3 ms·
I've been fighting with this for years, and I'm pretty sure Yandex is the problem. Hell, I even signed up for Yandex's webmaster tools as part of trying to fix
by c0nsumer 4y ago
I've been fighting with this for years, and I'm pretty sure Yandex is the problem. Hell, I even signed up for Yandex's webmaster tools as part of trying to fix this.
Years ago Yandex was flagging on some sample perl code that had a .txt extension (some something like udpscanner.pl.txt or so, IIRC) that I had sitting in a directory. There's no perl CGI, no way for it to execute on the server; just sample code. IIRC it was even served up as text/plain for easy reading in browsers. It was something that would be run directly on an OS, to do some fast scanning of open ports. For an end user to run it they would have to download it and get it executed by their perl interpreter. Definitely NOT an exploit in a browser.
As I recall it was something super basic that I found on a compromised server years ago and referenced in an old writeup.
For some reason it was flagged by Yandex as a browser exploit, they reported up to other places, and Malwarebytes flagged the whole site as malicious.
Since fighting the technical reasons why their scan is flawed is Sisyphus, I ended up just removing it from the site and getting Yandex to rescan. They now list the site as clean, but some old tools still say something untoward is going on.
It's frustrating.