THEME CONSISTING OF MALICIOUS CODE

Posted in: Newspaper
Post count: 13

I have purchased the theme, however there are issues. The theme is consisting of malicious code like
REP_INVERT’);if(typeof pattern===’string’){pattern=eval(pattern);} and base64_decode.

Please help.

Post count: 22421

Hello,
The code you exemplified does not come from the theme. Please check the files with winmerge and compare the default theme files to yours to see any at all code changes from the original files. Maybe your site got infected with mallware. If you identified the file in question, it’s easy to check it with winmerge and compare it to the main file from the package you download from envato.
Let us know how it goes.
Thank you!

Post count: 13

I would like to inform you that the eval and base64_decode are from js_composer directory . The plugin comes along with the package . Hence , it is the part of the theme. can you please help. I had bought this theme after reading a lot of reviews.

Post count: 22421

Hello,
The code does not come gfrom our theme nor is the code mallicious in any way. Wordfence detects it that way but these tools are not always right. Please check this topic: http://codecanyon.net/item/visual-composer-page-builder-for-wordpress/242431/comments?utf8=%E2%9C%93&term=+base64_decode&from_buyers_and_authors_only=0
This is the official response from the plugin author:
Hello, this is basically problem with Wordfence – the code used there has no harm and it can stay this way.
Thank you!

Post count: 13

These are the following path which are consisting of eval and base64_decode.Let me also inform you that it is a fresh install with wordpress.After i install the visual composer , again many path will have files under it containing eval and base64_decode.

wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/td_view_import_export_settings.php:33
wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/td_view_update_newspaper_6.php:347
wp-content/themes/Newspaper/includes/wp_booster/wp-admin/external/ace/worker-css.js:1
wp-content/themes/Newspaper/includes/wp_booster/wp-admin/external/ace/worker-javascript.js:1
wp-content/themes/Newspaper/includes/wp_booster/td_block.php:556

Please help

Post count: 13

After installing the Visual Composer the following paths are showing files having eval and bas64_decode

wp-content/plugins/js_composer/assets/js/dist/frontend-editor.min.js:3
wp-content/plugins/js_composer/assets/js/dist/backend.min.js:5
wp-content/plugins/js_composer/assets/lib/php.default/php.default.min.js:310
wp-content/plugins/js_composer/assets/lib/php.default/php.default.min.js:314
wp-content/plugins/js_composer/include/classes/shortcodes/vc-raw-js.php:22
wp-content/plugins/js_composer/assets/lib/php.default/php.default.min.js:625

Post count: 13

The plugin “Visual Composer” , “wp_booster ” are giving such codes. Please note: I am using Exploit scanner plugin to reveal such information to you.

Post count: 22421

Hi,

Well not all tools that say you have malicious code or other anomalies are correct. Visual composer states the same about wordfence:
Hi, we always test Visual Composer to be 100% safe – also our 3rd party developers check it and Envato as well. So if you purchase Visual Composer directly from WPBakery you can be 100% sure there are no malicious files in there. As for Wordfence – we personally doubt this plugin, because of the several cases in the past when it acted on such things like shortened URLs and so on.
To follow along with the plugin authors, we at TagDiv assure you there is no exploit or malicious code in our themes or the version of visual composer we provide and these tools are highly doubtful. In order to make a correct assesment, you neet to use more tools, not a single opinion from an untested plugin. We cannot say for sure what the plugin detects as I have checked all of the lines fo code mentioned in the errors you received but there is nothing potentially harmful there. You can rest assured there is no threat. A premium theme is built with custom code and plugins cannot detect this. WordPress plugins are created on the standard wordpress code and cannot recognize custom functions that we use. That is why it detects threats as the code is not in the standard wordpress codex. This is the case with all premium themes.
Thank you!

Post count: 13

Thank you Bogdan B.,

I appreciate your quick reply. If there is any issue i will report it to you.

Post count: 4

Hello,

Ive purchased the Newspaper 8.8 theme a few minutes ago at Envato Market, downloaded it directly from Envato to my copmuter and checked it for malicious code before uploading to my webserver. It says that it contains the following issues:
Security breaches : Use of base64_decode()
Security breaches : Use of base64_encode()
Presence of iframes : iframes are sometimes used to load unwanted adverts and malicious code on another site
Malware : Operations on file system
Malware : Network operations
Admin menu : Themes should use add_theme_page() for adding admin pages.

Is it safe to install your theme on my new Webserver? Can this code be used to hack my WordPress site or anything like this?

Thanks in advance!
Greetings

Post count: 20688

Hi,

The base64 encoding is used in many available themes and plugins
https://developer.mozilla.org/en-US/docs/Web/API/WindowBase64/Base64_encoding_and_decoding

Our theme also uses it but there will be no security concerns in this matter. Also those detected issues like “iframes are sometimes used…” or “themes should use…” are in general, not applicable here.

I would like to state that the theme is perfectly safe to use as long as downloaded from themeforest. The present theme is the result of years of development and improvements, also it is constantly updated.

However if you deduce that our theme presents a risk for your website, we will be able to provide a full refund if requested.

Thanks

Post count: 4

Ok great. Thank you for your fast replie.

Viewing 12 posts - 1 through 12 (of 12 total)
The forum ‘Newspaper’ is closed to new topics and replies.