Support

Admin Tools

#10202 Suspicious Files

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by earthrat on Friday, 06 January 2012 12:41 CST

earthrat
I am greatly appreciative of the new scanner tool and have been running it on all my sites. I have one site that appears to be having all sorts of problems with files that have been flagged (260 total).

I know there is always diligence that needs to be addressed when looking at these reports and there will inevitably be false positives. At the top of the report is a file that is in Admin Tools and I decided to do some research on it.

The file in question is:

administrator/components/com_admintools/akeeba/platform/jfscan/engines/archiver/jfscan.php

I took this file from the suspicious site and compared it to one that it was not reported from another site and as far as I could tell there is nothing different between the two.

So is it fair to question if this tool is working properly? Or could there be variables that would be causing the report to go completely off the wall as it appears it has on this site?

I have added the file I tested that is being reported as infected for you to have a look at. I changed it to a txt file...

nicholas
Akeeba Staff
Manager
Did you read the documentation? If you didn't, first read how the scanner works, then take a look at how you should read the report, especially the "Threat Score" section. This explains some basics about how the scanner works.

Now, back to your question. Normally, jfscan.php should always have a threat over the top. This is the file of the PHP File Change Scanner engine. It contains all of the patterns it's looking for, therefore matches many of them, causing a huge false alert. On the site where it is not reported, try deleting all scans and re-scan your site. You should see that file reported. In both sites, you should compare this file with the file shipped with your version of Admin Tools. If there's no difference, it's safe and you should mark it as such.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

earthrat
Thanks Nic, yes I did read it but I will probably read it a few more times. I think where things are throwing me off is most sites I have run this on are showing 0 threat warnings. I have ran it a few times on the ones that show 0 but it always stays 0. This site in question has a different amount of threats every time I scan. I will do some more testing today and see if this levels out to a normal (as it were) amount (so to speak).

nicholas
Akeeba Staff
Manager
The first scan showing 0 threats doesn't sound right! For starters, jfscan.php should have a threat index off the charts. I would check the permissions on the folders and files of those sites, making sure that all directories can be listed and all .php files can be read from PHP.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

earthrat
This is weird as all theses sites are on the same domain. I will do some investigating and test more and let you know what I find out. I have ran this on 9 sites now and all but to of them came back with 0 threat warnings. Once was more in line with what I expected to see and then this one that I started this post with that had a huge amount of threat warnings.

earthrat
Sorry I meant that they was all on the same server..

nicholas
Akeeba Staff
Manager
It was the very first scan for all sites, right?

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

earthrat
Yes, I am going to revisit those sites and run it a few times to see what happens.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!