We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 11681
    • 98 Posts
    After upgrading Ubuntu to version 12.04 today, I ran the included CLAM antivirus scanner [Antivirus engine 0.97.3, GUI version 4.38] over everything in my combined, dual-booting Windows and Linux filesystem. Having generated no complaints for months, this new CLAM AV complained about 36 files. Seven of these were found in local Evo and Revo installations. (I'm in the process of porting to Revo a site that I built back in the Evo 0.9x days and have since updated forward.)

    Six of the complaints seem related to Tinymce. One seems related to styling.

    The attached file summarizes the complaints. The date of one of these is given as "??" because I rashly opened the file and so wiped out the original date.

    I report this because it's either (a) a genuine security problem or (b) a false detection by CLAM AV. Neither possibility is good for MODx.

    Please advise whether or not there is a problem. I'm freezing further work for now. [ed. note: halfnium last edited this post 14 years, 5 months ago.]
      I looked just like that in 1964.
      • 22303 MODX Staff
      • 10,725 Posts
      If this is not a box exposed to public network traffic, I'm not sure what your concern is. If those are the original files that came in both the Evo and Revo versions of TinyMCE, I see no problem here other than the detection algorithms used by CLAM.
        • 11681
        • 98 Posts
        I appreciate your answering, because this does sound goofy.

        The original, Evo-based site is on a public-facing Web host. I brought it down to my own, non-Web-exposed machine to work on it. Once I've completed the Revo port, back up it goes to the Web host. And with it go any artifacts (i.e., obsolete file junk and potential genuine infestations) that came along with it.

        I don't know if the reported files are the original files that came in both the Evo and Revo versions of TinyMCE.

        Once I'm done with the Revo port, I think I should walk through the site and delete the obsolete stuff, file by file.

        I join you in supposing that this new CLAM revision has made false detections. If so, anyone else updating to Ubuntu 12.04 and running CLAM will see the same complaints. Neither false positives nor genuine problems are helpful to the MODx reputation, so I thought I ought to report them.

        The CLAM team provides a way to report false positives (at http://www.clamav.net/lang/en/sendvirus/), but I don't think ordinary MODx civilians like me ought to be claiming true or false virus problems on behalf of MODx. That would make for chaos.
          I looked just like that in 1964.