SnitchSeeker.com

SnitchSeeker.com (https://www.snitchseeker.com/forum.php)
-   SnitchSeeker Site News (https://www.snitchseeker.com/snitchseeker-site-news/)
-   -   Resolved, clean and not an issue: Google Malware warning (https://www.snitchseeker.com/snitchseeker-site-news/resolved-clean-and-not-an-issue-google-malware-warning-86309/)

Dumbledore 11-14-2011 06:46 PM

Resolved, clean and not an issue: Google Malware warning
 
Many of our members have noticed Malware warnings when visiting our site lately.

Something like this:
http://i1098.photobucket.com/albums/...re-warning.png

Clicking the link to the diagnostics page would give you this:
Quote:

<p class="d"><strong>What is the current listing status for www.snitchseeker.com/gallery/albums?</strong></p><blockquote><p>This site is not currently listed as suspicious.</p><p>Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.</p></blockquote><p class="d"><strong>What happened when Google visited this site?</strong></p><blockquote>Of the 3 pages we tested on the site over the past 90 days, 1 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2011-11-12, and the last time suspicious content was found on this site was on 2011-11-10.<p>Malicious software includes 2 trojan(s).</p><p>Malicious software is hosted on 1 domain(s), including <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=q3s.ru/&client=googlechrome&hl=en-US">q3s.ru/</a>.</p><p>This site was hosted on 1 network(s) including <a href="/safebrowsing/diagnostic?site=AS:46475&client=googlechrome&hl=en-US">AS46475 (LIMESTONENETWORKS)</a>.</p></blockquote><p class="d"><strong>Has this site acted as an intermediary resulting in further distribution of malware?</strong></p><blockquote><p>Over the past 90 days, www.snitchseeker.com/gallery/albums did not appear to function as an intermediary for the infection of any sites.</p></blockquote><p class="d"><strong>Has this site hosted malware?</strong></p><blockquote><p>No, this site has not hosted malicious software over the past 90 days.</p></blockquote>
This warning showed up because Google added a new feature to protect people from malicious sites and to help make the web a safer place. They scan all files on websites around the web (including ours) and if they find any suspicious looking code, they put up that warning to anybody who attempts to view any page anywhere on the site, regardless of if the section was flagged or not. The entire site gets the warning once any file on any section is found to contain malicious code.

In our case, the malicious code was an invisible iframe which hackers had placed in unused index files in our gallery. REPEAT: The files containing the malicious code were in UNUSED pages in our gallery - pages not linked to from anywhere and which nobody can visit. So nobody was at any time in danger of getting infected. But Google plays it safe and flagged our site anyway, just in case.

I have found and manually removed all the infected files, and resubmitted our site for Google to check. Yesterday we got confirmation from Google that the malicious files indeed are removed and our site has returned to good standing and is no longer flagged.

See screen from our Google webmaster tools confirmation (screen taken 13 Nov 2011):<blockquote><blockquote>
http://i1098.photobucket.com/albums/...gle-status.png</blockquote></blockquote>

The days leading up to November 13th, the message was this:<blockquote><blockquote>
http://i1098.photobucket.com/albums/...-warning-1.png
</blockquote></blockquote>

I hope this explains everything clearly for all of you. Bottom line: Nobody was ever in any real danger of infection, and now ALL files on our server (even ones not accessed by site visitors) have been cleaned and all malicious tags have been removed. Google has confirmed this and has removed the warning.

I apologize for any worries or inconvenience this might have caused you. Thank you for keeping us on our toes! :)

Love from your faithful headmaster,
Richard Harris aka Dumbledore

Ladybug 11-14-2011 07:14 PM

I thought it was just my computer at first! I was confused because Google Chrome liked SS before so I put it down as my computer. Then when I heard other people were getting the same problem I began to get a little worried.

But I'm so glad it's been fixed! Thank You!

