnerable plugins or theme feature that could be exploitable if you turn off this option).
Feel free to write back with more detail if figure out why this form was getting blocked or if you need more help to figure it out.
Forum: Plugins
In reply to: [Anti-Malware Security and Brute-Force Firewall] Gdpr and privacy policyNo, as my plugin does not store any cookies I have no need to make a page that discloses cookies.
Why would your policy need to link to or reference every single plugin you use on your site? I think you only need to disclose your usage of cookies and that of any other plugin that you utilize which also uses cookies.
Forum: Plugins
In reply to: [Anti-Malware Security and Brute-Force Firewall] Gdpr and privacy policyMy plugin does not store any cookie data for any visitors who come into contact with your site.
Please let me know if that does not cover it and you need any more info.
I think I have fixed this issue but I’m not sure why this file was identified as a known threat in the first place. Can you both please confirm what version of PHP is installed on your server?
Also, please download the latest definition updates and then run the Complete Scan again to confirm that this file is no longer detected as a known threat.
I would like to help you fix this issue but I will need to see the whole of the malicious code that was injected in that file.php …
Can you please email that infected file so that I can see what is going wrong with it?You can email me the whole file with the infection in it directly to me:
eli AT gotmls DOT netForum: Plugins
In reply to: [Anti-Malware Security and Brute-Force Firewall] GOTMLS no longer working?This looks like a new threat that might not be in my latest definitions. Can you please send me the full contents of one of those files so that I can add this new threat to my definition updates?
You can email the infected file or files to me directly:
eli AT gotmls DOT netThanks,
There is not as much of a need for plugin updates as you might think. My plugin works well and you can download definition update of new threats without updating the core plugin code. Therefore, there are only plugin updates when I an releasing a completely new feature or fixing a bug in the program. I am working on a few new feature that I hope to release soon, so there will actually be a new plugin update as soon as I have finished and tested these updates.Rest assured, the current version of my plugin if fully compatible with the latest release of WordPress, and I am constantly releasing new definition updates as new threats emerge.
That issue was caused by a false positive that I corrected this morning in my latest definition updates. Please make sure you have download the latest definition updates on all your sites before scanning again. Sorry for the inconvenience.
Thanks so much for reporting this. Yes, this is a false positive in the definition updates that I released last night. I have just released a new definition update to correct this issue. Please download the latest definition updates ( L3I4w ) before running the scan again.
Sorry for any trouble this might have caused and thanks again for spotting my mistake and bringing it to my attention.
Aloha, Eli
Forum: Plugins
In reply to: [Anti-Malware Security and Brute-Force Firewall] Full scan stuck at 0%A screenshot would be helpful so that I would see what it’s getting stuck on. There could be interference from another plugin, so it would great if you can open the Console tab in your browser’s Inspector so that we can see if it’s a JavaScript error. If there are no JavaScript errors then you can check the error_log files on your server for any PHP errors that might shed some light on why it’s getting stuck.
You can send any of these further details directly to me if you don’t want to post that stuff on this public forum.
eli AT gotmls DOT netForum: Plugins
In reply to: [Anti-Malware Security and Brute-Force Firewall] shedule scanI have been steadily working towards a scheduled scan feature but this has proved more difficult to implement than I had thought and I will need more time to work transform the scan engine so that it can run without a browser console. Also, a lot of thing in my life have changed so I have not had as much free time lately to work on new features. Life happens ;-/
Yes, you can delete the records in your Anti-Malware Quarantine, but these are just records of the infections and they are not dangerous to keep. It can also sometime prove to be very helpful to have these records to refer to if you need to track down the source of any recurring infections.
To delete all quarantine records just check the box next to “Check all Items in Quarantine”, then click the red Delete button, then you can click the link to Purge the deleted records if you are sure that you want to completely erase all the records of these infected files.
Forum: Plugins
In reply to: [Anti-Malware Security and Brute-Force Firewall] Skipped PagesMost of those files were probably skipped because they are binary file types that cannot be executed directly by your web-server. Therefore, it would be a waste of your time and your server’s resources to scan the contents of all those files for malicious code. You can also hover your mouse over those files on the skipped list to see the reason that each one was skipped. If you have any further questions about any specific files you can email me and I can give you a more specific answer.
eli AT gotmls DOT net