<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Liferay 7.1.2 GA2 - targeted by malware</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=119061497" />
  <subtitle>Liferay 7.1.2 GA2 - targeted by malware</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=119061497</id>
  <updated>2026-04-04T13:22:27Z</updated>
  <dc:date>2026-04-04T13:22:27Z</dc:date>
  <entry>
    <title>RE: Liferay 7.1.2 GA2 - targeted by malware</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119073863" />
    <author>
      <name>Dominik Marks</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119073863</id>
    <updated>2020-04-30T15:22:48Z</updated>
    <published>2020-04-30T15:22:48Z</published>
    <summary type="html">&lt;div class="quote-title"&gt;Davide del Vecchio:&lt;/div&gt;&lt;blockquote&gt;&lt;br /&gt;Thank you, last question (I hope):&lt;br /&gt;If I use the binary in the comments, what I need to do is  just replace the tomcat and osgi folder?&lt;/blockquote&gt;&lt;br /&gt;Yes, you just have to unzip the provided patches into your installation, overwriting every file found. The server should be stopped before. Afterwards it is recommended to clear some directories, so that no cached files or cached settings cause problems. That means, clear the following directories (if present):&lt;br /&gt;&lt;br /&gt;&lt;ul style="list-style: disc outside;"&gt;&lt;li&gt;bundles\osgi\state&lt;/li&gt;&lt;li&gt;bundles\tomcat-9.0.17\temp&lt;/li&gt;&lt;li&gt;bundles\tomcat-9.0.17\work&lt;/li&gt;&lt;li&gt;bundles\work&lt;/li&gt;&lt;/ul&gt;</summary>
    <dc:creator>Dominik Marks</dc:creator>
    <dc:date>2020-04-30T15:22:48Z</dc:date>
  </entry>
  <entry>
    <title>RE: Liferay 7.1.2 GA2 - targeted by malware</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119076392" />
    <author>
      <name>Christoph Rabel</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119076392</id>
    <updated>2020-04-30T13:58:51Z</updated>
    <published>2020-04-30T13:58:51Z</published>
    <summary type="html">I think, you use the wrong term here. At least for me CORS means &amp;#34;Cross-Origin Resource Sharing&amp;#34;. CORS has nothing to do with this.&lt;br /&gt;But allowing only certain IPs to access /api/jsonws should work, since attackers would have to attack from those IPs. Of course, it would still be best to really patch the issue.</summary>
    <dc:creator>Christoph Rabel</dc:creator>
    <dc:date>2020-04-30T13:58:51Z</dc:date>
  </entry>
  <entry>
    <title>RE: Liferay 7.1.2 GA2 - targeted by malware</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119075686" />
    <author>
      <name>Davide del Vecchio</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119075686</id>
    <updated>2020-04-30T13:13:20Z</updated>
    <published>2020-04-30T13:13:20Z</published>
    <summary type="html">&amp;lt;p&amp;gt;What if I set CORS (for specific IPs that I need) instead of shutting down all the API ?&amp;lt;/p&amp;gt;</summary>
    <dc:creator>Davide del Vecchio</dc:creator>
    <dc:date>2020-04-30T13:13:20Z</dc:date>
  </entry>
  <entry>
    <title>RE: Liferay 7.1.2 GA2 - targeted by malware</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119075334" />
    <author>
      <name>Davide del Vecchio</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119075334</id>
    <updated>2020-04-30T13:11:39Z</updated>
    <published>2020-04-30T13:11:39Z</published>
    <summary type="html">Thank you, last question (I hope):&lt;br /&gt;If I use the binary in the comments, what I need to do is  just replace the tomcat and osgi folder?</summary>
    <dc:creator>Davide del Vecchio</dc:creator>
    <dc:date>2020-04-30T13:11:39Z</dc:date>
  </entry>
  <entry>
    <title>RE: Liferay 7.1.2 GA2 - targeted by malware</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119066025" />
    <author>
      <name>Christoph Rabel</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119066025</id>
    <updated>2020-04-29T06:58:31Z</updated>
    <published>2020-04-29T06:58:31Z</published>
    <summary type="html">Yes. You need to create the binary patches too (or download them from the blogpost, Dominik Marks has provided links in the comments)</summary>
    <dc:creator>Christoph Rabel</dc:creator>
    <dc:date>2020-04-29T06:58:31Z</dc:date>
  </entry>
  <entry>
