Author Topic: url:phishing warning on my website  (Read 1793 times)

0 Members and 1 Guest are viewing this topic.

Offline john1693

  • Newbie
  • *
  • Posts: 1
url:phishing warning on my website
« on: February 05, 2020, 01:56:45 PM »
my website is being flagged by avast as url:phishing

https://redoceanblue.com/

I scanned it with Virus Total and it is clean https://www.virustotal.com/gui/url/05ae9d3096bb8d87cb6c51a6d910bb1f471073f5f7b0f527dc71ae38acea01c6/detection

I also scanned it with Securi as well https://sitecheck.sucuri.net/results/https/redoceanblue.com

How do I get the site cleared by Avast.

Thanks,
John

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: url:phishing warning on my website
« Reply #1 on: February 05, 2020, 02:02:21 PM »

Report a false positive (select file or website)
https://www.avast.com/false-positive-file-form.php
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: url:phishing warning on my website
« Reply #2 on: February 10, 2020, 11:54:59 AM »
Hi john1693,

Do not see it flagged any longer.
Still some issues to point out to: retirable libraries detected
Quote
Retire.js
bootstrap   3.3.7   Found in -https://redoceanblue.com/templates/shaper_educon/js/bootstrap.min.js
Vulnerability info:
High   28236 XSS in data-template, data-content and data-title properties of tooltip/popover CVE-2019-8331   
Medium   20184 XSS in data-target property of scrollspy CVE-2018-14041   
Medium   20184 XSS in collapse data-parent attribute CVE-2018-14040   
Medium   20184 XSS in data-container property of tooltip CVE-2018-14042   
jquery   1.12.4   Found in -https://redoceanblue.com/media/jui/js/jquery.min.js?ea1fe0f7e000d8a5e06e34094308a961
Vulnerability info:
Medium   2432 3rd party CORS request may execute CVE-2015-9251   
Medium   CVE-2015-9251 11974 parseHTML() executes scripts in event handlers   
Low   CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution
Vulners found:
Quote
content.js:15 [VULNERS] Match Bootstrap /js/bootstrap.min.js undefined
(anonymous) @ content.js:15
content.js:15 [VULNERS] Match Font Awesome <link href="/components/com_sppagebuilder/assets/css/font-awesome.min.css undefined
(anonymous) @ content.js:15
content.js:15 [VULNERS] Match animate.css <link href="/components/com_sppagebuilder/assets/css/animate.min.css undefined
(anonymous) @ content.js:15
content.js:15 [VULNERS] Match cpe:/a:jquery:jquery jquery.min.js undefined
(anonymous) @ content.js:15
content.js:15 [VULNERS] Match jQuery Migrate jquery-migrate.min.js undefined

25% of Google tracking may be blocked by script blockers.

4 validation errors found using Avast Safe Browser console:
Quote
VM74:1 line 25:  The “type” attribute for the “style” element is not needed and should be omitted.
eval @ VM74:1
VM74:1 line 26: CSS: “padding-top”: only “0” can be a “unit”. You must put a unit after your number.
eval @ VM74:1
VM74:1 line 26: CSS: “padding-right”: only “0” can be a “unit”. You must put a unit after your number.
eval @ VM74:1
VM74:1 line 26: CSS: “padding-bottom”: only “0” can be a “unit”. You must put a unit after your number.
eval @ VM74:1
VM74:1 line 26: CSS: “padding-left”: only “0” can be a “unit”. You must put a unit after your number.

Consider compliancy test results here: https://www.immuniweb.com/websec/?id=4l8wWZOu

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)

« Last Edit: February 10, 2020, 06:30:13 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6677
  • volunteer
Re: url:phishing warning on my website
« Reply #3 on: February 13, 2020, 03:34:51 AM »
Detection was removed in 11.02.2020

Quote from: Avast
Our virus specialists have been working on this problem and it has now been resolved. The provided website isn't detected by Avast anymore.