Generic.Hidden.Code.2
-
Hi Support
Thanks for a very useful plugin.
A recent VaultPress scan detected “suspicious” code here:
//google-listings-and-ads/vendor/symfony/polyfill-intl-normalizer
“This file contains suspicious hidden code, and should be checked for recent changes, or malicious code. Often hackers try to hide their hack attempts by obfuscating their attack code, to make it harder to detect. VaultPress has detected a string of suspicious characters in this file. Please check your backup history for recent changes to this file, or contact a Safekeeper if you are unsure.”
Is there any way to confirm if this is a false positive or a real threat. I appreciate the support.
The page I need help with: [log in to see the link]
-
Hi @intelligentweb,
Thank you for bringing this issue to our attention. We’ll take a look and get back to you immediately we have additional information.
In the meantime, could you please share your site’s System Status? You can find it via WooCommerce > Status. Select “Get system report” and then “Copy for support”. Once you’ve done that, you can paste it into your reply.
Hi?@intelligentweb,
The for reporting this issue. Could you provide the Google Listings & Ads version in use and some additional details like the exact file and line that’s triggering the warning?
WordPress Environment WordPress address (URL): https://africanbullion.co.za Site address (URL): https://africanbullion.co.za WC Version: 7.6.1 REST API Version: ? 7.6.1 WC Blocks Version: ? 10.1.0 Action Scheduler Version: ? 3.5.4 Log Directory Writable: ? WP Version: 6.2 WP Multisite: – WP Memory Limit: 512 MB WP Debug Mode: – WP Cron: ? Language: en_ZA External object cache: – Server Environment Server Info: Apache PHP Version: 8.0.28 PHP Post Max Size: 128 MB PHP Time Limit: 60 PHP Max Input Vars: 4500 cURL Version: 7.64.0 OpenSSL/1.1.1n SUHOSIN Installed: – MySQL Version: 10.4.28-MariaDB-1:10.4.28+maria~deb10 Max Upload Size: 128 MB Default Timezone is UTC: ? fsockopen/cURL: ? SoapClient: ? DOMDocument: ? GZip: ? Multibyte String: ? Remote Post: ? Remote Get: ? Database WC Database Version: 7.6.1 WC Database Prefix: brjwa4_ Total Database Size: 764.50MB Database Data Size: 456.44MB Database Index Size: 308.06MB brjwa4_woocommerce_sessions: Data: 1.02MB + Index: 0.02MB + Engine InnoDB brjwa4_woocommerce_api_keys: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_woocommerce_attribute_taxonomies: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_woocommerce_downloadable_product_permissions: Data: 0.02MB + Index: 0.06MB + Engine InnoDB brjwa4_woocommerce_order_items: Data: 2.52MB + Index: 0.47MB + Engine InnoDB brjwa4_woocommerce_order_itemmeta: Data: 10.52MB + Index: 10.03MB + Engine InnoDB brjwa4_woocommerce_tax_rates: Data: 0.02MB + Index: 0.06MB + Engine InnoDB brjwa4_woocommerce_tax_rate_locations: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_woocommerce_shipping_zones: Data: 0.02MB + Index: 0.00MB + Engine InnoDB brjwa4_woocommerce_shipping_zone_locations: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_woocommerce_shipping_zone_methods: Data: 0.02MB + Index: 0.00MB + Engine InnoDB brjwa4_woocommerce_payment_tokens: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_woocommerce_payment_tokenmeta: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_woocommerce_log: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_actionscheduler_actions: Data: 185.25MB + Index: 146.55MB + Engine InnoDB brjwa4_actionscheduler_claims: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_actionscheduler_groups: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_actionscheduler_logs: Data: 157.22MB + Index: 105.20MB + Engine InnoDB brjwa4_commentmeta: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_comments: Data: 7.52MB + Index: 9.09MB + Engine InnoDB brjwa4_feedmanager_channel: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_feedmanager_country: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_feedmanager_feed_status: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_feedmanager_field_categories: Data: 0.02MB + Index: 0.00MB + Engine InnoDB