Hello,
I hope this is the right forum to post about a possible false positive.
Since few days, my company website trucchislotmachine.com has been blocked by avast, it says URL:MAL
I have analyzed the website and the server and I don’t see any problem with it. Could you please check if it’s a false positive? I already sent a request through the contact form but I didn’t receive any reply.
Flagged here: https://www.virustotal.com/nl/domain/trucchislotmachine.com/information/
Potentially Suspicious files:
Detected unconditional redirection to external web resource in 17 instances.
[[]]
[[]] etc. etc.
Web application version:
Joomla Version 2.5.20 for: htxp://trucchislotmachine.com/media/media/js/mediamanager.js
Joomla Version 2.5.20 for: htxp://trucchislotmachine.com/language/en-GB/en-GB.ini
Joomla version outdated: Upgrade required.
Outdated Joomla Found: Joomla under 2.5.26 or 3.3.5
Outdated Web Server Apache Found: Apache/2.2.15 (has been mitigated?)
Thank you for your support,
some issues are not real at all (e.g: meta HTTP-EQUIV=“REFRESH” which are affiliate redirects to 100% safe websites), I’m going to fix remaining ones and let you know.
I mean as general it isn’t an elegant solution, a 301 isn’t.
These test however were passed succesfully: http://mobilefriendlytest.website/index.php
Mind the advice there. The refresh gets carried through resolving in multiple alert boxes.
If there were a malicious Meta Tag it would not be visible for the public (visitors).
In that case the easiest and safest fix is to completely wipe your public server space and DB,
then reinstall from a known clean backup.
I’m a bit curious in knowing how avast decides wether blocking a site or not.
I requested to get out of siteadvisor blacklist, few minutes ago site was removed and now avast is not blocking trucchislotmachine.com anymore. So it just checks mcafee blacklist? COOL!
I’m glad I don’t use MS win…
The website - trucchislotmachine.com is still being blocked by Avast Webshield as with URL:Mal
One of these domains on the same IP can also be responsible for the blocking: http://sameid.net/ip → http://sameid.net/ip/188.121.50.243/
What should be done is that the server shouldn’t give out excessive server version info: Apache/2.2.15 (CentOS) to the world and attackers.
This could be easily mended by settings in the server configuration, so we get Apache period.
While even with CentOS 6.3 apache/2.2.15 (centos) is not vulnerabe to exploits, just turn off the Apache and PHP versions in the headers and miraculously you might get a clean bill of health…
Report to virus@avast.com and ask for an exclusion (refer to this thread here). They could consider that, I cannot as unblocking websites is only reserved for avast team members, I am just a volunteer here with relevant knowledge. Anyway you considerably improved your website security by reporting here. Stay secure with Avast!
Asyn,
I submitted a ticked some weeks ago, I received an automatic reply and nothing else.
Domain is still blocked, I don’t understand why.
Do you think this is fair? My website is losing about 40-50 customers per day, I’m losing lot of money and Avast is not taking care of this false positive.