TOPIC:

Watchful.li malware scan reports 2 files to check 4 years 3 weeks ago #175953

  • Topic Author
  • vthomas
  • Offline
  • Fresh Breezer
  • Fresh Breezer
  • Posts: 17
  • Thanks: 0
I have been happy w/Breezing Forms. Just started using Watchful.li Admin Software. The malware scanner reports 2 Breezing forms files to check ...

/components/com_breezingforms/facileforms.process.php Reason: Hidden eval()
/administrator/components/com_breezingforms/libraries/dropbox/native-api/Client.php Reason: assert()

Are these two 'reasons' actually code that you placed in those files, so all is OK? I've seen them on a two of my site's audits, so either (1) yes, this code is OK ... or (2) I have infected files on both sites.
I know the malware scanner is looking for possible malware, so could be a false positive.

Thank you, Vicky

Please Log in or Create an account to join the conversation.

Last edit: Post by vthomas. Reason: clarity

Watchful.li malware scan reports 2 files to check 4 years 3 weeks ago #175973

  • TheMuffinMan's Avatar
  • TheMuffinMan
  • Offline
  • Developer
  • Developer
  • Posts: 9740
  • Karma: 167
  • Thanks: 782
Hi,

that's false positive. Eval() isn't bad per-se, so isn't assert().

However, just by the blank amount of evals that watchful.li finds it isn't easy to find how your site got breached.

Additionally, I would do it the classic way to cross-check the results:

1. Write down all 3rd party extensions (templates, plugins, components, modules) that you have installed, including version numbers. I know that services like watchful.li can help on that but relying only on those tools isn't enough.

2. Do some web search about if any of those versions contain known security issues and update if possible.

3. Try to find uploaded files, especially those ending with .php that are not part of a joomla or an extension install (very hard, but do-able).
I am referring especially to files that reached your webspace through uploads, so I would check upload folders first

4. Read your access logs and try to spot the date, time and url of very the first attack attempt (that will actually help to spot what exact hole the attacker was using).

5. last but not least clear all infected files from malicious code.

Please let us know how it went, we can also have a look through your logs if you like.

Best Regards,
Markus
The following user(s) said Thank You: vthomas

Please Log in or Create an account to join the conversation.

Watchful.li malware scan reports 2 files to check 4 years 3 weeks ago #176032

  • Topic Author
  • vthomas
  • Offline
  • Fresh Breezer
  • Fresh Breezer
  • Posts: 17
  • Thanks: 0
Thank you! Happily, those are the only two files the malware scan identified. So, since those values are intentional and OK in those files, I don't think I have a breach.

I just wanted to insure that you those values were intentional and placed there by the Breezing Forms team.

Also, thank you for giving good info on how to check my site if I think I ever have a breach.

Please Log in or Create an account to join the conversation.

Last edit: Post by vthomas. Reason: clarity
  • Page:
  • 1
Moderators: ForumSupport
Time to create page: 0.045 seconds

BreezingForms Pro 1.4.7 for WordPress Released!

Available in the membership section.

Summer Sale!

Massive discounts on all subscriptions!

Get Your Subscription Here

Quick Links

Downloads

BreezingForms

ContentBuilder

BreezingCommerce

Templates

Documentation

BreezingForms

ContentBuilder

BreezingCommerce

Apprendre BreezingForms (French Community)

Apprendre et maîtriser BreezingForms par des tutoriels et exemples, le tout en français

breezingforms.eddy-vh.com

Questions et réponses sur les forums de l'AFUJ

AFUJ

Special Offer

Summer Sale! All subscriptions at a special price!

Includes prio support, all of our current and future Joomla!® extensions and Joomla!® templates for the duration of your membership.

Get it from here

3rd Party Discount - 25% Off

We help you to keep your costs under control. If you are a new member and purchased a form building tool from a different form vendor, then you'll get a 25% discount on our subscription plans.

How to receive the discount:

Send us a quick email to sales@crosstec.org with a proof of purchase (for example a paypal receipt), await payment instructions and enjoy your membership!