brjwa4_feedmanager_product_feed: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_feedmanager_product_feedmeta: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_feedmanager_source: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_gla_attribute_mapping_rules: Data: 0.02MB + Index: 0.00MB + Engine InnoDB brjwa4_gla_budget_recommendations: Data: 0.22MB + Index: 0.14MB + Engine InnoDB brjwa4_gla_merchant_issues: Data: 0.06MB + Index: 0.00MB + Engine InnoDB brjwa4_gla_shipping_rates: Data: 0.02MB + Index: 0.05MB + Engine InnoDB brjwa4_gla_shipping_times: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_links: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_options: Data: 13.11MB + Index: 0.48MB + Engine InnoDB brjwa4_postmeta: Data: 42.53MB + Index: 29.72MB + Engine InnoDB brjwa4_posts: Data: 29.20MB + Index: 2.48MB + Engine InnoDB brjwa4_stock_log: Data: 0.25MB + Index: 0.00MB + Engine InnoDB brjwa4_termmeta: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_terms: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_term_relationships: Data: 0.06MB + Index: 0.05MB + Engine InnoDB brjwa4_term_taxonomy: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_usermeta: Data: 0.27MB + Index: 0.31MB + Engine InnoDB brjwa4_users: Data: 0.02MB + Index: 0.05MB + Engine InnoDB brjwa4_wcpdf_invoice_number: Data: 0.08MB + Index: 0.00MB + Engine InnoDB brjwa4_wc_admin_notes: Data: 0.08MB + Index: 0.00MB + Engine InnoDB brjwa4_wc_admin_note_actions: Data: 0.05MB + Index: 0.02MB + Engine InnoDB brjwa4_wc_category_lookup: Data: 0.02MB + Index: 0.00MB + Engine InnoDB brjwa4_wc_customer_lookup: Data: 0.38MB + Index: 0.30MB + Engine InnoDB brjwa4_wc_download_log: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_wc_order_coupon_lookup: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_wc_order_product_lookup: Data: 2.52MB + Index: 1.42MB + Engine InnoDB brjwa4_wc_order_stats: Data: 2.52MB + Index: 0.73MB + Engine InnoDB brjwa4_wc_order_tax_lookup: Data: 0.02MB + Index: 0.03MB + Engine InnoDB brjwa4_wc_product_attributes_lookup: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_wc_product_download_directories: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_wc_product_meta_lookup: Data: 0.05MB + Index: 0.09MB + Engine InnoDB brjwa4_wc_rate_limits: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_wc_reserved_stock: Data: 0.02MB + Index: 0.00MB + Engine InnoDB brjwa4_wc_tax_rate_classes: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_wc_webhooks: Data: 0.02MB + Index: 0.02MB + Engine InnoDB brjwa4_woocommerce_shipping_table_rates: Data: 0.02MB + Index: 0.00MB + Engine InnoDB brjwa4_wpfm_backup: Data: 0.02MB + Index: 0.00MB + Engine InnoDB brjwa4_wt_iew_action_history: Data: 0.17MB + Index: 0.00MB + Engine InnoDB brjwa4_wt_iew_mapping_template: Data: 0.02MB + Index: 0.00MB + Engine InnoDB Post Type Counts attachment: 673 condition_group: 5 custom_css: 2 gblocks_global_style: 1 GOTMLS_quarantine: 1 gp_elements: 11 happyform: 1 mc4wp-form: 1 nav_menu_item: 26 page: 42 post: 49 product: 161 product_variation: 8 product-feed: 1 revision: 971 seedprod: 1 shop_order: 8162 shop_order_refund: 4 sidebar: 2 wafs: 1 wp_block: 4 wp_global_styles: 1 wp_show_posts: 1 Security Secure connection (HTTPS): ? Hide errors from visitors: ? Active Plugins (32) VaultPress: by Automattic – 2.2.3 BackupBuddy: by iThemes – 8.8.3 Content Aware Sidebars: by Joachim Jensen - DEV Institute – 3.19 GenerateBlocks Pro: by Tom Usborne – 1.5.2 GenerateBlocks: by Tom Usborne – 1.7.3 Google Listings and Ads: by WooCommerce – 2.4.4 GP Premium: by Tom Usborne – 2.3.1 Happyforms (free): by Happyforms – 1.25.5 IgniteWoo Updater: by IgniteWoo.com – 3.0.4 Lightweight Accordion: by Andy Feliciotti – 1.5.16 NinjaFirewall (WP Edition): by The Ninja Technologies Network – 4.5.7 Order Export & Order Import for WooCommerce: by WebToffee – 2.3.3 Product Import Export for WooCommerce: by WebToffee – 2.2.9 Really Simple SSL: by Really Simple Plugins – 6.2.5 Rearrange Woocommerce Products: by Aslam Doctor – 4.1.2 Regenerate Thumbnails: by Alex Mills (Viper007Bond) – 3.1.5 ShoppingFeeder: by