Two issues are highlighted here, one is Sucuri Malware Auditor and the other is Simple Firewall. Both are security plugins used on sites.
Sucuri Malware Auditor
Sucuri Malware auditor is used on pretty much all of the sites. It had a bug during the first half of January causing a white screen to come up with an error message from Sucuri. An example is below:
Sucuri:(1452098269) Send_log:SSL connect error
Warning: Cannot modify header information – headers already sent by (output started at/home/cwj1214/public_html/wp-content/plugins/sucuri-scanner/sucuri.php:6929)in/home/cwj1214/public_html/wp-admin/post.php on line 197
Refreshing your screen would normally get rid of the problem.
These messages appear when you are editing something and relate to a security plugin attempting to send a message to a log file on another website. A fix was created, and the problem occurs much less frequently. I do not believe it affects users at all.
If it is getting in your way, go to Plugins, and looks for Sucuri in the list of plugins and deactivate it while you are working on the site. When you have completed your edits turn it back on.
The developers behind this plugin will eventually release a version where Sucuri just becomes invisible again working in the the background.
WordPress Security Firewall
************************************************************************
Update: 24th January 2016
This is the latest information on this bug:
The developer is aware that all sites using the WordPress Security Firewall (formerly known as “Simple Firewall”) are sending back messages about checksum errors. This is because a new feature has been added, but not adequately tested.
I have checked a few sites and there is not a problem on the sites I have checked. As we are generally very secure (provided we keep our passwords both tough and secret), I am not concerned about this problem.
Most of you will not see the error messages because they come to me. For those that also see them, do not worry about them for now. Do come back and check this page in a week’s time to see if anything has changed.
I have posted a message to the developer, and the developer is working on solutions with a small group of Beta Testers (advanced testers that check something before it is released to the public).
There is a fix that could be employed, where the plugin that detects the problem repairs it by downloading the new file from the source repository. This is not currently enabled. I recommend that for now we wait and see if this is resolved automatically.
*********************************************************************
Original post
A new feature in this plugin is throwing up errors on index.php files reporting a checksum error on two files. I have had two cases reported and in each case I have investigated it and the problem in both of these cases were no cause for concern.
The errors that have been appearing are reproduced below:
The MD5 Checksum Hashes for following core files do not match the official WordPress.org Checksum Hashes:
– wp-content/themes/index.php
– wp-content/plugins/index.php
However if you get that error on your site, do let me know and I will check and confirm. Do not ignore it because an index.php file is a great place to hide something nasty. The index.php files in question hide the contents of the directories they are in.
The Simple Firewall does a check sum on the files in the system to see if any have been modified from the original files. The process is much more complicated than this but if you had a file with the values 10, 5, 13, 21, 16, 20,000, 14, 2, 7, 8, 15 and 61, the checksum algorithm adds them up and creates a sum of the values, in this case it would be 20,172.
If a hacker compromised the website and added in his code into the file, let’s say the hackers code was 13,4,5, then the checksum would be different. In this case the modified file would be 10, 5, 13, 21, 16, 20,000, 14, 2, 8, + 13,4,5 which would equal: 20,194.
The checksum program knows the value should be 20,172, but the calculation it has performed results in 20,194 indicating that there may be something wrong with the file.
It is better to have this feature turned on rather than off.
Some people may look at my description and think it is easy to work around. And you would be right! I have over simplified the explanation, the result is encrypted, and there are other parameters which are measured as well as the sum of the values in the file. But hopefully most people could follow the explanation.
I checked the plugin author’s support pages and he is introducing a fix for the problem, with regards to these two files. So it is quite possible by the time you read this that the problem no longer exists.