Support

Admin Tools

#21549 PHP File Change Scanner Modified Every Time

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by DaveOzric on Wednesday, 26 November 2014 11:43 CST

DaveOzric
Hello, I read the section on PHP file scanning and am getting a different result than expected on some websites. Some websites show zero modified files even after many weeks between scans. Other sites show them between consecutive scans one after another.

This is the documentation that is confusing me.

When a file change is detected. A file change is detected only if the file is added or modified since the immediately previous scan. This means that if you scan now, modify a PHP file and scan again, it will show up as modified. If you perform a third scan right after the second one, the file will NOT be reported as changed. This is normal! The file was changed between the first and second scan, but not between the second and third scan.

Here's the result I am looking at for the site that keeps showing modified files.


A site that does not.


Also on the site that is showing modified on every scan I have enabled DIFF but opening the report and clicking on a file I see no link to the changes.

If you have enabled the diff feature in the component's configuration page and this is a Modified file, you will also see the Diff to the previous version pane. On this pane you will see the consolidated differences between the scanned file and its previous state.

Thank you

nicholas
Akeeba Staff
Manager
Please take a careful look at the screenshots. The site which insists that 96 files are modified also reports that 96 files are possible threats. They will always be displayed as modified until you go ahead and mark them as safe. Click on View Report to see the suspicious files, then follow our documentation instructions to make sure they are really safe. Then you can mark them as safe.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

DaveOzric
That was my goal by trying to compare the diffs in these. I just launched the site yesterday so I am fairly certain it has not been compromised in any way?

Where can I see the file changes if they are modified as it states. Or am I not understanding the documentation that says you can see the changes in the files marked modified.

Also why are some sites that have been up for years not showing anything (all zeros)

Thank you

nicholas
Akeeba Staff
Manager
Where can I see the file changes if they are modified as it states.


Click on the View Report button. Then you will see all scanned files. You can filter by Threat Score descending and Marked as Safe set to No to get the unsafe files shown first. Then check them and mark them as safe.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

DaveOzric
In view report I select "Modified" from the selection dropdown and it shows No records found

The page showing the scans shows 96 modified for that scan but the report shows no modified records. I am confused.

Another part of my confusion is the difference between different sites. The site from the screenshot above shows a scan that was from a Joomla 2.5 site and the last one was after it was upgraded to Joomla 3 with over a year between scans. How could zero files have been modified?

Thanks for your patience.

nicholas
Akeeba Staff
Manager
I think that the files cache may have been corrupt. Please click the "Purge file cache" button at the toolbar of the PHP File Change Scanner page and run a new scan. You will need to go through all potential threat files again.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

DaveOzric
That worked one time and now it's back to reporting the 96 modified.

Still very confused how one site over a year old has never had a modified file when new site has 96 in a month.

I guess I'll just leave it at AT is protecting my site and file scanner makes no sense to me.

Thanks for your help.

nicholas
Akeeba Staff
Manager
Sorry, I can't reproduce this issue.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

DaveOzric
No worries, just checking due to the JoomDonation issue. I don't think I have any issues related to these hackers. It's just some fear tactics.

Thanks

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!