Wordfence critical security notice with Premium

UpdraftPlus Home Forums Paid support forum – UpdraftPlus backup plugin Wordfence critical security notice with Premium

Viewing 14 posts - 1 through 14 (of 14 total)
  • Author
    Posts
  • #245469
    Scott
    Participant

    I just installed UpdraftPlus Premium yesterday and am getting a critical security notice from Wordfence on each site it’s installed on (copied/pasted below). Will you confirm if the following is an issue, and if there’s something that needs to be fixed?

    Thanks,
    Scott

    ———

    This file may contain malicious executable code: /public_html/wp-content/plugins/updraftplus/vendor/phpseclib/phpseclib/phpseclib/Crypt/Base.php

    Filename: wp-content/plugins/updraftplus/vendor/phpseclib/phpseclib/phpseclib/Crypt/Base.php
    File type: Not a core, theme or plugin file.
    Issue first detected: 15 mins ago.
    Severity: Critical
    Status: New

    This file is a PHP executable file and contains the word ‘eval’ (without quotes) and the word ‘unpack(‘ (without quotes). The eval() function along with an encoding function like the one mentioned are commonly used by hackers to hide their code. If you know about this file you can choose to ignore it to exclude it from future scans. This file was detected because you have enabled HIGH SENSITIVITY scanning. This option is more aggressive than the usual scans, and may cause false positives.

    #245471
    udadmin
    Keymaster

    It’s almost certainly a false positive, in that that file (part of https://github.com/phpseclib/phpseclib/ , the PHP standard encryption library) contains that. Please report it to Wordfence… we’ve had this question so many times, and would really like it if they could fix their scanner so that it doesn’t flag up the same false positives repeatedly!

    David

    #245473
    Scott
    Participant

    Thanks David, that’s reassuring to hear.

    I’ll drop a note to Wordfence about it.

    Scott

    #329202
    Linda
    Participant

    Just FYI that I got the same “critical” warning from Wordfence yesterday. This with Wordfence Premium. Further to the warning, Wordfence says “Since you have the beta threat defense feed enabled, there is a high likelihood that your results could include false positives.”

    I opened a ticket with Wordfence and sent them the file and a link to this post. This is the reply I got:

    “I see we have this file in our system as non-malicious. Of course, you will always want to continue to keep an eye on things, even when you see false positives. As Updraft mentioned, I believe it is safe to say this is a false positive.”

    Thought I’d share as it’s scary to get the critical warning plus a prompt to hire Wordfence to clean the site for malware ;-)

    #329760
    Scott
    Participant

    Thanks for sharing that, Linda!

    #339443
    Linda
    Participant

    Hi again –

    I’m getting another critical warning from Wordfence for this file:

    START

    wp-content/plugins/updraftplus/vendor/phpseclib/phpseclib/tests/Unit/Crypt/RSA/LoadKeyTest.php

    Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The matched text in this file is: $key = ‘MIICXAIBAAKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUp’ .\x0a ‘wmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ5’ .\x0a ‘…

    The issue type is: Backdoor:PHP/SEemf0Ji
    Description: A backdoor known as SEemf0Ji

    END

    Can you confirm that it’s a legitimate file or not?

    #340881
    Dee Nutbourne
    Moderator

    Hi,

    Apologies for the delay.

    This appears to be a false positive. The file is legitimate, and the matched strings are part of the file.

    Best Wishes,
    David N

    #345208
    ssh1
    Participant

    Hi,

    I’m getting the same issue, I think:

    Filename: wp-content/plugins/updraftplus/vendor/phpseclib/phpseclib/tests/Unit/Crypt/RSA/LoadKeyTest.php
    File Type: Not a core, theme, or plugin file from wordpress.org.
    Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The matched text in this file is: $key = ‘MIICXAIBAAKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUp’ .\x0a ‘wmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ5’ .\x0a ‘…

    The issue type is: Backdoor:PHP/SEemf0Ji
    Description: A backdoor known as SEemf0Ji

    Can you let me know if this is a false positive or something that needs to be addressed?

    Thanks.

    #345229
    support303
    Participant

    I got the same warning today from Wordfence:

    * File appears to be malicious: wp-content/plugins/updraftplus/vendor/phpseclib/phpseclib/tests/Unit/Crypt/RSA/LoadKeyTest.php

    Can you please let us know if this is a false positive or something that needs to be addressed?
    Thanks.

    #345239
    vinceparrott
    Participant

    I received the same warning today from Wordfence:

    Filename: wp-content/plugins/updraftplus/vendor/phpseclib/phpseclib/tests/Unit/Crypt/RSA/LoadKeyTest.php

    File Type: Not a core, theme, or plugin file from wordpress.org.

    Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The matched text in this file is: $key = ‘MIICXAIBAAKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUp’ .\x0a ‘wmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ5’ .\x0a ‘…

    The issue type is: Backdoor:PHP/SEemf0Ji
    Description: A backdoor known as SEemf0Ji

    Please confirm that this is a false positive.

    Thank you.

    #345240
    adambnicely
    Participant

    I too got the critical alert from Wordfence.

    Filename: wp-content/plugins/updraftplus/vendor/phpseclib/phpseclib/tests/Unit/Crypt/RSA/LoadKeyTest.php
    File Type: Not a core, theme, or plugin file from wordpress.org.

    Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The matched text in this file is: $key = ‘MIICXAIBAAKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUp’ .\x0a ‘wmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ5’ .\x0a ‘…

    The issue type is: Backdoor:PHP/SEemf0Ji
    Description: A backdoor known as SEemf0Ji

    I compared the file to the one that is hosted on the official phpseclib 1.0 branch at GitHub and the files are exactly the same, so I believe this to be a false positive.

    I will write Wordfence to let them know.

    #345330
    chrisghill
    Participant

    Same issue here today:

    File appears to be malicious: wp-content/plugins/updraftplus/vendor/phpseclib/phpseclib/tests/Unit/Crypt/RSA/LoadKeyTest.php
    Type: File
    Issue Found February 5, 2019 6:16 AM
    Critical
    Stop Ignoring

    Details

    Filename: wp-content/plugins/updraftplus/vendor/phpseclib/phpseclib/tests/Unit/Crypt/RSA/LoadKeyTest.php
    File Type: Not a core, theme, or plugin file from wordpress.org.
    Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The matched text in this file is: $key = ‘MIICXAIBAAKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUp’ .\x0a ‘wmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ5’ .\x0a ‘…

    The issue type is: Backdoor:PHP/SEemf0Ji

    I hope it’s still a false positive.

    #345410
    adambnicely
    Participant

    I got a quick response from Wordfence Support:

    “Thanks for reaching out. This is a known false positive and we have disabled the rule. It shouldn’t show up in new scans while we are investigating and implementing a fix for the scan signature.”

    #345411
    chrisghill
    Participant

    I got a similar response as well. They seem to be on it.

Viewing 14 posts - 1 through 14 (of 14 total)
  • The topic ‘Wordfence critical security notice with Premium’ is closed to new replies.