Author Topic: Site Blocked  (Read 2032 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
Site Blocked
« on: November 15, 2014, 11:27:16 AM »
Hi all, I got my site blocked by Avast.

The url is: "http://www.bonnyread.com.tw/"

I suspect the issue was due to an invalid SSL Cert that the site hosting was using; It should be fixed by now by removing the certificate when trying to access the url with https port.

I wondering how can I get my site unblocked from avast. I have contacted avast with the contact form from the website but I haven't heard of them since more than a week.

Any help or suggestions would be greatly appreciate it as I have been struggling with this issue for quite a long time, losing tons of sales and customers since it is blocked.

Thanks in Advance.

Tony




REDACTED

  • Guest
Re: Site Blocked
« Reply #2 on: November 15, 2014, 12:35:13 PM »
Hi Eddy,

Thanks for the info and reply. Initially the SSL used was different from the Domain, thus, I suspect it is why we got blocked. I have fixed the issue by removing the SSL cert, so the site doesn't have SSL now, and hopefully fixing the issue. But the problem is that that avast and other blockers like BitDefender still have th site in their blacklist. I wondering how we can request them to remove it from the list or to make another analysis if possible.

Thanks

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Site Blocked
« Reply #3 on: November 15, 2014, 12:55:26 PM »
You can report it here   http://www.avast.com/contact-form.php


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Site Blocked
« Reply #4 on: November 16, 2014, 01:07:44 AM »
WARNING: MX records duplicates (same IP address):
68.178.213.203: [mailstore1.secureserver.net. smtp.secureserver.net.]
Although technically valid, duplicate MX records have no benefits and can cause confusion.
See: http://www.dnsinspect.com/bonnyread.com.tw/1416095547

For server
One correct security header -> Content   Content-Type   text/html; charset=utf-8   Use 'text/html;charset=utf-8'
Eight missing and  four with warnings check details and scan here: http://cyh.herokuapp.com/cyh
Excessive header info proliferation Server: Apache/2.2.29 (Amazon)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.17
Clickjacking warning.  RUM could break filemanager.

There are also IDS alerts on site here: http://urlquery.net/report.php?id=1415682615915
SURICATA TLS invalid handshake message

External track data found: https://www.virustotal.com/nl/ip-address/5.10.73.70/information/

This is the error report as I see it, furthermore avast sees the site as insecure.
One could file a FP report and wait for a reaction.
We here aren't avast team member that can unblock, just forum users with relevant knowledge.

polonus (volunteer website security analyst and error-hunter)
« Last Edit: November 16, 2014, 01:14:29 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!