Author Topic: Can you remove my website from Avast blacklist?  (Read 7261 times)

0 Members and 3 Guests are viewing this topic.

REDACTED

  • Guest
Can you remove my website from Avast blacklist?
« on: August 21, 2016, 08:18:45 PM »
Hello.
I dont know why my website is blocked by Avast.
Can you remove my website from Avast?
URL: hxxps://szczurekpros.pl/

Thanks
« Last Edit: August 22, 2016, 12:59:03 AM by szczurekPROS »


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34061
  • malware fighter
Re: Can you remove my website from Avast blacklist?
« Reply #2 on: August 21, 2016, 08:47:35 PM »
Ha Eddy, je was me 1 seconde voor  :P

Witam szczurekPROS,

I do not get any Avast alert for your site, nor on AOS or WOT either.

Some jquery libraries to retire, while wat you acquire you should also retire:
-https://szczurekpros.pl/
Detected libraries:
jquery - 1.5.0 : http://ajax.googleapis.com/ajax/libs/jquery/1.5.0/jquery.min.js
Info: Severity: medium
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4969
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
jquery - 1.11.2 : (active1) https://ajax.googleapis.com/ajax/libs/jquery/1.11.2/jquery.min.js
Info: Severity: medium
https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
(active) - the library was also found to be active by running code
2 vulnerable libraries detected

And a meagre F-Status here: https://sritest.io/#report/a887675e-1816-443a-bf4d-dc781a1a5859   3 issues with external script (2)  and stylesheet (1)

Found mail servers with inconsistent reverse DNS entries. You should fix them if you are using those servers to send email. (hoster = Dutch AS)

When there was something flagged, it could come IP related: https://www.virustotal.com/en-gb/ip-address/185.11.145.5/information/  other domains on that same IP there were Win32:Malware-gen infested.
Also consider: http://cyberwarzone.com/malicious-history-of-185-11-145-5/

pozdrawiam,

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: Can you remove my website from Avast blacklist?
« Reply #3 on: August 21, 2016, 08:53:50 PM »
Ha Eddy, je was me 1 seconde voor  :P

Witam szczurekPROS,

I do not get any Avast alert for your site, nor on AOS or WOT either.

Some jquery libraries to retire, while wat you acquire you should also retire:
-https://szczurekpros.pl/
Detected libraries:
jquery - 1.5.0 : http://ajax.googleapis.com/ajax/libs/jquery/1.5.0/jquery.min.js
Info: Severity: medium
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4969
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
jquery - 1.11.2 : (active1) https://ajax.googleapis.com/ajax/libs/jquery/1.11.2/jquery.min.js
Info: Severity: medium
https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
(active) - the library was also found to be active by running code
2 vulnerable libraries detected

And a meagre F-Status here: https://sritest.io/#report/a887675e-1816-443a-bf4d-dc781a1a5859   3 issues with external script (2)  and stylesheet (1)

Found mail servers with inconsistent reverse DNS entries. You should fix them if you are using those servers to send email. (hoster = Dutch AS)

When there was something flagged, it could come IP related: https://www.virustotal.com/en-gb/ip-address/185.11.145.5/information/  other domains on that same IP there were Win32:Malware-gen infested.
Also consider: http://cyberwarzone.com/malicious-history-of-185-11-145-5/

pozdrawiam,

polonus (volunteer website security analyst and website error-hunter)

Many peoples from my facebook group have problem with my website because Avast block my website.
This is shared hosting so i dont know what can i do.
On my website: https://szczurekpros.pl/ i dont have any malicious code so i dont know where is problem.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34061
  • malware fighter
Re: Can you remove my website from Avast blacklist?
« Reply #4 on: August 21, 2016, 09:26:38 PM »
Cześć,

I get a warning that site tries to load unsafe script, but absolutely no avast alert, no avast block for me first now I have it,
so the downloader-trojan acts intermittantly.

After the script loads Avast alert for a Downloader: JS:Downloader-DEL[Trj]

Working a laptop with avast av installed, now located in Zachodniopomorski

I am not on facebook, so I can not tell what happens from external links there.

The hoster you are on does not have a very reputable web rep: https://www.mywot.com/en/scorecard/blazingfast.io?utm_source=addon&utm_content=rw-viewsc

Netcraft risk rating 2 out of 10: http://toolbar.netcraft.com/site_report?url=https://szczurekpros.pl

At the end of the code there is a XMLHttpRequest(); xhr.onload see:- https://aw-snap.info/file-viewer/?tgt=https%3A%2F%2Fszczurekpros.pl%2F&ref_sel=GSP2&ua_sel=ff&fs=1

polonus
« Last Edit: August 21, 2016, 09:43:44 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Can you remove my website from Avast blacklist?
« Reply #5 on: August 21, 2016, 09:29:51 PM »
BTW your forum runs to an error page of CPanel :)

Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Can you remove my website from Avast blacklist?
« Reply #6 on: August 21, 2016, 09:37:41 PM »
Quote
This is shared hosting
Get dedicated hosting.

REDACTED

  • Guest
Re: Can you remove my website from Avast blacklist?
« Reply #7 on: August 21, 2016, 10:05:19 PM »
Cześć,

I get a warning that site tries to load unsafe script, but absolutely no avast alert, no avast block for me first now I have it,
so the downloader-trojan acts intermittantly.

After the script loads Avast alert for a Downloader: JS:Downloader-DEL[Trj]

Working a laptop with avast av installed, now located in Zachodniopomorski

I am not on facebook, so I can not tell what happens from external links there.

