The following warnings occurred: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Warning [2] Undefined array key "avatartype" - Line: 783 - File: global.php PHP 8.1.31 (Linux)
|
Virus Detected - Printable Version +- Form Tools (https://forums.formtools.org) +-- Forum: Form Tools (https://forums.formtools.org/forumdisplay.php?fid=1) +--- Forum: General Discussion (https://forums.formtools.org/forumdisplay.php?fid=5) +--- Thread: Virus Detected (/showthread.php?tid=1849) Pages:
1
2
|
Virus Detected - teamwebb2007 - Jan 10th, 2012 Can't use the product because of a virus. Anyone else having this problem!! If consistently being attacked will not be able to use anymore. RE: Virus Detected - Ben - Jan 10th, 2012 Hi Teamwebb, Sorry - could you provide a little more info about precisely what's happening? Are you running anti-virus software on your computer? Also, I received an email from someone else claiming that your post in these forums was recognized as containing a virus (AVG identified it as malicious). So whatever has affected your browser is possibly also infecting content that you see through your browser. What makes you think this has anything to do with Form Tools? I really don't think they're related. Good luck...! Viruses are an unbelievable pain. - Ben RE: Virus Detected - Ben - Jan 10th, 2012 Hi Teamweb, I'm so sorry - this was again a problem on our end. Fixed now. This last month after the last time the site was hacked, I've been working on re-structuring of the site to prevent this from occurring; but the new site isn't rolled out yet (with > 12,000 files, > 2GB of repository content it's a HELL of a lot of work). Did you do an upgrade this morning? Feel free to write to me at ben.keen@gmail.com - Ben RE: Virus Detected - daz1034 - Jan 10th, 2012 Hay ben i upgraded today i found this Code: (function(b){var e,d,a=[],c=window;b.fn.tinymce=function(j){var p=this,g,k,h,m,i,l="",n="";if(!p.length){return p}if(!j){return tinyMCE.get(p[0].id)}p.css("visibility","hidden");function o(){var r=[],q=0;if(f){f();f=null}p.each(function(t,u){var s,w=u.id,v=j.oninit;if(!w){u.id=w=tinymce.DOM.uniqueId()}s=new tinymce.Editor(w,j);r.push(s);s.onInit.add(function(){var x,y=v;p.css("visibility","");if(v){if(++q==r.length){if(tinymce.is(y,"string")){x=(y.indexOf(".")===-1)?null:tinymce.resolve(y.replace(/\.\w+$/,""));y=tinymce.resolve(y)}y.apply(x||tinymce,r)}}})});b.each(r,function(t,s){s.render()})}if(!c.tinymce&&!d&&(g=j.script_url)){d=1;h=g.substring(0,g.lastIndexOf("/"));if(/_(src|dev)\.js/g.test(g)){n="_src"}m=g.lastIndexOf("?");if(m!=-1){l=g.substring(m+1)}c.tinyMCEPreInit=c.tinyMCEPreInit||{base:h,suffix:n,query:l};if(g.indexOf("gzip")!=-1){i=j.language||"en";g=g+(/\?/.test(g)?"&":"?")+"js=true&core=true&suffix="+escape(n)+"&themes="+escape(j.theme)+"&plugins="+escape(j.plugins)+"&languages="+i;if(!c.tinyMCE_GZ){tinyMCE_GZ={start:function(){tinymce.suffix=n;function q(r){tinymce.ScriptLoader.markDone(tinyMCE.baseURI.toAbsolute(r))}q("langs/"+i+".js");q("themes/"+j.theme+"/editor_template"+n+".js");q("themes/"+j.theme+"/langs/"+i+".js");b.each(j.plugins.split(","),function(s,r){if(r){q("plugins/"+r+"/editor_plugin"+n+".js");q("plugins/"+r+"/langs/"+i+".js")}})},end:function(){}}}}b.ajax({type:"GET",url:g,dataType:"script",cache:true,success:function(){tinymce.dom.Event.domLoaded=1;d=2;if(j.script_loaded){j.script_loaded()}o();b.each(a,function(q,r){r()})}})}else{if(d===1){a.push(o)}else{o()}}return p};b.extend(b.expr[":"],{tinymce:function(g){return g.id&&!!tinyMCE.get(g.id)}});function f(){function i(l){if(l==="remove"){this.each(function(n,o){var m=h(o);if(m){m.remove()}})}this.find("span.mceEditor,div.mceEditor").each(function(n,o){var m=tinyMCE.get(o.id.replace(/_parent$/,""));if(m){m.remove()}})}function k(n){var m=this,l;if(n!==e){i.call(m);m.each(function(p,q){var o;if(o=tinyMCE.get(q.id)){o.setContent(n)}})}else{if(m.length>0){if(l=tinyMCE.get(m[0].id)){return l.getContent()}}}}function h(m){var l=null;(m)&&(m.id)&&(c.tinymce)&&(l=tinyMCE.get(m.id));return l}function g(l){return !!