BPS Pro Alert: Hidden Plugin Folders|Files (HPF) Alert

Home Forums BulletProof Security Pro BPS Pro Alert: Hidden Plugin Folders|Files (HPF) Alert

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #38512
    malcolm
    Participant

    Hi I keep getting email alerts regarding a plug in I installed from the word press repository (GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership)

    As the name implies the plugin deals with payments using crypto-currency (Bitcoin etc) and so it could potentially have a malicious file.

    I don’t think that’s the case but I’m not capable of determining that.

    the alert on the WP dashboard reads;

    BPS Hidden Plugin Folder|Files (HPF) Alert
    A plugin folder was found in your /plugins/ folder that is either a hidden plugin (plugin that is not displayed on the WordPress Plugins page) or an empty plugin folder. You can either delete this folder or if you recognize this folder and/or it is safe to ignore this folder you can ignore this folder check by adding the HPF Ignore Rule shown below in the Ignore Hidden Plugin Folders & Files textarea box option to make this Alert go away.
    Plugin Folder Path: /home/user/photography.phasm.co.uk/wp-content/plugins/gourl-php
    HPF Ignore Rule: gourl-php
    Last Modified Time: 16th January 2020 @ 2:01 am
    Last Change Time: 16th January 2020 @ 2:01 am
    Last Access Time: 16th January 2020 @ 2:01 am

    any advice?

    #38517
    AITpro Admin
    Keymaster

    Create an HPF ignore rule for this additional plugin folder created by the GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership plugin.  I tested the plugin and when you install and activate the plugin it creates this additional plugin folder: /gourl-php/. The HPF checking code sees this as a possible illegitimate/malicious plugin folder because the HPF check that is done compares all plugins that are installed and listed on your WordPress Plugins page against plugin folders in your plugins folder. The additional /gourl-php/ plugin folder is not listed on your WordPress Plugins page. So the HPF check sees it as illegitimate/suspicious/malicious.  Or in other words, the /gourl-php/ plugin folder is a hidden plugin folder.

    The GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership plugin creates 2 plugin folders:
    /gourl-bitcoin-payment-gateway-paid-downloads-membership/
    /gourl-php/

Viewing 2 posts - 1 through 2 (of 2 total)
  • You must be logged in to reply to this topic.