Support

Admin Tools

#23391 backend/views/cpanel/tmpl/default.php detected as malware on Infomaniak

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by appnweb on Thursday, 08 October 2015 09:37 CDT

appnweb
 Hi,

Some of our customers are hosted on Infomaniak and while trying to update to version 3.6.2 a file was detected as malicious.

This file is the default.php located in /backend/views/cpanel/tmpl.

We asked infomaniak support to tell us what in this file was considered as malicious and it seems their antivirus detected it because of the presence of the url https://api.ipify.org/.

Could you please confirm us that it is normal to find this url in there ?

And please note that it can be a problem with some antivirus, it may be useful for further release. Admin tool being a must have for us, it would be quite a problem if we cannot install it on all hosts.

Thanks in advance for your help.

nicholas
Akeeba Staff
Manager
That URL is actually perfectly normal to be there. I don't understand why they block it. It merely reports back your public IP address. Simply put, it's a false positive. If you want to see what exactly it does just visit https://api.ipify.org/ See? All you get is your IP address... Please let your host know that their antivirus is reporting false positives.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

appnweb
Thanks for your answer.

I already tested this ip, saw what it was doing and personnaly thought it is normal.

I just wanted to be sure and have the developer's feedback on it, in order to give Infomaniak a solid confirmation.

Sorry for the inconvenience and have a nice day !

nicholas
Akeeba Staff
Manager
For what is worth, I'm going to add a workaround for the next version. It's not elegant code, but what can you do...?

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

appnweb
Well, it's the only swiss host on wich I encountered this problem so maybe they can do something on their side. Would be better no ?

I forwarded your feedback there and am waiting for their answer but I won't have any before tommorow morning.

Will keep you informed.

If unfortunately they do not want to let us go with that, thanks in advance for the future workaround. We do not want to have Joomla websites running without Admintool ;-)

nicholas
Akeeba Staff
Manager
I've been told that a French host does that too.

For what is worth, about two years ago I had to do something similar. Some hosts would mistakenly consider the malware scanning engine of Admin Tools as malware itself. The solution was to gzip and base64 encode the malware data, i.e. what a real hacker would do to mask their actions. Double irony *sigh*

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

appnweb
Hi Nicholas,

I finally had a positive answer from infomaniak and they managed to correct the behaviour of their antivirus in order to avoid detecting this file.

Everything is ok for us now.

Thanks for your help.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!