As a software developer and web designer I recommends Avast since the beginnings. But now it blocks a website I am writing for a customer with a very nasty message that suggests that this website contains malware.
The website is located on my own Strato Server, everything is made by myself and there is definitely no malware on it. In fact it is a pretty simple website, no downloads, not links to other sites, just ordinary HTML with a little CSS. Also other websites of my own feather are hosted on the same server without any problem.
I have no idea why Avast do this? It is a thread for my small business!
But Avast Online Security kicks up an alert - web rep report and says the webpage could harm your computer.
Result
The address you entered is unnecessarily exposing the following response headers which divulge its choice of web platform:
Server: Apache/2.4.10 (Debian)
Configuring the application to not return unnecessary headers keeps this information silent and makes it significantly more difficult to identify the underlying frameworks.
@polonus
Thank you very much for your kind information. I have turned off the unnecessary header. This was very helpful.
I updated http://www.discovery-design.de to the latest version. This is our main website and reverse dns points to it for many websites. Also very good. Thank you!
We do not have any possibilities on the DNS server, for this is handled by our service provider Strato AG germany.
However the problem persists on any windows machine we could check. There are numerous. See screen copy for the current status with latest Avast update.
If it is true, that Avast did not block it. Who was it then who bring out this blocking window?
Strange that I tried to visit the Link to screenshot: given by Tania Hagn, only to have Firefox Block it. ‘Firefox has not connected to this website.’ The advanced view gives more details.
Finally for the external link to www.ejbca.org
For their certificate:
Please contact the Certificate Authority for further verification.
Warnings
BEAST
The BEAST attack is not mitigated on this server.
Well why was it blocked in IE and did firefox kick up a warning. Because of this DANG: https://shaaaaaaaaaaaaa.com/check/www.discovery-design.de This server’s certificate is not trusted - Signature algorithm SHA1withRSA WEAK
You have a TRUST issue and with that considered Qualys gives a poor T overall rating, else you would have reached B-Status.
As of January 1, 2016, no publicly trusted CA is allowed to issue a SHA-1 certificate. So any new certificate you get should automatically use a SHA-2 algorithm for its signature.
Handshake Simulation
Android 2.3.7 No SNI 2 Incorrect certificate because this client doesn’t support SNI
RSA 2048 (SHA1) | TLS 1.0 | TLS_RSA_WITH_AES_128_CBC_SHA
Handshake Simulation
Android 2.3.7 No SNI 2 Incorrect certificate because this client doesn’t support SNI
IE 6 / XP No FS 1 No SNI 2 Server closed connection
IE 7 / Vista RSA 4096 (SHA1) TLS 1.0 TLS_RSA_WITH_AES_128_CBC_SHA No FS
IE 8 / XP No FS 1 No SNI 2 Incorrect certificate because this client doesn’t support SNI
RSA 2048 (SHA1) | TLS 1.0 | TLS_RSA_WITH_3DES_EDE_CBC_SHA
Java 6u45 No SNI 2 Incorrect certificate because this client doesn’t support SNI
Android 2.3.7 No SNI 2 Incorrect certificate because this client doesn’t support SNI
Java 6u45 No SNI 2 Incorrect certificate because this client doesn’t support SNI
Apple ATS 9 / iOS 9 R Client requires SHA2 certificate signatures
So you have a serious SSL Server Test Security Issue,
you may want to nullifi the -http://www.aabu.eu link as its giving me warnings on my streamfilter log just been linked in the forum 6 instances of the ip 85.214.102.33 giving me a “Service buffer reach the injection” warning. I never once clicked the link to goto the site yet its interacting with my avast.
Also privacy badger is telling me im getting cookies from -www.discovery-design.de which is also on the same IP as aabu.
Thank you, Lotan, for the heads-up on that one. The website owners certainly have some work to do on the security side of things.
Anyway they are privileged to get all this security information for free here, a sure benefit for website owners when they come to the forums and have their website analyzed for security issues via ‘cold’ reconnaissance third party scanning. We educate and inform and hopefully they will apply. ;D
Let’s see…
“The website is located on my own Strato Server” and “We do not have any possibilities on the DNS server”
Even on the cheap shared hosting that I use, I have options to set the DNS.
Time to get a more decent host I would say.
It is a thread for my small business!
As I see it you are the real thread.
A web-designer that is using obsolete code as well as vulnerable libraries on their own website is for sure not one I would hire to take care of my website.
If it is your server (I take it, it is a dedicated one), you are responsible for correct install and use of the certificate.
@DavidR: I am not talking about the SSL issue here, as stated before the SSL side is not yet implemented! I am talking about the Avast blocking here in the chrome browser (See my screenshot)!
In other browsers there is no block. Maybe there is a problem with the chrome browser that leads to problems in combination with avast. I would agree that this might be a bot, but then this bot is very widespread because the block occurs on many different computers in different locations and with different ownerships. In my opinion it would be very helpful to track down this issue also, because then this bot would be a very very widespread one and it is not discovered by Avast up to now.
@Eddy: Looks like you have not much more to offer than lamenting on the SSL thing and to insult me. No need of this. As I wrote before SSL is not implemented yet, it is the one selfsigned from the server. Further more I will forward your critics concerning the DNS to Strato AG, that you accuse to be a security risk and a bad provider
Well, I have stripped down the site a little. Here is the source code of my web site:
Ah, now it works. I have restored the original website, perfect.
Thank you very much for the fast and good help and please forgive me for beeing impatient. I have deep understanding that false positives may be occur in this field. Everything is fine now for this could be fixed so easily.
I will continue to recommend Avast to our customers. Take care!