ShoppingFeeder – 1.4.9 Bob Go smart shipping solution: by bobgroup – 2.5.15 Import Export WordPress Users and WooCommerce Customers: by WebToffee – 2.3.9 WooCommerce Blocks: by Automattic – 10.1.0 WooCommerce Advanced Free Shipping: by Jeroen Sormani – 1.1.5 WooCommerce Precious Metals: by IgniteWoo.com – 3.0.20 PDF Invoices & Packing Slips for WooCommerce: by WP Overnight – 3.5.2 WooCommerce Product Add-ons: by WooCommerce – 5.0.0 Stock Manager for WooCommerce: by StoreApps – 2.10.0 WooCommerce Subscribe to Newsletter: by Themesquad – 3.4.0 WooCommerce Table Rate Shipping: by WooCommerce – 3.0.40 WooCommerce: by Automattic – 7.6.1 WordPress Importer: by wordpressdotorg – 0.8.1 WP Product Feed Manager: by Michel Jongbloed – 1.49.1 SEOPress: by The SEO Guys at SEOPress – 6.6.3 WP Show Posts: by Tom Usborne – 1.1.4 Inactive Plugins (0) Must Use Plugins (1) 0-ninjafirewall.php: by The Ninja Technologies Network – 1.0 Settings API Enabled: – Force SSL: – Currency: ZAR (R) Currency Position: left Thousand Separator: , Decimal Separator: . Number of Decimals: 2 Taxonomies: Product Types: external (external) grouped (grouped) simple (simple) variable (variable) Taxonomies: Product Visibility: exclude-from-catalog (exclude-from-catalog) exclude-from-search (exclude-from-search) featured (featured) outofstock (outofstock) rated-1 (rated-1) rated-2 (rated-2) rated-3 (rated-3) rated-4 (rated-4) rated-5 (rated-5) Connected to WooCommerce.com: – Enforce Approved Product Download Directories: ? Order datastore: WC_Order_Data_Store_CPT WC Pages Shop base: #3582 - /shop/ Basket: #3583 - /cart/ Checkout: #3584 - /checkout/ My account: #3585 - /my-account/ Terms and conditions: #1375 - /terms-and-conditions/ Theme Name: GeneratePress Version: 3.3.0 Author URL: https://tomusborne.com Child Theme: ? – If you are modifying WooCommerce on a parent theme that you did not build personally we recommend using a child theme. See: How to create a child theme WooCommerce Support: ? Templates Overrides: – Admin Enabled Features: activity-panels analytics coupons customer-effort-score-tracks import-products-task experimental-fashion-sample-products shipping-smart-defaults shipping-setting-tour homescreen marketing multichannel-marketing mobile-app-banner navigation onboarding onboarding-tasks remote-inbox-notifications remote-free-extensions payment-gateway-suggestions shipping-label-banner subscriptions store-alerts transient-notices woo-mobile-welcome wc-pay-promotion wc-pay-welcome-page Disabled Features: block-editor-feature-enabled minified-js new-product-management-experience product-variation-management settings Daily Cron: ? Next scheduled: 2023-05-05 11:03:20 +02:00 Options: ? Notes: 113 Onboarding: completed Action Scheduler Complete: 458,133 Oldest: 2023-04-04 11:33:37 +0200 Newest: 2023-05-05 11:36:02 +0200 Failed: 100,891 Oldest: 2022-08-11 17:14:03 +0200 Newest: 2023-05-04 11:44:58 +0200 Pending: 51 Oldest: 2023-05-05 11:31:52 +0200 Newest: 2023-05-06 05:00:00 +0200 Newsletter Subscription Provider: - Status report information Generated at: 2023-05-05 11:36:08 +02:00 `
Plugin version: Version 2.4.4
I appreciate the support.
Hi?@intelligentweb, thanks for providing more info.
I tested with the same version and scanned by Jetpack?Scan two times, but couldn’t get the same suspicious report. Maybe it’s a false positive.
Could you help to confirm if the reported line of code in the Normalizer.php is the same line as this line? https://github.com/symfony/polyfill-intl-normalizer/blob/v1.26.0/Normalizer.php#L40
If yes, then it would be a false positive.
Hey Eason. Thanks very much for taking the time to investigate. I really appreciate the support. Both lines of code are identical so will assume a false positive. All the very best, Mike
You’re very welcome, @intelligentweb! ??
I will mark the thread as solved. If you have a few minutes, we’d love it if you could leave us a review here: https://www.ads-software.com/support/plugin/google-listings-and-ads/reviews/
Cheers!
Thank you for helping to check and the confirm, @intelligentweb!
- The topic ‘Generic.Hidden.Code.2’ is closed to new replies.