cPanel found a virus in update package from 3.3.14 to 3.3.15

Get help with installation and running phpBB 3.3.x here. Please do not post bug reports, feature requests, or extension related questions here.
mpolito1969
Registered User
Posts: 200
Joined: Mon Jul 14, 2008 1:43 pm
Name: Massimililano Polito

cPanel found a virus in update package from 3.3.14 to 3.3.15

Post by mpolito1969 »

Dear all,

I have a phpBB 3.3.14 installation and I want to update it to 3.3.15 using the Changed Files method.

I tried to upload the packages containing the files changed from 3.3.14 to 3.3.15 but after the upload cPanel reports the following message:
The file you uploaded, phpBB-3.3.15-files.tar.bz2, contains a virus so the upload was canceled: {HEX}Malware.Expert.php.caret.hex.hex.hex.hex.upload.return.file.get.contents.str.split.UNOFFICIAL FOUND
This is what I did:
  1. I downloaded the archive file phpBB-3.3.15-files.tar.bz2 from https://www.phpbb.com/downloads/3.3/changedfiles
  2. I checked the SHA256 signature of the downloaded copy and it is OK
  3. I removed all tarballs I wasn't interested in and only left the following folders/file:
    • docs
    • install
    • vendor
    • phpBB-3.3.14_to_3.3.15.tar
  4. I tried to upload this "purged" archive but cPanel blocked the transfer with the error reported above.
Is there really a virus in the published phpBB-3.3.15-files.tar.bz2 archive? It seems impossible to me. Anyway, if there's really a virus what can I do to get rid of it?

Ciao,
Max
User avatar
thecoalman
Community Team Member
Community Team Member
Posts: 6836
Joined: Wed Dec 22, 2004 3:52 am
Location: Pennsylvania, U.S.A.

Re: cPanel found a virus in update package from 3.3.14 to 3.3.15

Post by thecoalman »

This is likely a false positive. All security related issues are reported to security tracker. Someone will help you there.

https://tracker.phpbb.com/secure/Browse ... jspa#10020

Closing this topic.
“Results! Why, man, I have gotten a lot of results! I have found several thousand things that won’t work.”

Attributed - Thomas Edison

Return to “[3.3.x] Support Forum”