Project

General

Profile

Actions

Bug #94640

closed

Feature: #91354 - Integrate server response security checks causes linux-malware-detect trigger "false" detection

Added by Rene Tobias over 3 years ago. Updated 5 months ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
Security
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
9
PHP Version:
7.3
Tags:
Complexity:
medium
Is Regression:
Sprint Focus:

Description

Hello,

Feature: #91354 - Integrate server response security checks - causes linux-malware-detect trigger "false" detection.

So your code which TYPO3 include in files '.php.wrong' and '.php.txt' triggers malware detection.

For malware detection we are using "linux-malware-detect" - https://github.com/rfxn/linux-malware-detect https://www.rfxn.com/projects/linux-malware-detect/

The problematic code is: base64_decode('UEhQIGNvbnRlbnQ=');

Full code:

<!DOCTYPE html><html lang="en"><body><div><?php echo base64_decode('UEhQIGNvbnRlbnQ=');?></div></body></html>

TYPO3 9.5.18
CenOS 7.9


Related issues 1 (0 open1 closed)

Related to TYPO3 Core - Task #91354: Integrate server response security checksClosedOliver Hader2020-05-10

Actions
Actions #1

Updated by Oliver Hader over 3 years ago

Thanks for creating this issue. Please notice it is NOT my code - this is an open source community and therefore it belongs to everybody. The GNU General Public License explicitly allows to use, copy and modify the source code. So, please just go ahead and suggest an alternative way...

Or... report it back to "linux-malware-detect" as false-positive, since the "detected malware" is actually this:

php > echo base64_decode('UEhQIGNvbnRlbnQ=');
PHP content
Actions #2

Updated by Oliver Hader over 3 years ago

  • Assignee deleted (Oliver Hader)
  • Start date deleted (2021-07-27)
Actions #3

Updated by Oliver Hader over 3 years ago

  • Target version deleted (Candidate for patchlevel)
Actions #4

Updated by Oliver Hader over 3 years ago

  • Related to Task #91354: Integrate server response security checks added
Actions #5

Updated by Georg Ringer 5 months ago

  • Status changed from New to Closed

I am closing this issue as this is not the fault of TYPO3

Actions

Also available in: Atom PDF