((l)&&(l.length)&&(c.tinymce)&&(l.is(":tinymce")))}var j={};b.each(["text","html","val"],function(n,l){var o=j[l]=b.fn[l],m=(l==="text");b.fn[l]=function(s){var p=this;if(!g(p)){return o.apply(p,arguments)}if(s!==e){k.call(p.filter(":tinymce"),s);o.apply(p.not(":tinymce"),arguments);return p}else{var r="";var q=arguments;(m?p:p.eq(0)).each(function(u,v){var t=h(v);r+=t?(m?t.getContent().replace(/<(?:"[^"]*"|'[^']*'|[^'">])*>/g,""):t.getContent()):o.apply(b(v),q)});return r}}});b.each(["append","prepend"],function(n,m){var o=j[m]=b.fn[m],l=(m==="prepend");b.fn[m]=function(q){var p=this;if(!g(p)){return o.apply(p,arguments)}if(q!==e){p.filter(":tinymce").each(function(s,t){var r=h(t);r&&r.setContent(l?q+r.getContent():r.getContent()+q)});o.apply(p.not(":tinymce"),arguments);return p}}});b.each(["remove","replaceWith","replaceAll","empty"],function(m,l){var n=j[l]=b.fn[l];b.fn[l]=function(){i.call(this,l);return n.apply(this,arguments)}});j.attr=b.fn.attr;b.fn.attr=function(n,q,o){var m=this;if((!n)||(n!=="value")||(!g(m))){return j.attr.call(m,n,q,o)}if(q!==e){k.call(m.filter(":tinymce"),q);j.attr.call(m.not(":tinymce"),n,q,o);return m}else{var p=m[0],l=h(p);return l?l.getContent():j.attr.call(b(p),n,q,o)}}}})(jQuery); in modules / field_type_tinymce / tinymce / jquery.tinymce.js RE: Virus Detected - teamwebb2007 - Jan 10th, 2012 Email sent. (Jan 10th, 2012, 1:29 PM)daz1034 Wrote: Hay ben i upgraded today i found thisWhat the heck is that??? RE: Virus Detected - daz1034 - Jan 10th, 2012 I don't know am not sure if it happened in to days upgrade or was there be for as we don't normally use tinymce part of formtools. Am sure ben will sort it out RE: Virus Detected - Ben - Jan 10th, 2012 Daz - Yes, that's malicious. Here's what to do. 1. Download the latest zipfile from here: http://www.formtools.org/download.php 2. Unzip it locally, and delete the /install folder. Then, upload the entire contents to your website, overwriting the old files. 3. In your download package, did you upgrade any modules as well? You should manually update those as well. The problem is now fixed on the site, but I'm taking the Upgrade and Custom Build scripts offline until the new website is rolled out. I'm *exceedingly* sorry - and very distressed there's still a backdoor somewhere on the site that's allowing the hacker in. The problem is, it's very difficult to know where the flaw resides. As mentioned, there are thousands of files on the site, any one of which may be compromised. I noticed that myBB (the maker of these forums) encountered the exact same problem back in October of last year (http://blog.mybb.com/2011/10/25/some-closure-on-the-1-6-4-security-vulnerability/). I've contacted them; perhaps they may shed some light as to the cause. - Ben [EDIT: also, you'll need to clear your browser cache after updating all the files]. RE: Virus Detected - daz1034 - Jan 10th, 2012 can i ask what it does as we have a lot of sensitive data in formtools and would like to know so i can work out how best to word this to my bosses Thanks for the fast reply as well ben i now how much of a nightmare this can be RE: Virus Detected - Ben - Jan 10th, 2012 Hi Daz, Quote:can i ask what it does as we have a lot of sensitive data in formtools and would like to know so i can work out how best to word this to my bosses Absolutely, I totally understand. Give this post a read through: http://www.formtools.org/wordpress/?p=599 I *very* much doubt your data is at risk. From everything I can learn about it, it's just sending info about your browser environment and could possibly insert ads/junk. Please let me know if you have any other questions. - Ben RE: Virus Detected - daz1034 - Jan 10th, 2012 Your a star thanks a lot I can now sleep to night. Once again thanks for you help and fast replys you need a medal |