Author Topic: How to remove website from Avast blocklist ?  (Read 25017 times)

0 Members and 1 Guest are viewing this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88786
  • No support PMs thanks
Re: How to remove website from Avast blocklist ?
« Reply #15 on: October 14, 2015, 07:33:36 PM »
Please unblock www.telos.de and www.telos.info

There are no harmful things there. We have testet it with a bunch of software packages.

Thank you

Avast sees that there is something else loading with the page the /|>{gzip} bit at the end of the URL in my attached image. The same alert is occurring at both links that you gave.

Having seen this type of alert before, the indication is that it is loading a compressed script file. Is there anything like that loading intentionally at your site ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.1.6099 (build 24.1.8821.762) UI 1.0.796/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33873
  • malware fighter
Re: How to remove website from Avast blocklist ?
« Reply #16 on: October 15, 2015, 12:44:26 AM »
Address is could be redirecting to banner malcode?
Issues with telos dot de.
OpenSSH 5.5p1 Debian 6+squeeze7 (protocol 2.0) PHP/5.3.3-7+squeeze1
PHP vulnerable to arbitrary PHP code execution.
Site risk status 1 red out of 10: http://toolbar.netcraft.com/site_report?url=http://satellit.telos.de
For wxw.telos.de -> Overview
Cookies not flagged as "HttpOnly" may be read by client side script and are at risk of being interpreted by a cross site scripting (XSS) attack. Whilst there are times where a cookie set by the server may be legitimately read by client script, most times the "HttpOnly" flag is missing it is due to oversight rather than by design.

Result
It looks like 2 cookies are being set without the "HttpOnly" flag being set (name : value):

PHPSESSID : mk16r3l8l278mpqh8oc7uhjul0
nf_wp_session : 69eb2731a4e2578d600b0d0f57a9bb46%7C%7C1444863977%7C%7C1444863917

This is what is flagged: Requested URL: -http://www.telos.de/ | Response URL: -http://www.telos.de/ | Page title: telos Systementwicklung GmbH | telos | HTTP status code: 200 (OK) | Response size: 31,367 bytes (gzip'd) | Duration: 1,625 ms  Clickjacking...

polonus
« Last Edit: October 15, 2015, 12:47:47 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: How to remove website from Avast blocklist ?
« Reply #17 on: October 15, 2015, 12:14:37 PM »
Hi,
Avast was complaining about including link to zero-creatives.de, which we blocked since February 2012. I am now unblocking zero-creatives.de, so you should not see any warnings on telos.de or telos.info domains.
Thanks for reporting!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88786
  • No support PMs thanks
Re: How to remove website from Avast blocklist ?
« Reply #18 on: October 15, 2015, 04:42:21 PM »
Confirmed no alerts on those domains now.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.1.6099 (build 24.1.8821.762) UI 1.0.796/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

REDACTED

  • Guest
Re: How to remove website from Avast blocklist ?
« Reply #19 on: December 09, 2015, 06:38:44 PM »
Dear Avast,

It seems one of our website is blocked by mistake from Avast Antivirus.
The website url is http://kidsingreece.com.
Some Avast users reported that http://merinannies.com is blacklisted as well, but my latest version of avast antivirus marks it as safe.

Please remove them both from your blacklists.

Thank you in advance.

Best regards,
Yannis

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37478
  • Not a avast user


REDACTED

  • Guest
Re: How to remove website from Avast blocklist ?
« Reply #22 on: December 09, 2015, 07:27:05 PM »
IP history   https://www.virustotal.com/en/ip-address/85.25.207.150/information/

IP history   https://www.virustotal.com/en/ip-address/104.28.25.36/information/


scroll down to support ticket and report it   https://support.avast.com/support/home


We reanalyzed the kidsingreece.com website in virustotal. It says its absolutely safe. You can see the results, here:
https://www.virustotal.com/en/url/3e6d387821a2fc7a86e78f1a537e74a160b902552290f62183a69143a618a90e/analysis/1449685491/

