Forum Replies Created

Viewing 15 replies - 421 through 435 (of 2,029 total)
  • Plugin Author Eli

    (@scheeeli)

    The first step is to determine if this infection is coming from another internal file on your site or from another site. Check the timestamps on the latest infected file to see exactly when it was infected (before you clean the file). If you have already cleaned the infection with my plugin then you can find the exact infection time in the Anti-Malware Quarantine (times are recorded as GMT). Then cross-reference that time with any activity in your access_log file at the same exact time (keep in mind that your log file times might be adjusted for your server’s local time).

    If there is nothing in your access_log for the times of your last infection then you will know that this infection is spreading from another site to yours (probably another site on your server). Typically, shared hosting accounts are not protected from cross-contamination, so infections from one vulnerable site can easily spread to other sites on the same server (even if they are on another account).

    If you find a suspect in you log files please send it to me for further examination. If not then you should move your site to another (more secure) server.

    Plugin Author Eli

    (@scheeeli)

    @adiboo67,
    I am sorry that you had to wait 14 hours for my reply, but I was asleep when you posted this. Please understand that I am only one person and I can only support my plugin when I am awake. I have reviewed the information you posted here and looked at your site. I can see this malicious script in your header in the midst of other scripts which are supposed to be there. This malicious script is already in my definition update, so I am not sure why it is not finding it on your site, but I would like to help you get to the bottom of this. If you have downloaded the latest definition and it the Complete Scan is still not finding it then there are two possibilities I can think of: either this script is further encrypted and obfuscated in some new way; or it’s now hiding in any of the file on your site, but rather stored in your database and dumped out in your HTML by some vulnerability in your theme or plugins.

    Can you please send you the header.php file for your active theme? If it’s not there I would need to know what other plugins you have installed.

    You can email files directly to me: eli AT gotmls DOT net

    @kalantor,
    I saw and replied to your post on my own forum asking for your domain, and you have not posted it there either. You said there that you have emailed me but I have no emails from you. Please try emailing me from another address and I will check my spam folder.

    Plugin Author Eli

    (@scheeeli)

    I don’t see any redirects on your site. Are you sure it’s not just cached on your side or somehow caused by your browser?

    Can you link to any outside reference to this redirect so that I can see what evidence of malware that you are reacting to?

    Plugin Author Eli

    (@scheeeli)

    It looks like your site is clean now. Google might be responding to their cache from before. What does Webmaster Tools say (Google Search Console)?

    Plugin Author Eli

    (@scheeeli)

    Those two JS files were found to be safe in other cases but the read errors were caused by the memory_limit being set too low in the php.ini file on your server.

    What malware is still persistent on your site?

    What is your site or what URL is still infected?

    Plugin Author Eli

    (@scheeeli)

    Make sure that you have downloaded the latest definition updates. Then, if the scan finds any known threats, you will see an automatic fix button.

    If you think that this was done correctly but you’re not seeing the button then please post a screenshot of what you do see so that I can tell what’s wrong.

    Plugin Author Eli

    (@scheeeli)

    Sorry for the confusion but there are actually two fields on that line of the registration form. If you cannot see the borders of each field that separates the left side of the name field from the right side then just try entering your last name into the right side of that field (or after entering your first name on the far left just hit the Tab key on your keyboard and then enter your last name ; – )

    Plugin Author Eli

    (@scheeeli)

    This CORS Error has been fixed by altering my Firewall rules but you will want to make sure that this API of your’s does not misuse the FW__fs_blog_admin parameter to validate admin authorization falsely. It has been discovered that some plugins that use the older Freemius Class without understanding the potential vulnerability.

    Plugin Author Eli

    (@scheeeli)

    Thanks for sending me that log file. I can see that the code that was found as malicious in your log files was “eval($_REQUEST[1])”, which is very certainly malicious code. Of course it is unlikely that this code in your log file could be a direct threat but it is an indication of a malicious attack on your site.

    It is also unusual that those access_log files would be in a directory that is inside your site_root, thus being in the scan results at all. However, seeing these malicious injection attempts in your logs does shed some light on the nature of the attacks. It would seem that they were intending to infect a Joomla site so I don’t think anything they attempted was successful.

    You might want to confirm that your log files are placed outside your site_root so that they are not publicly accessible though.

    Plugin Author Eli

    (@scheeeli)

    Again, when I run the re-scan feature on sucuri it says that your site is now clean as well.

    Plugin Author Eli

    (@scheeeli)

    That’s a great question. my plugin scans the contents of any files in the scan path, looking for patterns that match Known Threats. I cannot say why your access_log files were flagged as a threat without see the contents for myself.

    If you want to send me one of these files I can give you a better answer. You can email those files directly to me:
    eli AT gotmls DOT net

    To be honest I am quite curious myself as to why those logs would have matching threat patterns in them so I look forward to your email.

    Plugin Author Eli

    (@scheeeli)

    Hi Jonney,
    I’m very sorry but I do not understand your question. How is “Loco translate” compatible with my Anti-Malware plugin?

    I don’t know what you mean. How is it not compatible?

    Please describe the symptoms you are experiencing so that I can better understand the underlying problem which lead you to ask this question (a screenshot might help too).

    Plugin Author Eli

    (@scheeeli)

    It’s hard to say where that output buffer handler is being called from or even if it is even a problem.

    First, does the Complete Scan work, does it finish, and how long does it take?

    If you can run the scan, does it find any Known Threats?

    If not then you might want to go through and disable each of your plugins one ata time, checking to see if that message goes away.

    Please let me know what you find and if you need more help you can also email me directly:
    eli AT gotmls DOT net

    Plugin Author Eli

    (@scheeeli)

    I’m sorry to tell you but I would guess that more than just the two sites you spoke of are infected on this server. It likely that there are many other infected site (on other accounts if not your own) or maybe even a root hack on the server.

    I would strongly suggest that you find a more secure hosting environment to move your sites to where you can be sure that they will not be reinfected again.

    You can email me directly if you need more direct help:
    eli AT gotmls DOT net

    Plugin Author Eli

    (@scheeeli)

    Looks like the same stuff on that other site.

    Lit me know if it doesn’t come clean after the scan (be sure to clear the cache after the auto-fix).

Viewing 15 replies - 421 through 435 (of 2,029 total)