Latest version of the theme has a virus

Hi,

I recently downloaded the latest version of the X Theme and tried installing it on my website. I kept receiving the following error:

Forbidden
You don’t have permission to access /upload/bf8e1040-7b6c-70fc-5b65-5bf91860d021 on this server.

I referred the matter to my Hetzner, with whom I host, and this is the response that I received:

Dear Julius

Thank you for your mail.

Upon an in-depth investigation of the server logs, we found an Apache error for the domain webdex.co.za with a time stamp of [Sat Nov 24 11:17:53] where we can see that an upload was rejected due to “Virus found in uploaded file”, the full error log hereof below:


[Sat Nov 24 11:17:53.302406 2018] [:error] [pid 71878:tid 140629375809280] [client 209.203.21.162] ModSecurity: Access denied with code 403 (phase 2). File “/opt/modsecurity/upload/20181124-111743-W-kXN8XdDhcAARjGxs8AAABv-file-il82Os” rejected by the approver script “/bin/runAV”: 0 clamscan: Sanesecurity.Malware.27490.XmlHeur.Actx.UNOFFICIAL [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_46_av_scanning.conf”] [line “17”] [id “950115”] [msg “Virus found in uploaded file”] [severity “CRITICAL”] [tag “MALICIOUS_SOFTWARE/VIRUS”] [tag “PCI/5.1”] [hostname “webdex.co.za”] [uri “/wp-admin/update.php”] [unique_id “W-kXN8XdDhcAARjGxs8AAABv”]

In the event that this is the same timestamp that you tried to install the theme I would recommend contacting the developers of the theme and provide them with the above error message for further investigation.

Please let me know should you require any further assistance.

Please advise accordingly

Hi Julius,

I’m sorry to hear you’re running into this. This is something we’ve seen a few cases of before. After investigating, we’ve found this to be a false positive with the some scanner.

The file (cs-vendor.js) in the theme contains all of the javascript dependencies needed for Cornerstone’s Ember.js application. It’s not dangerous, but does have some advanced data manipulation libraries, including client-side base64 encoding/decoding. Similar technology is used by viruses that wish to obscure data, so I can see why a false positive may be occurring. Please ask your hosting provider to whitelist it as it does not contain any malwares.

Thank you

Thank you, I have submitted your response to the hosting provider.

You’re welcome! :slight_smile:

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.