The other website runs through cloudflare, and its ip is from cloudlfare.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33873
  • malware fighter
Re: How to remove website from Avast blocklist ?
« Reply #23 on: December 09, 2015, 07:44:23 PM »
Your website may not have actual malware being spread, there are insecurities like jQuery libraries that should be retired asap:
-http://kidsingreece.com
Detected libraries:
swfobject - 2.2 : -http://kidsingreece.com/components/com_imageshow/assets/js/swfobject.js
jquery - 1.4.2 : (active1) -http://kidsingreece.com/templates/gk_the_real_design/js/jquery-1.4.2.min.js
Info: Severity: medium
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4969
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
jquery - 1.7.2 : -http://kidsingreece.com/templates/gk_the_real_design/js/jquery.min.js
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
jquery-ui-dialog - 1.8.23 : -http://kidsingreece.com/templates/gk_the_real_design/js/jquery-ui.min.js
Info: Severity: medium
http://bugs.jqueryui.com/ticket/6016
jquery-ui-autocomplete - 1.8.23 : http://kidsingreece.com/templates/gk_the_real_design/js/jquery-ui.min.js
jquery-ui-dialog - 1.8.4 : http://kidsingreece.com/templates/gk_the_real_design/js/jquery-ui-1.8.4.custom.min.js
jquery-ui-autocomplete - 1.8.4 : http://kidsingreece.com/templates/gk_the_real_design/js/jquery-ui-1.8.4.custom.min.js
(active) - the library was also found to be active by running code
3 vulnerable libraries detected

Check SPF record
WARNING: Domain doesn't have SPF record. SPF (Sender Policy Framework) record is designed to prevent e-mail SPAM. Typical SPF record would be:
v=spf1 a mx ~all or v=spf1 a mx include:_spf.google.com ~all if you are using Google Apps.

When website is blocked, it is because it shares the same IP with malware spreading domains on that IP: https://www.virustotal.com/nl/ip-address/85.25.207.150/information/
This is the morst likely scenario. Ask for an exclusion via https://www.avast.com/nl-nl/contact-form.php
Remember unblocking can only be performed by an Avast Team Member, and we here are not, we are just volunteers with relevant knowledge,

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: How to remove website from Avast blocklist ?
« Reply #24 on: December 09, 2015, 08:07:35 PM »
I unblocked kidsingreece.com now ;)
merinannies.com does not seem to be blocked now.

REDACTED

  • Guest
Re: How to remove website from Avast blocklist ?
« Reply #25 on: December 10, 2015, 03:48:50 PM »
Frist of all, I want to thank you all for volunteeringly  helping in the issue.
We made an extented search and we are facing also the same problem for the following domains:

1) medical-shop.gr
2) kakaounakis.gr
3) chamonix-nannies.com
4) courchevelnannies.com
5) courchevelnannies.com
6) chamonix-nannies.com

4 of them, are practicaly the same website.
Can you please unblock them as well?

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: How to remove website from Avast blocklist ?
« Reply #26 on: December 14, 2015, 11:00:29 AM »
Yup, I unblocked them just now ;)

REDACTED

  • Guest
Re: How to remove website from Avast blocklist ?
« Reply #27 on: December 14, 2015, 06:22:36 PM »
Brookvillebands.org

is being blocked. I've run several URL scans and all say it is clean. Any suggestions?

FYI, it is a Go Daddy site and they say it is clean.
« Last Edit: December 14, 2015, 06:27:05 PM by jjswope »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31081
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: How to remove website from Avast blocklist ?
« Reply #28 on: December 14, 2015, 06:36:20 PM »
Next time also do a IP check.

URL:MAL = IP is blacklisted

https://www.avast.com/contact-form.php?subject=VIRUS-FILE

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: How to remove website from Avast blocklist ?
« Reply #29 on: December 15, 2015, 07:38:43 AM »
@Eddy: URL:Mal means either blacklisted domain or IP (or both). There is no easy way of finding out (you can connect to the IP directly and see if it is blocked).

@jjswope: The domain was blocked due to suspicion to Angler exploit kit a month ago. I do not see anything malicious coming from it now, so I unblocked it ;)