James_Potter 11-14-2011 08:48 PM

I'm glad it got fixed! I saw others talking about it and I hadn't seen it. But eventually my Google Chrome was telling me the same thing.

Thanks everyone!

Buggy-Boo 11-14-2011 09:05 PM

I never saw the message. But thanks for taking care of it :)

Connie 11-14-2011 09:06 PM

Thank you for your diligence and hard work to keep all us SnitchSeekers safe.

PadfootAndTheWolf 11-14-2011 09:35 PM

Thanks again Rich for all of your tech-awesomeness! :glomp:

hpluvr037 11-14-2011 09:54 PM

Thanks for figuring that out. You guys rock, SS staff!

laurange 11-15-2011 02:20 AM

Thanks for solving it! I thought it was just me...

YOU ROCK SS Staff!

Tommehbell 11-15-2011 03:03 AM

Glad it was nothing serious. I downloaded a virus and It was not fun! My computer died and it was so sad :cry:

So thank you for getting this fixed!

Ringo 11-15-2011 03:31 AM

Oh THANK YOU! I got real scared when it popped up and I couldn't get on for three days :lol: I thought I was gonna die without this amazing site! Yeah that's right, I'm addicted :lol:

kayquilz 11-15-2011 03:31 AM

I knew SS would never EVER get infected...I was so confused cuz I thought SS was so safe. I thought my computer was just being stupid! so yay!

pinkphoenix 11-15-2011 05:08 AM

Thanks for being so quick to take care of it. I was worried since it happened out of the blue and seemed really odd.

cheeseStrings 11-15-2011 06:46 AM

Yeah, I also didn't see the message, but thanks for repairing it!! :)

Slowfie 11-15-2011 11:14 AM

Ahh. I was too scared that something might happen to my laptop, so I was SS-less for like.. 3 days. Very boring. D:

RandomRaven 11-15-2011 11:32 AM

Thanks it was solved. But I wander why when I accessed SS with GC it have the warning, while I accessed SS with firefox didn't have the warning? [:/]

TeafortheSoul 11-15-2011 12:03 PM

Quote:

Originally Posted by alchemist_18 (Post 10765314)
Thanks it was solved. But I wander why when I accessed SS with GC it have the warning, while I accessed SS with firefox didn't have the warning? [:/]

That's simply because Google chrome has the Google diagnostics tool installed on the browser while other browsers do not. You can turn off Google Diagnostics if you go to the Under the Hood section of your Chrome browser. If 'Enable phishing and malware protection' is checked, then the Google Diagnostic tool will automatically check for malware hosted on a website, which is awesome because that is how we found out there was a problem in the first place.

TwistedHearts 11-15-2011 03:18 PM

Yeeey! Haha, I really thought something was up before. Great job, SS Staff especially the founder, Dumbledore. :D *thumbs up*

Deezerz 11-15-2011 05:25 PM

Woooot! This is a huge relief. Thanks for keeping this site safe!:glomp:

JustAlice 11-15-2011 07:38 PM

*flail*

bonnieginnyfan1 11-15-2011 08:32 PM

Thanks for fixing it! :D

Jessiqua 11-16-2011 12:12 AM

I was a bit confused by it! But I'm glad it's not there any more :D :D

mellamaet 11-16-2011 01:10 PM

Whew! Thank God! :lol: I wasn't able to visit the site because of that warning :xd: Thanks for fixing it :x3:

Starbreeze 11-16-2011 08:30 PM

So happy that's gone, thanks so much. :)

cake.ninjak 11-17-2011 11:04 AM

Rich, you're the best. Thanks for fixing this! :)

slytherus 11-17-2011 12:00 PM

I switched from GC to FF when I was in portable mode because of the warning. [:/]
Anyways, thanks for fixing that up. You're the best! :xd:


All times are GMT. The time now is 01:32 PM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.3.2 © 2009, Crawlability, Inc.
Site designed by Richard Harris Design


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255