Author Topic: Site blocked for phishing  (Read 1426 times)

0 Members and 1 Guest are viewing this topic.

Offline geigev

  • Newbie
  • *
  • Posts: 4
Site blocked for phishing
« on: September 26, 2019, 09:49:18 PM »
Avast/avg has corrected this -- thank you.
« Last Edit: September 28, 2019, 08:38:37 PM by geigev »

Offline geigev

  • Newbie
  • *
  • Posts: 4
Re: Site blocked for phishing
« Reply #1 on: September 27, 2019, 12:25:06 AM »
Having to deal with hundreds of emails/messages about this -- how long does the review process generally take?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Site blocked for phishing
« Reply #2 on: September 27, 2019, 12:37:03 AM »
An avast team member, responsible for the detection, has to look into the matter.
Normally that would not take that long or it should be reported over the weekend.
Wait for their final verdict. We here are just volunteers with expertise knowledge,
but cannot come and unblock.

See the code: https://aw-snap.info/file-viewer/?protocol=secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=c3R9e3xteXx9Iy5eXW1g~enc

Re: https://sitecheck.sucuri.net/results/https/streamyard.com  (some security header issues mentioned);
Linting website development recommendations here: https://webhint.io/scanner/0918b118-7aaf-400d-a240-4e3fe7a70da9
with some 198 of such tips, some security related (see under security there).

DOM-XSS issues on website: Results from scanning URL: -https://cdnjs.cloudflare.com/ajax/libs/autotrack/2.4.1/autotrack.js
Number of sources found: 266
Number of sinks found: 94

Could it be a hidden iFrame is being flagged: <iframe src="hxtps://www.googletagmanager.com/ns.html?id=GTM-5KG4PZD" height="0" width="0" style="display:none;visibility:hidden"></iframe>

Privacy concerns in more detail about this here: https://webcookies.org/cookies/streamyard.com/28452500?360900

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)

« Last Edit: September 27, 2019, 12:39:31 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89057
  • No support PMs thanks
Re: Site blocked for phishing
« Reply #3 on: September 27, 2019, 12:40:43 AM »
Having to deal with hundreds of emails/messages about this -- how long does the review process generally take?

I don't believe there is a specific time frame, but that link goes to the virus labs and they analyse the site.  I guess it would depend on the workloads, but generally they are quite quick but not in the same day.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Site blocked for phishing
« Reply #4 on: September 28, 2019, 12:13:28 PM »
Consider: https://webcookies.org/cookies/streamyard.com/28452500
and on that there: Results from scanning URL: -https://cdnjs.cloudflare.com/12066138
Number of sources found: 1
Number of sinks found: 75

Results from scanning URL: -https://cdnjs.cloudflare.com/ajax/libs/pace/1.0.2/pace.min.js
Number of sources found: 3
Number of sinks found: 0

Results from scanning URL: -https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/2.3.1/js/bootstrap-dropdown.min.js
Number of sources found: 2
Number of sinks found: 0

Results from scanning URL: -https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/2.3.1/js/bootstrap-tooltip.min.js
Number of sources found: 6
Number of sinks found: 0

!! Results from scanning URL: -https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/2.3.1/js/bootstrap-tooltip.min.js
Number of sources found: 41
Number of sinks found: 17

Results from scanning URL: -https://cdnjs.cloudflare.com/ajax/libs/lodash.js/4.17.4/lodash.min.js
Number of sources found: 7
Number of sinks found: 2

Results from scanning URL: -https://cdnjs.cloudflare.com/ajax/libs/lodash.js/4.17.4/lodash.min.js
Number of sources found: 7
Number of sinks found: 2

!! Results from scanning URL: -https://cdnjs.cloudflare.com/ajax/libs/handlebars.js/1.3.0/handlebars.min.js
Number of sources found: 18
Number of sinks found: 5

Results from scanning URL: -https://cdnjs.cloudflare.com/ajax/libs/algoliasearch/3.24.4/algoliasearchLite.min.js
Number of sources found: 23
Number of sinks found: 3

!! Results from scanning URL: -https://cdnjs.cloudflare.com/ajax/libs/scrollprogress/2.1.2/scrollProgress.min.js
Number of sources found: 1
Number of sinks found: 75

Results from scanning URL: -https://cdn.statuspage.io/se-v2.js
Number of sources found: 1
Number of sinks found: 4
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!