The hoster you are on does not have a very reputable web rep: https://www.mywot.com/en/scorecard/blazingfast.io?utm_source=addon&utm_content=rw-viewsc

Netcraft risk rating 2 out of 10: http://toolbar.netcraft.com/site_report?url=https://szczurekpros.pl

At the end of the code there is a XMLHttpRequest(); xhr.onload see:- https://aw-snap.info/file-viewer/?tgt=https%3A%2F%2Fszczurekpros.pl%2F&ref_sel=GSP2&ua_sel=ff&fs=1

polonus

I know about my hosting reputation. They allow almost for host all on hosting.
Can you give me any tips what can i do for fix this.

Thanks

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Can you remove my website from Avast blacklist?
« Reply #8 on: August 21, 2016, 10:15:23 PM »
Suspicious > 2 suspicious inline scripts found.
http://www.UnmaskParasites.com/security-report/?page=szczurekpros.pl


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34061
  • malware fighter
Re: Can you remove my website from Avast blacklist?
« Reply #9 on: August 21, 2016, 10:23:01 PM »
Cześć szczurekPROS,

As I told you and Pondus shows unsafe scripts detected by Avast as what it flags.
Pondus thanks for that link  ;)

When that is your overall position on that Dutch hoster,  and you are aware of this being the case,
then move to a hoster that does not spread malware or condones such practices by others.

Else you are stuck with this situation.

Also on a shared IP address with bad neighbors.

Może to oznaczać zwykły skok z deszczu pod rynnę!

Warnings for HTTP only cookies: Warning

Requested URL: https://szczurekpros.pl/GET | Response URL: https://szczurekpros.pl/GET | Page title: RATzone Community | HTTP status code: 200 (OK) | Response size: 4,747 bytes (gzip'd) | Duration: 931 ms
Overview
Cookies not flagged as "HttpOnly" may be read by client side script and are at risk of being interpreted by a cross site scripting (XSS) attack. Whilst there are times where a cookie set by the server may be legitimately read by client script, most times the "HttpOnly" flag is missing it is due to oversight rather than by design.

Result
It looks like a cookie is being set without the "HttpOnly" flag being set (name : value):

rcksid : HvmHaHJWmPp1Y5mLfMkVxCIuC2y4jftusTAo48x5BQx8HRuRSxovEvsaHfJaZ6yx
Unless the cookie legitimately needs to be read by JavaScript on the client, the "HttpOnly" flag should always be set to ensure it cannot be read by the client and used in an XSS attack.

Secure cookies: Warning

Requested URL: https://szczurekpros.pl/GET | Response URL: https://szczurekpros.pl/GET | Page title: RATzone Community | HTTP status code: 200 (OK) | Response size: 4,747 bytes (gzip'd) | Duration: 931 ms
Overview
Cookies served over HTTPS but not flagged as "secure" may be sent over an insecure connection by the browser. Often this may be a simple request for an asset such as a bitmap file but if it's on the same domain as the cookie is valid for then it will be sent in an insecure fashion. This poses a risk of interception via a man in the middle attack.

Result
It looks like a cookie is being served over HTTPS without the "secure" flag being set (name : value):

rcksid : HvmHaHJWmPp1Y5mLfMkVxCIuC2y4jftusTAo48x5BQx8HRuRSxovEvsaHfJaZ6yx
Unless the cookie needs to be sent over an insecure connection, the "secure" flag should always be set to ensure it can only be sent with an HTTPS request.

Clickjacking Warning:

Overview
Websites are at risk of a clickjacking attack when they allow content to be embedded within a frame. An attacker may use this risk to invisibly load the target website into their own site and trick users into clicking on links which they never intended to. An "X-Frame-Options" header should be sent by the server to either deny framing of content, only allow it from the same origin or allow it from a trusted URIs.

Result
It doesn't look like an X-Frame-Options header was returned from the server which means that this website could be at risk of a clickjacking attack. Add a header to explicitly describe the acceptable framing practices (if any) for this site.
pozdrawiam,

polonus
« Last Edit: August 21, 2016, 10:41:21 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: Can you remove my website from Avast blacklist?
« Reply #10 on: August 21, 2016, 10:40:24 PM »
Cześć szczurekPROS,

As I told you and Pondus shows unsafe scripts detected by Avast as what it flags.
Pondus thanks for that link  ;)

When that is your overall position on that Dutch hoster,  and you are aware of this being the case,
then move to a hoster that does not spread malware or condones such practices by others.

Else you are stuck with this situation.

Also on a shared IP address with bad neighbors.

Może to oznaczać zwykły skok z deszczu pod rynnę!

pozdrawiam,

polonus

This suspicious inline scripts are obfuscated HTML code only.

So i need change hosting?
Do you have any good hosting, I dont care about price

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Can you remove my website from Avast blacklist?
« Reply #11 on: August 21, 2016, 10:47:32 PM »
I use this one for years > https://www.mijndomein.nl/
Never had a problem with them.
Once I saw a dubious website on the same IP, mentioned it to them and my site was placed on another IP within 24 hours.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34061
  • malware fighter
Re: Can you remove my website from Avast blacklist?
« Reply #12 on: August 21, 2016, 11:03:26 PM »
Eddy, such suggestions please per PM, we do not want our forum friends accuse us of spamming.  ;)
I also made some suggestions to our friend, szczurekPROS, he cannot PM back for now, but receive messages he can.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34061
  • malware fighter
Re: Can you remove my website from Avast blacklist?
« Reply #13 on: August 21, 2016, 11:36:47 PM »
I have asked an Avast Team Member to react here to-morrow.
Whenever he does, we can say more on the subject and where the inline scripts originate from
(as I think is obfuscated script from that Dutch hosting party,
and establish whether it is malicious or benign).

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
« Last Edit: August 22, 2016, 12:24:06 AM by Eddy »