• 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!

TOPIC: Cache: Highly suspicious inclusion (poss. Crypto

Cache: Highly suspicious inclusion (poss. Crypto 8 years 5 months ago #33568

  • Julian
  • Julian's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 3
Hi everybody,

I had yesterday a message, deleted the files, and today there is a new one:
Highly suspicious inclusion (possible CryptoPHP)

I wonder because it´s in the cache-folder.
Does it happen, that cached files are false positive or is it expectable that hackers place theire files into the cache-folder?

All the best, Julian!
The administrator has disabled public write access.

Cache: Highly suspicious inclusion (poss. Crypto 8 years 5 months ago #33573

  • alexp
  • alexp's Avatar
  • OFFLINE
  • RSJoomla! Official Staff
  • Posts: 2253
  • Thank you received: 180
False positives can occur, but you should manually inspect the file just to be on the safe side.
Please note: my help is not official customer support. To receive your support, submit a ticket by clicking here
Regards,
RSJoomla! Development Team
The administrator has disabled public write access.

Cache: Highly suspicious inclusion (poss. Crypto 8 years 5 months ago #33579

  • Julian
  • Julian's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 3
Hi Alexp,

the file is way to laare to inspect it for me. I simply don´t understand all the code inside.

Here is a screenshot of the rsFirewall-log. Does this help to find out if it´s serious?




All the best, Julian!
The administrator has disabled public write access.

Cache: Highly suspicious inclusion (poss. Crypto 8 years 5 months ago #33580

  • alexp
  • alexp's Avatar
  • OFFLINE
  • RSJoomla! Official Staff
  • Posts: 2253
  • Thank you received: 180
Based on the given screenshot, this looks like a false positive.
Please note: my help is not official customer support. To receive your support, submit a ticket by clicking here
Regards,
RSJoomla! Development Team
The administrator has disabled public write access.
  • 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!