• Resolved markslang

    (@markslang)


    I am a new Security Pro user, and I am trying to better understand the track file changes feature. I have a log entry for changed files that expands into 615 pages of files that include all kinds of things. They are under “added.” Perhaps the first time it lists every file? Would that explain this? I have a partial listing below. I have other entries, for example, that seem to reflect when I update a plugin as there are many changes in that plugin directory. I am trying to understand how I know whether changes are normal or malicious. Does Security Pro flag some changes differently?

    I formerly used WordFence, which compares all WordPress files and plugins to the master ones at WordPress and flags differences. This sometimes picks up extraneous things, like when a comment is changed in the master file to indicate the latest WordPress version supported. However, Security Pro could show a whole lot of changes if I perhaps update my theme. I am trying to understand how to practically interpret this feature.

    I also checked the option to compare to WordPress, which it says only impacts WordPress core files and iThemes plugins at this point. I am not sure how that affects the regular list of files changed.

    Any advice is appreciated. Thanks.

    Here are a couple of pages of the changed files listing:

    • added
    o wp-config.php
     d = 1453824471
     h = d8f7e8c8b36770b4e20bc9ace8665500
    o wp-admin/install-helper.php
     d = 1450060367
     h = 6456b260aa9dece9b30431260cdb1a6c
    o wp-admin/options.php
     d = 1450060367
     h = 75a0f09f837949e8f902c572067ce3eb
    o wp-admin/options-media.php
     d = 1450060367
     h = ec412c7889ecc50fe0f792fd6ca8ac91
    o wp-admin/edit.php
     d = 1460567323
     h = d1188bd32484c1f264351ed2d1797ecd
    o wp-admin/options-general.php
     d = 1460567323
     h = c412045051e5049d3b2535b86f2db0ce
    o wp-admin/link-add.php
     d = 1380082692
     h = 759747ef8d44c52fadcfa5c457f3f283
    o wp-admin/ms-admin.php
     d = 1380082692
     h = 9a05b49740dfcdaf4516851b623606e4
    o wp-admin/edit-form-advanced.php
     d = 1460567323
     h = ec47b8411683ab0c2cdefc4588062a83
    o wp-admin/network/site-users.php
     d = 1460567323
     h = 780a49acdc080139f16d282a7ab257f9
    o wp-admin/network/edit.php
     d = 1417364482
     h = 0deb5ea059c21f268c973b5ea0fcd21a
    o wp-admin/network/admin.php
     d = 1397275276
     h = 4e85d4354373cc17b9099b130b121f12
    o wp-admin/network/update.php
     d = 1380082692
     h = ba45a05ecc211e8cab75b4d529ff75f7
    o wp-admin/network/sites.php
     d = 1460567323
     h = 82b9a0b6a12060380ee6085133696280
    o wp-admin/network/site-new.php
     d = 1460567323
     h = ec0ac55626819fd1a76547d6ea0ec854
    o wp-admin/network/plugin-install.php
     d = 1380082692
     h = 6bbd804f795fa5a934f529a51a9886bf
    o wp-admin/network/menu.php
     d = 1440695643
     h = dec182302b1a3d0b6cda2ea687574083
    o wp-admin/network/users.php
     d = 1460567323
     h = c30d91850d6fee6fa04ef366834109e8
    o wp-admin/network/theme-editor.php
     d = 1380082692
     h = 804f9a460fa9e3646d83f915c51cd36a
    o wp-admin/network/freedoms.php
     d = 1380082692
     h = 109efa9312c00370894f7e2ba27e9c31
    o wp-admin/network/plugin-editor.php
     d = 1380082692
     h = 3fb5cd9ab947024d84585a0d693dcc12
    o wp-admin/network/user-new.php
     d = 1460567323
     h = e63b9ea131e88ac260ebfb6e7f21456c
    o wp-admin/network/index.php
     d = 1440695643
     h = b38da979af35e6ac535160790ed0b6e8
    o wp-admin/network/site-info.php
     d = 1460567323
     h = 009a87e11a02fa093f6c3a7c3d36e243
    o wp-admin/network/profile.php
     d = 1380082692
     h = d86926a7511d1d5cd3a2f0a502e7b6a8
    o wp-admin/network/themes.php
     d = 1460567323
     h = 07d4e94d9e73179e7e7a2ba0a4976038
    o wp-admin/network/about.php
     d = 1380082692