    <title>RE: Liferay 7.1.2 GA2 - targeted by malware</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119065671" />
    <author>
      <name>Davide del Vecchio</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119065671</id>
    <updated>2020-04-28T21:10:30Z</updated>
    <published>2020-04-28T21:10:30Z</published>
    <summary type="html">So updating to GA4 doesn&amp;#39;t solve it?&lt;br /&gt;I need to create binary patches too?&lt;br /&gt;Unfortunately I need to use jsonws.</summary>
    <dc:creator>Davide del Vecchio</dc:creator>
    <dc:date>2020-04-28T21:10:30Z</dc:date>
  </entry>
  <entry>
    <title>RE: Liferay 7.1.2 GA2 - targeted by malware</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119062816" />
    <author>
      <name>Christoph Rabel</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119062816</id>
    <updated>2020-04-28T18:43:58Z</updated>
    <published>2020-04-28T18:43:58Z</published>
    <summary type="html">Dominik Marks has already posted a link to his post &amp;#34;Creating Liferay Security Binary Patches&amp;#34;.&lt;br /&gt;Another way to protect your system is to block access to /api/jsonws completely. Please note that this could affect some functionality e.g. it isn&amp;#39;t possible to select categories for content anymore afterwards. But if you don&amp;#39;t need that and you have already a reverse proxy in front of Liferay, it is pretty easy to do that.</summary>
    <dc:creator>Christoph Rabel</dc:creator>
    <dc:date>2020-04-28T18:43:58Z</dc:date>
  </entry>
  <entry>
    <title>RE: Liferay 7.1.2 GA2 - targeted by malware</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119062208" />
    <author>
      <name>Davide del Vecchio</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119062208</id>
    <updated>2020-04-28T14:15:25Z</updated>
    <published>2020-04-28T14:15:25Z</published>
    <summary type="html">Thanks for the reply, i&amp;#39;m triying right now to upgrade to 7.1.3 GA4.&lt;br /&gt;&lt;br /&gt;&amp;#34;apply the latest security patches&amp;#34;&lt;br /&gt;How is it done?</summary>
    <dc:creator>Davide del Vecchio</dc:creator>
    <dc:date>2020-04-28T14:15:25Z</dc:date>
  </entry>
  <entry>
    <title>RE: Liferay 7.1.2 GA2 - targeted by malware</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119061863" />
    <author>
      <name>Dominik Marks</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119061863</id>
    <updated>2020-04-28T14:09:10Z</updated>
    <published>2020-04-28T14:09:10Z</published>
    <summary type="html">Hello Davide,&lt;br /&gt;&lt;br /&gt;if you can you should upgrade to the latest Liferay version. If not, consider updating to the latest GA of 7.1 (which is 7.1.3 GA4) and apply the latest security patches.&lt;br /&gt;&lt;br /&gt;The Liferay versions which are affected by the current exploit are mentioned in this blog post: &lt;a href="https://liferay.dev/blogs/-/blogs/security-patches-for-liferay-portal-6-2-7-0-and-7-1"&gt;https://liferay.dev/blogs/-/blogs/security-patches-for-liferay-portal-6-2-7-0-and-7-1&lt;/a&gt;&lt;br /&gt; &lt;br /&gt;Also consider my own blog post on how to create binary patches for the source code patches mentioned in the blog post above:  &lt;a href="https://liferay.dev/blogs/-/blogs/creating-liferay-security-binary-patches"&gt;https://liferay.dev/blogs/-/blogs/creating-liferay-security-binary-patches&lt;/a&gt;</summary>
    <dc:creator>Dominik Marks</dc:creator>
    <dc:date>2020-04-28T14:09:10Z</dc:date>
  </entry>
  <entry>
    <title>Liferay 7.1.2 GA2 - targeted by malware</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119061496" />
    <author>
      <name>Davide del Vecchio</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=119061496</id>
    <updated>2020-04-28T13:30:34Z</updated>
    <published>2020-04-28T13:30:34Z</published>
    <summary type="html">Hello,the server where the portal is running is getting targeted by a cryptocurrency malware (should I share the name?).&lt;br /&gt;Can someone help me?What can I do to prevent this, where can I look?&lt;br /&gt;Upgrading to a more recent version like GA4 can solve the prbolem or should I go with something newer like 7.2 or 7.3?&lt;br /&gt;&lt;br /&gt;Please help</summary>
    <dc:creator>Davide del Vecchio</dc:creator>
    <dc:date>2020-04-28T13:30:34Z</dc:date>
  </entry>
</feed>
