Magento Security Tool False Positive? prototype.js identified as compromise injection The Next...
Solidity! Invalid implicit conversion from string memory to bytes memory requested
Contours of a clandestine nature
What connection does MS Office have to Netscape Navigator?
Is "for causing autism in X" grammatical?
Grabbing quick drinks
Would a galaxy be visible from outside, but nearby?
Written every which way
MessageLevel in QGIS3
How to avoid supervisors with prejudiced views?
What happened in Rome, when the western empire "fell"?
Inappropriate reference requests from Journal reviewers
Why is the US ranked as #45 in Press Freedom ratings, despite its extremely permissive free speech laws?
How long to clear the 'suck zone' of a turbofan after start is initiated?
How do scammers retract money, while you can’t?
Real integral using residue theorem - why doesn't this work?
How did people program for Consoles with multiple CPUs?
What happens if you roll doubles 3 times then land on "Go to jail?"
In excess I'm lethal
Elegant way to replace substring in a regex with optional groups in Python?
Preparing Indesign booklet with .psd graphics for print
Indicator light circuit
Why does the UK parliament need a vote on the political declaration?
Why does standard notation not preserve intervals (visually)
Can I run my washing machine drain line into a condensate pump so it drains better?
Magento Security Tool False Positive? prototype.js identified as compromise injection
The Next CEO of Stack OverflowMagento Security Scan not able to verify siteMagento Security Scan : some of results are UNKNOWNMagento Security Scanner does not detect SUPEE-8788Magento 2 : Security Check Can Not be Verified!Having issue with Magento 2 security scan. Magento Compromise InjectionGetting errors in Magento 1.9.3 SECURITY SCAN - Total four error critical errorSecurity Scan returning an empty reportSecurity Scan supee-10415 false positive?Is there something mad going on with Magento critical vulnerability scanner
Is anyone else having issues with Magento Security Tool Scanner?
https://account.magento.com/scanner/
Your site is compromised with injected JavaScript. (79)
The malicious code signature(s) has been found in resources:
/js/prototype/prototype.js
/js/prototype/validation.js
/js/scriptaculous/controls.js
I am getting this scan failure on 12 different magento sites so it must be a false positive. Yesterday all sites were passing the scanner. Today they all say they are compromised injected with malware.
All warnings on all sites are pointing to prototype.js
security-scan-tool
add a comment |
Is anyone else having issues with Magento Security Tool Scanner?
https://account.magento.com/scanner/
Your site is compromised with injected JavaScript. (79)
The malicious code signature(s) has been found in resources:
/js/prototype/prototype.js
/js/prototype/validation.js
/js/scriptaculous/controls.js
I am getting this scan failure on 12 different magento sites so it must be a false positive. Yesterday all sites were passing the scanner. Today they all say they are compromised injected with malware.
All warnings on all sites are pointing to prototype.js
security-scan-tool
Having the same issue.
– chirag
Apr 16 '18 at 14:29
add a comment |
Is anyone else having issues with Magento Security Tool Scanner?
https://account.magento.com/scanner/
Your site is compromised with injected JavaScript. (79)
The malicious code signature(s) has been found in resources:
/js/prototype/prototype.js
/js/prototype/validation.js
/js/scriptaculous/controls.js
I am getting this scan failure on 12 different magento sites so it must be a false positive. Yesterday all sites were passing the scanner. Today they all say they are compromised injected with malware.
All warnings on all sites are pointing to prototype.js
security-scan-tool
Is anyone else having issues with Magento Security Tool Scanner?
https://account.magento.com/scanner/
Your site is compromised with injected JavaScript. (79)
The malicious code signature(s) has been found in resources:
/js/prototype/prototype.js
/js/prototype/validation.js
/js/scriptaculous/controls.js
I am getting this scan failure on 12 different magento sites so it must be a false positive. Yesterday all sites were passing the scanner. Today they all say they are compromised injected with malware.
All warnings on all sites are pointing to prototype.js
security-scan-tool
security-scan-tool
edited 42 mins ago
Teja Bhagavan Kollepara
3,01241949
3,01241949
asked Apr 3 '18 at 14:31
mpersingermpersinger
111
111
Having the same issue.
– chirag
Apr 16 '18 at 14:29
add a comment |
Having the same issue.
– chirag
Apr 16 '18 at 14:29
Having the same issue.
– chirag
Apr 16 '18 at 14:29
Having the same issue.
– chirag
Apr 16 '18 at 14:29
add a comment |
1 Answer
1
active
oldest
votes
Run head against the files and tail and see if you have any base64 etc at the top or bottom. Don’t just edit in nano or something. It might be a false positive but most likely will be revealed by head command or tail.
add a comment |
Your Answer
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "479"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fmagento.stackexchange.com%2fquestions%2f220901%2fmagento-security-tool-false-positive-prototype-js-identified-as-compromise-inje%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
Run head against the files and tail and see if you have any base64 etc at the top or bottom. Don’t just edit in nano or something. It might be a false positive but most likely will be revealed by head command or tail.
add a comment |
Run head against the files and tail and see if you have any base64 etc at the top or bottom. Don’t just edit in nano or something. It might be a false positive but most likely will be revealed by head command or tail.
add a comment |
Run head against the files and tail and see if you have any base64 etc at the top or bottom. Don’t just edit in nano or something. It might be a false positive but most likely will be revealed by head command or tail.
Run head against the files and tail and see if you have any base64 etc at the top or bottom. Don’t just edit in nano or something. It might be a false positive but most likely will be revealed by head command or tail.
answered Apr 3 '18 at 20:04
Timothy FrewTimothy Frew
31929
31929
add a comment |
add a comment |
Thanks for contributing an answer to Magento Stack Exchange!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fmagento.stackexchange.com%2fquestions%2f220901%2fmagento-security-tool-false-positive-prototype-js-identified-as-compromise-inje%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Having the same issue.
– chirag
Apr 16 '18 at 14:29