     h = e9e33df9da15a95356e6da0e56889fec
    o wp-admin/network/plugins.php
     d = 1380082692
     h = 4193887cb9cb7f4d4d3000bdf303bf1e
    o wp-admin/network/update-core.php
     d = 1380082692
     h = a1223f017d52327b385cac03833f52ea
    o wp-admin/network/setup.php
     d = 1380082692
     h = ee19cf426d3e6e397a5d891f08d19ae2
    o wp-admin/network/settings.php
     d = 1460567323
     h = f9a79b79a2dccacc4fe0088061af9dff
    o wp-admin/network/user-edit.php
     d = 1380082692
     h = 318173b6ccb63ed80ba3d08563c3ff14
    o wp-admin/network/upgrade.php
     d = 1460567323
     h = 7ceed5e8662adce9f428100ffd87af08
    o wp-admin/network/credits.php
     d = 1380082692
     h = 38192cde34142cc7ecf558f58ef475f0
    o wp-admin/network/theme-install.php
     d = 1380082692
     h = 26d5b7cd315570d025e09e11313d24e4
    o wp-admin/network/site-settings.php
     d = 1460567323
     h = c33dbbceff17c761ca17a1d8921802a3
    o wp-admin/network/site-themes.php
     d = 1460567323
     h = b9f3aae2c1e6e6d005d7b46b34d2430c
    o wp-admin/load-scripts.php
     d = 1460567323
     h = 1fb821b121bb44bd0f44733f9eaf1eca
    o wp-admin/admin.php
     d = 1460567323
     h = 9c3b51477a084b08c41c6bc054cb1471
    o wp-admin/options-head.php
     d = 1362176050
     h = bad695605e6db04e400a546f667eb70b
    o wp-admin/term.php
     d = 1460567323
     h = 7e4fbf51d01bbd3bbb1d94cd8a43856c
    o wp-admin/moderation.php
     d = 1380082692
     h = 541242a293805952a0e22234f09d6fa9
    o wp-admin/js/customize-controls.js
     d = 1460567323
     h = 38dcd3fd1e6f4a9e4503eb6eae7ae92f
    o wp-admin/js/postbox.js
     d = 1460567323
     h = 865e4f8df693705b404c45fddc1bd65f
    o wp-admin/js/bookmarklet.min.js
     d = 1440695643
     h = b7ee968190e961f9aefeddac25543c45
    o wp-admin/js/farbtastic.js
     d = 1289511262
     h = a73af354a03241715d8698feea340b92
    o wp-admin/js/tags.js
     d = 1426179146
     h = 4cc64266f1b35a86c63cc1b2c42f7306
    o wp-admin/js/user-profile.min.js
     d = 1460567323
     h = bb06b01380b31741cc3c6bb0475fa15e
    o wp-admin/js/media.min.js
     d = 1428051148
     h = 2e8efd83242126157ff0bffd5e249159
    o wp-admin/js/customize-controls.min.js
     d = 1460567323
     h = 14749abf568a231c66bc8d7b086a32ac
    o wp-admin/js/editor-expand.min.js
     d = 1460567323
     h = eb145a2ecb2bb7e11fb759364301c88b
    o wp-admin/js/edit-comments.min.js
     d = 1460567323
     h = 3c16bfa9df88e42ccd3756bec32fe937
    o wp-admin/js/set-post-thumbnail.js
     d = 1384510330
     h = 2b5153576d1eee4002fb7ed9e5831251
    o wp-admin/js/user-suggest.js
     d = 1390882212
     h = 1e33290807fa8b2829ddb0347d0a9305
    o wp-admin/js/customize-nav-menus.js
     d = 1460567323
     h = 852fe74d1ce464ec9e621e10e52428e8
    o wp-admin/js/inline-edit-post.js
     d = 1460567323
     h = e3751de1470210ce39ef99ef70f598e5
    o wp-admin/js/tags-box.min.js
     d = 1450060367
     h = a446052ae0cf9947db74a78d2dfd1b1f
    o wp-admin/js/press-this.min.js
     d = 1450060367
     h = 18c78fc40d75f973159700ac6bbdd83a
    o wp-admin/js/password-strength-meter.min.js
     d = 1384510330
     h = 3185f27c8fa4123db79a1d6de055c9d7
    o wp-admin/js/custom-background.js
     d = 1384425612
     h = f26af7294ee07fb9a0cb88c2a8697623
    o wp-admin/js/xfn.min.js
     d = 1384484290
     h = 66b227ca28f41f2e0615b04a390d5e04
    o wp-admin/js/editor.min.js
     d = 1460567323
     h = 6e13c98d1b89242683a6a1f0ffe3466e
    o wp-admin/js/language-chooser.min.js
     d = 1407199636
     h = 1d6822384a71090c74add106e4468581
    o wp-admin/js/inline-edit-tax.js
     d = 1460567323
     h = bff3a6a1fcc82259876743865f72d438
    o wp-admin/js/nav-menu.js
     d = 1460567323
     h = 2018071a5a024a8a8c56f793c415e4c1
    o wp-admin/js/common.js
     d = 1460567323
     h = 0b5a51ad30a18d0328f17c2616da58a2
    o wp-admin/js/gallery.min.js
     d = 1450060367
     h = 4e7b25e9bc3374cf391d5a652651a277

