Forum OpenACS Q&A: Virus found JS/Obfuscated
I downloaded the Windows port of OpenACS from http://www.spazioit.com/pages_en/sol_inf_en/windows-openacs_en/ and ran an AVG scan on it. It came back with "Virus found JS/Obfuscated." I tried posting about this on the comments at that site, but for one thing, I have to wait registration approval before I can do that (still waiting for the 2nd day), and second of all it seems to be pretty low traffic there - wouldn't be surprised if it took weeks to get approved and weeks to get feedback on a post. So I decided to come here.
I'm guessing that this organization is not affiliated with that port, but at any rate, has anyone else seen this? Can anyone else confirm the virus on that download? Or is it possible that it is a false positive?
can you be more specific and mention what is/are the effected file/s?
Thanks a lot in advance,
very good catch indeed.
This is how things are:
1. I checked always all files and distributions with my antivirus: Avira Antivir and no problems where ever found.
2. When using AVG it finds the virus you mention in the file ...\packages\acs-templating\www\resources\xinha-nightly\plugins\QuickTag\tag-lib.js (of course it finds it also in the .exe file, because the .exe file - the installer - contains the above mentioned .js file).
3. I checked that file (tag-lib.js) against the orginal distributions (OpenACS 5.6.0) and (.LRN 2.5.0). There's no difference among the files contained in the original tar files and the ones in my distribution. For example if you download OpenACS 5.6.0, untar it and scan it with your anti virus, you'll get the same problem notification.
4. Now the file tag-lib.js is in an encrypted form and I can't really tell if it is infected or not. I would think it is not. If it is, also the OpenACS and .LRN distributions need to be cleaned/amended.
Hope it helps,
PS: we all live in a world with timezones and where people usually have a job to do (to pay for some fun time in the Open Source area...) I believe I reacted to your observations even quicker and faster than a normal company (with a properly paid support contract) would ever do...
So what do we do now? Hope that someone else sees this and responds? I don't want to install the software unless it is confirmed or not that OpenACS has a virus.
At any rate, thanks a lot for your help.
I'll be more explicit.
I believe you found a false positive.
If you still feel uncomfortable, you can of course delete that file - it is only required for a specific feature of the Xinha WYSIWYG editing component ("QuickTags").
That last sentence was a joke, heh
It is your own resposibility and your responsibility only.
I'd like to stress what I wrote:
1. I believe... (and not I know for sure)
2. If you still feel uncomfortable, you can of course delete that file - it is only required for a specific feature of the Xinha WYSIWYG editing component ("QuickTags").
So again, it is your own call.
why is it compressed in the tar distribution and not in the HEAD branch?
If compression is important (for performance reasons) it should be present in both; if it is not it should be removed in both.