Page 1 of 2
Malware link on NCleanGrey theme footer?
Posted: Mon Aug 11, 2008 9:30 pm
by jensenbuhl
A click on the link "Icons by Vistaicons.com" in the footer of the NCleanGrey admin theme (CMSMS 1.4.1) invoked massive messages from my virus protection (Trojan Horses, Malware and so on). - I use Avast PRO on Vista.
Is that a fact? - Then it should be warned I think!
Can such links be avoided (removed)?
Regards Finn
Re: Malware link on NCleanGrey theme footer?
Posted: Mon Aug 11, 2008 9:42 pm
by reneh
I have no problem with that link on XP with NORMAN IC and AdAware etc.
And yes this link must be there for copyright reasons.
Re: Malware link on NCleanGrey theme footer?
Posted: Mon Aug 11, 2008 9:44 pm
by Dr.CSS
I don't have that problem...
Re: Malware link on NCleanGrey theme footer?
Posted: Mon Aug 11, 2008 9:50 pm
by Coldman
I did a test with Eset Nod32 and it didn't found anything
Re: Malware link on NCleanGrey theme footer?
Posted: Mon Aug 11, 2008 9:55 pm
by alby
Sophos notes:
xxxxxxx:
xxxxxxx is for malicious scripts that use obfuscation to load other malicious content.
in IE only! not in FF
I saw this months ago also but I don't think is a real malware
Alby
Re: Malware link on NCleanGrey theme footer?
Posted: Mon Aug 11, 2008 10:02 pm
by nuno
Unfortunately we can not remove the link to Vista icons (I know is not the best choice) if you want to remove my NAME that's ok (each head their judgement) the only thing I want is that, the theme NCleanGrey is used ONLY in CMSMS.
Please seen all licenses in NCleanGrey Folder include the Icons by Vistaicons.com license!
Have a nice day!
Nuno Costa
UPDATE:
Tested on VISTA, XP and LINUX it's all clean!
Re: Malware link on NCleanGrey theme footer?
Posted: Tue Aug 12, 2008 6:06 am
by jensenbuhl
Impressive reaction! - Thank you.
Did a reboot of my computer, tested it this morning on both Vista (Avast PRO) and XP (Avast home). - I cannot reproduce the problem, so I dont know what really happened (a bit scary though) - Sorry for the fuzz I created.
Ofcourse cleans links are OK. You deserve credit for your great work.
Regards, Finn
Re: Malware link on NCleanGrey theme footer?
Posted: Tue Aug 12, 2008 8:03 am
by jensenbuhl
Sorry to re-open the case.
We discussed the issue at work, and decided to try here. XP PRO (Symantec Antivirus).
This does definately not make one confident visiting the page. - See attched screenshot.
After "not accepting" any suspicious and closing all warning boxes from symantec, I tried to re-click the link. - Now There were no warnings. The page vistaico.com just showed up. - What is this?
Regards, Finn
Re: Malware link on NCleanGrey theme footer?
Posted: Tue Aug 12, 2008 5:47 pm
by nuno
jensenbuhl Hi
yes i reproduce now the issue, let me think wat i can do about!
Thank you
Nuno Costa
Re: Malware link on NCleanGrey theme footer?
Posted: Tue Aug 12, 2008 6:17 pm
by Dr.CSS
I have notified the good folks at VistaIcons as to our problem and hope to hear from them soon...
Hello...
Some of your icons are being used in the theme for the admin/back end for CMS Made Simple so there is a link in the bottom of all pages in it. There has been some reports of people coming to your site from that link and getting notification from their antivirus software of malware trying to infect there computer. This is only happening when using IE. I'm concerned that your site may have been hacked with some ActiveX script for drive by downloads. You may view the thread in the forum here, (link to this thread).
The icons are very nice and we appreciate the use of them and have the link to you as we think it should be done but with the possibility of having users infected by something from your site, regrettably, the link may have to be removed to protect the CMS Made Simple community.
Re: Malware link on NCleanGrey theme footer?
Posted: Tue Aug 12, 2008 9:01 pm
by nuno
Okay i changed in svn that link for
http://www.cmsmadesimple.org/visaico-license.pdf
and send to folks one email, so ..., let see what happen!
If you guys want change the link modify in NCleanGreyTheme.php for
http://www.cmsmadesimple.org/visaico-license.pdf but for now do not remove the VistaIcon Name!
More reports it's appreciate!
Nuno
Re: Malware link on NCleanGrey theme footer?
Posted: Wed Aug 13, 2008 7:29 pm
by jensenbuhl
I understand that we are trying to avoid links to a potential insecure page.
Now the link is in "the next" level, and I just tried it again - result was the same - it still provokes my security program.
It is worth to mention that nothing supiscious happans at the next visit (brave me)?!.
Have I mentioned that I think that the NCleanGrey theme really gives this great CMS system a nice look. Hope that this issue will not affect the popularity.
/Finn
Re: Malware link on NCleanGrey theme footer?
Posted: Thu Aug 14, 2008 10:24 am
by kermit
dump the icons; find truly free alternatives, of which there are countless to choose from.
imho, there shouldn't be a separate 'designed by' credit (sorry, nuno) OR credit for 'icons' in the footers of admin pages.
whatever is in the cmsms distribution archive should all be gpl or compatible licensed, period -- specific attribution requirements and/or usage restrictions are not.
and, the only 'credit' that should appear anywhere is one for cms made simple, the project. i have, on several occasions, suggested an 'about cmsms' page in the admin area where specific credit can be made for each person on the cmsms dev team, and each third-party project that cmsms incorporates into itself; and such a page is a much more appropriate place for them... but tacking on credits for this and that at the bottom of pages is.. well.. tacky... where does it end?
Re: Malware link on NCleanGrey theme footer?
Posted: Thu Aug 14, 2008 10:46 am
by nuno
kermit wrote:
imho, there shouldn't be a separate 'designed by' credit (sorry, nuno) OR credit for 'icons' in the footers of admin pages.
This is just to your knowledge was not my idea to put my credits in the admin was calguy1000 ted idea, to encouraging more people to develop themes for the admin site.
i did not the admin theme to put my name in there, but you'll excuse me and all, but my theme is only for use in cmsms not want to see my theme in other cms's so ... I have this right.
if you ppl want tak of my name you and all are welcome!
kermit wrote:
dump the icons; find truly free alternatives, of which there are countless to choose from.
Well, if you find tell me
kermit wrote:
whatever is in the cmsms distribution archive should all be gpl or compatible licensed, period -- specific attribution requirements and/or usage restrictions are not.
Ted send a email to the vistaico folks in that time, i don't see any problerms with vistaico icons (i think...) !
Re: Malware link on NCleanGrey theme footer?
Posted: Thu Aug 14, 2008 11:35 am
by nuno
In svn:
Removed my name (Nuno Costa) in footer ... enjoy ... and my license updated (is not the first to suggests remove my name of the theme I am very disappointed, if the name Calguy1000 was there you guys suggested also to remove?)
remove vistaicon link until they take off the Malware
Hope you guys are HAPPY now!!!
Nuno Costa