    https://wordpress.org/plugins/better-wp-security/

Viewing 2 replies - 1 through 2 (of 2 total)
  • @markslang

    First of all apologies for my late response.
    I more or less promised to answer your question so here it is.

    Before digging into your question a short remark about posting questions in this forum related to the iTSec Pro plugin.

    When you buy the iTSec Pro plugin from iThemes 1 year of support from iThemes is included. So you would normally log into the iThemes Member Panel with your credentials obtained at purchase and then create a support ticket.

    That said File Change Detection is not a Pro only feature so for this particular topic you can also expect support from the wordpress.org community (even though you are using the Pro plugin).

    The first time the iTSec (Pro) plugin runs a File Change Detection scan there is no data (stored in the database) to compare with. So all files are listed as Added. This is normal and expected behavior.

    The data displayed after clicking on the Details link in the Logs page is difficult to understand for an average person using the plugin (though the data is formatted the way it is for a very good reason), but if you switch to the “File Change History” Select Filter: at the top of the log and then click on a Details link you’ll find that the data is displayed in a much more readable format.

    The File Change Detection feature works basically the same in the free and Pro plugin with one exception. In the Pro plugin there is an extra setting available named Compare Files Online.
    If enabled WordPress core files and iThemes plugin/theme files with detected changes will be compared with the clean master files at WordPress.org and/or at iThemes.
    If the checksums of changed files match with the checksums of the clean online master files they are removed from the File Change Detection scan result.
    So this results in much less file changes listed under the Details link in the Logs page. Very cool feature.

    It is your job to link reported file changes to events that occurred in your WordPress env. These events range from WordPress core updates to updating/deleting plugins, themes etc. Any reported file changes that you cannot link to a legit event in your WordPress env needs your special attention.

    I hope this clarifies the File Change Detection feature.

    dwinden

    Thread Starter markslang

    (@markslang)

    Thanks, dwinden. I am starting to understand this plugin. It will be useful when they upgrade the Compare Files Online feature to include plugins and themes beyond the iThemes ones. Otherwise, I have to review things. I notice that BackupBuddy, for example, apparently regularly changes a file .htaccess (not the main one). When I update my theme or a plugin, I expect to see files in that particular directory change.

    On a separate note, I see that I am getting 404 errors detected where someone is scanning my sites, apparently looking to see if I have certain vulnerable plugins they can exploit. That is something I never saw with WordFence. It is scary who is out there looking for vulnerable sites all the time.

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘Interpretting changed file indications in iThemes Security Pro’ is closed to new replies.