Forum Replies Created

Viewing 15 replies - 436 through 450 (of 2,029 total)
  • Plugin Author Eli

    (@scheeeli)

    Ok, I see the live site now…

    The first thing I noticed was this error:
    Fatal error: Uncaught Error: Call to undefined function wp_foots() in …wp-content/themes/genesis/footer.php on line 56

    I didn’t see that redirect script until I looked at some of the sub-pages. Now I see that the remaining malicious scripts were probably injected directly into your page content.

    I have added these new script references to my definition updates so they should be found by the Complete Scan now, and you can remove them using the Automatic Fix.

    If they are still not found then please let me know and I will look for another source for this malicious output.

    Plugin Author Eli

    (@scheeeli)

    Sorry, but I still only see your holding page so I can’t see any signs that your site is still infected.

    What specifically are you seeing that indicates that your site is still infected?

    Plugin Author Eli

    (@scheeeli)

    It looks like it cleaned some stuff, did you “Force a Re-scan” to clear the cache on that sucuri page after you cleaned the site?

    It looks like you just have a holding page up now. How do you know that you are still infected?

    This threat is usually triggered from a malicious include in your theme’s functions.php file. Can you check the Anti-Malware Quarantine to see if that was found and cleaned?

    If you want to share anything with me that you don’t want to post on this public forum then you can email me directly:
    eli AT gotmls DOT net

    Plugin Author Eli

    (@scheeeli)

    Sorry @minhternet,
    I did my best get a moderator to help you with the edit you wanted but I think I might have pissed her off (Sorry Jan, just trying to help Minh out).

    Anyway, I would suggest that you at least change your admin username again so that this info you posted would not help someone to brute-force your password.

    Plugin Author Eli

    (@scheeeli)

    @jdembowski,
    I think that the POST_log is the most private value that should be removed.

    Plugin Author Eli

    (@scheeeli)

    Ok, got you email, thanks for confirming that deactivating the “false blog admin” protection in the firewall restored the full functionality and there no more CORS errors.

    It looks like this protection might interfere with any plugin that uses the 3rd-party “Freemius class” that has not been since before 2016.

    I am trying to find a good way to locate this class in plugins and determine in which ones this exploit is still a vulnerability.

    Please let me know if you can figure out which of your plugins uses this Freemius class.

    Plugin Author Eli

    (@scheeeli)

    Thanks for reporting this. I would like to verify that this was isolated to a single Firewall rule violation and confirm that it was do to a vulnerability in another plugin.

    First, you would only need to Disable the “False blog_admin” Protection in the Firewall Options to suspend this odd behavior, it is not necessary that you deactivate the whole GOTMLS plugin.

    More important, is that this firewall rule is in place to stop the known exploit of a plugin called “WP Cost Estimation & Payment Forms Builder”. This plugin can be exploited and used by anyone (even a non-authenticated user) to upload and execute PHP code. This particular firewall rule prevents this exploit but it may interfere with the functionality of this vulnerable plugin as well.

    If you are willing to help me get to the bottom of this then I would like to work with you to verify the deficiencies and improve this firewall rule.

    Can you please confirm if you have the WP Cost Estimation & Payment Forms Builder plugin installed on this site?

    Also, would you be willing to re-activate the GOTMLS plugin and then disable the False blog_admin Protection in the Firewall Options to make sure that everything works as expected?

    Plugin Author Eli

    (@scheeeli)

    Don’t you think that the POST_log is the most private value that should be removed?

    Plugin Author Eli

    (@scheeeli)

    It shows his POST_log (login) and REMOTE_ADDR mainly but the whole think can be removed.

    Plugin Author Eli

    (@scheeeli)

    Thanks for your email. I glad that you were able to getting it working.

    Unfortunately, Only a WP Moderator can edit your post now. I am tagging the following people who are moderators and might be able to help remove your private data from that URL that you posted.

    @jdembowski @macmanx @anevins @sterndata

    Plugin Author Eli

    (@scheeeli)

    Hi Minh,
    There were issues with the NO_HTTP_REFERER error coming up on some iPad devices but that was fixed in the latest version of my plugin and I’m not sure that it was even relevant to Firefox on a OS X anyway, but I see that you are using an older version and so the first thing you should try is to update my plugin to the latest release. You can also try logging in with a different computer (I do not get that redirect page when I fail to login to your site from my PC).

    Secondly, There does seem to be some missing hidden fields on the login page for your site and it does not seem to be outputting the right HTML form if you have the Brute-force Login protection turned on in the Anti-Malware Fire Settings. There must be some other plugin or manipulative code that is altering your login page and interfering with my plugin. Do you have any caching plugin enabled?

    You should start by deactivating and deleting my plugin from your site. You can simply delete the gotmls folder from the plugins directory on your server using FTP or the File Manager in your hosting control panel if you cannot get into your wp-admin. Then you can login to your wp-admin and install my Anti-Malware plugin again. Then I would suggest that you got to the Firewall Options and Disable the Brute-Force protection right away. Then test your login page and re-enable the protection while you can test the login from the original Mac while you are still logged in and can disable it again if it still does not work. You can also do more testing by disabling any caching on your site and deactivating any other plugins that might be interfering.

    Please let me know what you find, and if you need any more help, you can also contact me directly:
    eli AT gotmls DOT net
    … especially if you want to share any info that you don’t want on this public forum. You only needed to provide me with the error number 147229470 for me to know what the problem was, all that other info in the safe-load URL that you posted might give away personal details that you don’t really want to have out there. If you can I would suggest editing your post and removing that safe-load URL.

    Plugin Author Eli

    (@scheeeli)

    Your inability to upload new posts does sound unrelated as my plug-in has nothing to do with that functionality. But delete my plug-in and confirm that is unrelated.

    I am not sure what that first image suggests and I don’t understand what you mean by “met by this icon when I enter the plugin section”.

    The query seems successful but reports Zero Records were updated so I’m not sure if that’s because you already ran it before that or you are running it on the wrong table. Are you sure that wp8m_options is the right table?

    Make sure that you have deleted the entire plug-in from your site, and confirm that everything works as expected. Then try reinstalling the newest version of the plugin from the add plug-in feature on the plugins menu within your wp-admin.

    If you need to send me any data that you’re not comfortable posting here you can contact me directly:
    eli AT gotmls DOT net

    Plugin Author Eli

    (@scheeeli)

    Make sure to use regular single quotes around the last value in the SQL string, not the fancy curly quotes that this forum uses

    DELETE FROM wp_options WHERE option_name LIKE 'gotmls_definitions_%'

    also, if you try the new version you cannot just replace the older version with the new files via FTP. The old version of the plugin must be deleted, and then you can go into your wp-admin and install the new version through your plugins menu. Then, when you activate the new plugin it will purge the old definitions.

    Plugin Author Eli

    (@scheeeli)

    You can now download version 4.18.63 to force the updates to reset which will fix this issue.

    Plugin Author Eli

    (@scheeeli)

    As I said, you can delete all the GOTMLS definitions in your DB and then you can reactivate the plugin.

    In PhpMyAdmin you can run a query like this to purge the old updates:
    DELETE FROM wp_options WHERE option_name LIKE ‘gotmls_definitions_%’

Viewing 15 replies - 436 through 450 (of 2,029 total)