requarks / wiki-v1

Legacy version (1.x) of Wiki.js
https://wiki.js.org
GNU Affero General Public License v3.0
101 stars 75 forks source link

Malware in js/vendor.js #194

Open mdyrhaug opened 5 years ago

mdyrhaug commented 5 years ago

Actual behavior

After I install Wiki 1.117 the website is reported as having malware.

I was alerted to this via corporate anti-virus scanner and confirmed using third party tool:

Scan using: https://scanner.pcrisk.com

It reports malware in /js/vendor.js

Expected behavior

Clean Scan

Steps to reproduce the behavior

Install using:

curl -sSo- https://wiki.js.org/install.sh | bash

Once running, Scan using: https://scanner.pcrisk.com

NGPixel commented 5 years ago

The scanner link you provided throws an error when attempting to scan https://docs-legacy.requarks.io (which runs 1.0.117).

I ran the site through a dozen other "website malware scanner" and there was no positives.

So if you can provide a detailed report of what is being reported as malware, I'll look into it, but for now I'll mark this issue as invalid.

mdyrhaug commented 5 years ago

Here is a link to a report on the docs-legacy.requarks.io domain. I am going to try to scan just the vendor.js to get more info.

https://scanner.pcrisk.com/detailed_report/docs-legacy.requarks.io#details

scan_result