Author Topic: false positive for our site !!!!!!!  (Read 2487 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
false positive for our site !!!!!!!
« on: March 21, 2017, 10:22:44 AM »
We are the Sunny Inch company based in France. We noticed that our site has been hacked on Monday 13/03/2017. We have already solved this problem. But, the extension avast Online Security always indicates our site is an danger. It concerns the extension downlowded in google web chrome (avast online secutity).

Could you please again analyse our site and update the new information in your system that our site is not dangerous anymore?

We contacted the customer service 4 days ago! We did not receive any news! Your system already blocs our site, please solve this probleme right now. Our customers lost the confidence in our website, also the logg-in in their costumer account isn't possible !!!!!!!!

For your information, we also contacted the Norton company (the extension: Norton Safe Search as default Chromium), they have already updated and confirmed our site is now safe.

Our site : www.sunny-inch.fr

Looking forward to reading to you.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: false positive for our site !!!!!!!
« Reply #1 on: March 21, 2017, 10:25:50 AM »
You can report a URL here: https://www.avast.com/report-a-url.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline LukasJ

  • Avast team
  • Jr. Member
  • *
  • Posts: 86
Re: false positive for our site !!!!!!!
« Reply #2 on: March 21, 2017, 10:33:43 AM »
URL has been removed from blacklist.

REDACTED

  • Guest
Re: false positive for our site !!!!!!!
« Reply #3 on: March 21, 2017, 10:44:26 AM »
You can report a URL here: https://www.avast.com/report-a-url.php

I have already report it in this URL. But not have any new......

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: false positive for our site !!!!!!!
« Reply #4 on: March 21, 2017, 10:47:36 AM »
You can report a URL here: https://www.avast.com/report-a-url.php
I have already report it in this URL. But not have any new......
See Reply #2. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: false positive for our site !!!!!!!
« Reply #5 on: March 21, 2017, 10:51:02 AM »
URL has been removed from blacklist.
what it means? Red icon is disappearing ? when ?

REDACTED

  • Guest
Re: false positive for our site !!!!!!!
« Reply #6 on: March 21, 2017, 10:54:33 AM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: false positive for our site !!!!!!!
« Reply #7 on: March 21, 2017, 11:23:03 AM »
URL has been removed from blacklist.

run manual update and reboot computer

any change?


Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: false positive for our site !!!!!!!
« Reply #8 on: March 21, 2017, 11:26:04 AM »
URL has been removed from blacklist.
what it means? Red icon is disappearing ? when ?

That isn't the virus definitions, if it was you wouldn't be able to visit your site without an avast alert.

That is the avast Browser security extension (AOS), I'm not sure what avast has to do to counter that. Or whether a VPS update would do that also.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline LukasJ

  • Avast team
  • Jr. Member
  • *
  • Posts: 86
Re: false positive for our site !!!!!!!
« Reply #9 on: March 21, 2017, 02:17:38 PM »
There was a phishing in the site. Then I had to remove site from blacklist and after it we waited for updating AOS.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: false positive for our site !!!!!!!
« Reply #10 on: March 21, 2017, 06:00:05 PM »
Some improvements could be made:
https://urlscan.io/result/856c2e8d-97c3-47c1-955e-eedb71f83335#summary
and
https://observatory.mozilla.org/analyze.html?host=www.sunny-inch.fr
vuln:
http://www.domxssscanner.com/scan?url=https%3A%2F%2Fwww.sunny-inch.fr%2F
2 vulnerable libraries:
http://retire.insecurity.today/#!/scan/b54c388f819da0a78912aa0b0afd054cb2d0ae199cfb5dd7a9e471c78e41acec
Most users block -https://tracking.veille-referencement.com/TAG/TAG_passage.js?idsite=12848
because it is in the EasyPrivacy list. -> http://www.domxssscanner.com/scan?url=https%3A%2F%2Ftracking.veille-referencement.com%2FTAG%2FTAG_passage.js%3Fidsite%3D12848 (also missing SRI-hash detected for this script)

B-Status two script issues: https://sritest.io/#report/8266ba73-ec79-4f6c-b2eb-0014553c6fd2

polonus (volunteer website security analyst and website error-hunter)
« Last Edit: March 21, 2017, 06:02:21 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!