Support

Admin Tools

#33782 false positives?

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Thursday, 29 October 2020 01:17 CDT

revemiketool

Tonight I have been received a rush of emails from a site I completed today and made live. The message I am receiving is "Critical file modifies on Pulse Automation Solutions

It tells me that a list of files have been changed. I have watched the files and there is no sign of any of these files having been changed. Could it be that the changes made while I was working on the site triggered this change and the notification is on a bit of a loop?

Hello,

We would like to notify you that one or more critical files have been modified on your site, Pulse Automation Solutions. The list of files modified on your site is as follows:

  • configuration.php
  • index.php
  • administrator/index.php
  • templates/beez3/index.php
  • templates/beez3/error.php
  • templates/beez3/component.php
  • templates/it_milano/index.php
  • templates/it_milano/error.php
  • templates/it_milano/component.php
  • templates/protostar/index.php
  • templates/protostar/error.php
  • templates/protostar/component.php
  • templates/system/index.php
  • templates/system/error.php
  • templates/system/component.php
Should I be worried?

Critical files, in the context of this email, are the files most usually targeted by hackers upon successful hacking of a site. These files can also be modified for legitimate reasons, for example when you save your site's Global Configuration or when you update Joomla! or one of its templates.

You should NOT worry if you received this email after you, or another administrator you trust, performed any of the following changes on your site:

  • Restored the site from a backup
  • Modified the Global Configuration
  • Updated Joomla!
  • Updated a site template

If this message was not sent to you as the result of such a desirable and expected change please review your site immediately as this would be an indication of hacking activity.

Best regards,

The Pulse Automation Solutions team

 

 

 

Please look at the bottom of this page (under Support Policy Summary) for our support policy summary, containing important information regarding our working hours and our support policy. Thank you!

tampe125
Akeeba Staff

Hello,

Long story short: I've already seen this happening in the past. Most likely there is some kind of delay between reads and writes on the database, so you get a lot of emails.

A more detailed explanation: Admin Tools fetches the contents of those files and stores an hash checksum of them into the database. In the next page load, it will read those hashes from the database, compute the hashes again form the live site and, if they are different, a warning email is sent.

If the database is a bit "slow" on writing the previous hash, when we load we get the "old" one, so it's different and the email is sent, even if no changes were made.

Sadly, as for today, there's no workaround for that; your only solution is to disable such feature. 

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

revemiketool

Thanks, Davide. I am happy to leave it as it is for now. I am just happy that it is not the result of hackers.

 

Cheers,

Mike Wharton

tampe125
Akeeba Staff

You're welcome!

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!