Author Topic: False Positive - site aborted by Web Shield - JS:Decode-CID[Trj]  (Read 2081 times)

0 Members and 1 Guest are viewing this topic.

Offline edward183

  • Newbie
  • *
  • Posts: 9
Hello,

I am website security expert and have a forum site that focuses on website security that is being incorrectly aborted/blocked by Web Shield.  This is a false positive that needs to be corrected in Avast so that any visitors to my website are not blocked/aborted from viewing my site.

Steps to reproduce the false positive block/abort:
Visit my website:  https://forum.ait-pro.com/activity/
Enter this search term in the search text box located at the top right side navigation bar:  admin-ajax.php
Select both Search Filters checkboxes:  Show Topics only and Show Topics & Replies
Click the Search button.
You should see the Avast Web Shield popup.

Edit|Update: I just found your False Positive submission form and have submitted a false positive form request.
« Last Edit: July 26, 2019, 07:59:57 PM by edward183 »


Offline edward183

  • Newbie
  • *
  • Posts: 9
Re: False Positive - site aborted by Web Shield - JS:Decode-CID[Trj]
« Reply #2 on: July 26, 2019, 11:35:55 PM »
Interesting since that would mean WordPress itself has these issues and not my particular website since I am using the bundled libraries that come with WordPress. I think the warnings are probably overly picky/cautious and does not mean that anything actually need to be "fixed". Anyway that issue probably wouldn't have anything to do with the false positive from Avast or maybe Avast is also being overly picky/cautious. Doubt that is what is going on though.

Got to say the CAPTCHA feature in this forum is pretty bad. You can hardly read the letters and when you request to listen for the CAPTCHA you can barely hear the audio.  I don't know who came up with the ridiculous concept of making CAPTCHA's unreadable to humans. I created a CAPTCHA in my software that is human friendly that does not do anything retarded like obfuscating the letters/images because that concept is totally ridiculous and unnecessary.  My CAPTCHA has been 100% effective at stopping all Bots for over 8 years now > https://www.ait-pro.com/wp-login.php
« Last Edit: July 26, 2019, 11:38:10 PM by edward183 »

Offline edward183

  • Newbie
  • *
  • Posts: 9
Re: False Positive - site aborted by Web Shield - JS:Decode-CID[Trj]
« Reply #3 on: July 26, 2019, 11:42:03 PM »
Oops my bad. jQuery is responsible for fixing the vulnerabilities in their libraries.  So yeah not me, not WordPress, but jQuery needs to fix those things.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: False Positive - site aborted by Web Shield - JS:Decode-CID[Trj]
« Reply #4 on: July 26, 2019, 11:59:07 PM »
Quote
Anyway that issue probably wouldn't have anything to do with the false positive from Avast or maybe Avast is also being overly picky/cautious. Doubt that is what is going on though.
I am not saying that is the reason for avast detection, just gave you info found online and only avast lab can answer why they detect ....



Quote
Got to say the CAPTCHA feature in this forum is pretty bad.
Forum spam protection, if you have problems then so does the spammers 

Only first 3 posts so you are done now   ;)




Offline edward183

  • Newbie
  • *
  • Posts: 9
Re: False Positive - site aborted by Web Shield - JS:Decode-CID[Trj]
« Reply #5 on: July 27, 2019, 02:27:40 AM »
Yeah I got that you were just pointing out some issues that need to be fixed.

Well on my site the CAPTCHA that I created is user friendly.  So humans have no problems at all and spambots and hackerbots are blocked 100%.  That makes a lot more sense to me.  Human spammers and hackers of course only make up 1% of all spamming and hacking.  99% of spamming and hacking is automated with bots.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
« Last Edit: July 27, 2019, 01:20:34 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!