9 ms·
Google flagged our site as malware on our prelaunch announcement day
- level09 13y agoHappened to me as well, developed a website for a client and they started to get that malware warning on a specific page. there was absolutely nothing special about that page except the content, I noticed that the content included words like "Visa, passport, license etc .." so Google classified it as a probable scam. after a few submissions, I think the page got whitelisted. its very annoying indeed, especially that this functionality is now built into the primary browser.
- softmodeling 13y agoAnd if you still see the malware warning yet, well, join me in our appreaciation to Google efforts for protecting internet users against very evil business like mine :-( (I guess they think they only ones that follow the "Don't be evil" motto)
- ddalex 13y agoI can't be the only one here that think Google has way too much power for anyone's good. This being said, I have no idea what could be done, if anything, to avoid being in a situation where Google can, mistakenly, blacklist your from the Internet. This is why I stopped using Chrome, and learned to love Firefox, again.
- softmodeling 13y agoI'm ashamed to confess that when I saw this, I wished the world was full of Internet Explorer users :-)
- derefr 13y agoWe could require that Google, Microsoft, Mozilla et al use only third-party open blacklists (and contribute to those projects with their blacklist data if they feel they know more than the project does, but where the project has final say in what does or doesn't go in.) This decouples the incentive structure.
- tytso 13y agoMy experience is that third party blacklists (especially for e-mail spam) have a much worse false positive problem. As I said in another comment, economics is working against you. There is relatively little or no cost to a blacklist provider if there is a false positive. And there are a lot of people who care very much about spam, or malware, who put a lot of pressure on blacklist providers to be as comprehensive and to react as quickly as positive. Heck, if you are looking at this from a larger social good perspective, it might even be better for society at large to have the blacklist provider be much more aggressive about blacklisting sites quickly. What's the cost of a malware compromising someone's machine, and requiring someone to take their desktop off-line for a day or more while they reinstall everything from scratch (and find out that they no longer can find their MS Office reinstall disks, and the new MS Office requires them to relearn where all controls are on the reorganized toolbar)? Versus the economic cost of some minor web site getting blocked for a few days? In any case, given that you as the minor web site won't be providing any payments to the blacklist provider, why do you assume the incentive structure will be any better with third-party blacklists?
- derefr 13y agoI think the interesting thing about decoupling the incentive structure isn't so much how the blacklist operator would react (more liberal blacklists), but how the browser maker would react. Since the browser maker will no longer control the blacklist, they will now have users telling them that sites are broken (because they've been blacklisted), and they won't be able to do anything about it on the blacklist side. So, what they will be incentivized to do, is to make whitelisting a blacklisted site (especially those that only get loaded through invisible iframes etc.) have a much simpler/easier/clearer UX, so that their complaints go down. This is good for everyone, but it's not something they'll do when they still have the option "just remove X from the blacklist."
- tytso 13y agoBut the sites aren't really _broken_. There will be a warning displayed to the user, but the user can always say, "give me the site anyway". And users do hate it when they hit a web site which trashes their machine with malware. So they might be in favor of more stringent blacklists as well. It might be a bad assumption that users will demand a more liberal blacklist. That's certainly not how e-mail blacklists have worked out. Sometimes the people most in favor of the blacklists that hit all sorts of innocent mail senders are the users sick and tired of spam.
- magicalist 13y ago> This is why I stopped using Chrome, and learned to love Firefox, again Firefox uses Google for safe browsing filtering.
- taopao 13y agoThe author acknowledged ITT that the site probably did serve malware. The right thing was done IMO. Wouldn't it be worse if the OP was blamed for infecting his users? "Probably both sites were infected at some point. Again, I never saw the malware message myself but the guy that alerted us first copied the message he got and it was explicitly mentioning the demo site: “Content from demos.shapingrain.com, a known malware distributor, has been inserted into this web page. Visiting this page now is very likely to infect your Mac with malware.”"
- ashray 13y agoI feel like I should share a story here. The fight against spam is becoming a serious problem for legitimate businesses. I've suffered from the same malware issue earlier. Since we use ad networks for advertising it works as follows. 1 ad network has about 3000 different ads running in different locations. If any of those domains get compromised and blacklisted and Google notices that you served something from that domain - BOOM! You're on stopbadware.org and need to get your website reviewed. You block the ad, and apply for a review. To their credit, it takes about 24 hours for the whole process (review happens, they delist you, Google caches update, etc.). However, for 24 hours anyone who comes to your site or clicks on a google result for you, or clicks anywhere to come to you - Gets a massive warning. The cost in terms of lost revenue and reputation damage are almost incalculable. This has happened to me in the past, several times. I have severed relationships with several ad networks and yet this keeps happening - even with the most reputable networks and you try to stay ahead of the curve but if you fall behind even a bit, you may get blacklisted again. All this for a site that makes maybe $200/month. Another problem I faced was with SURBL. It's a spam blacklist that works on a bizarre system. Basically if they find your domain name beind spammed around the internet (it could be anyone else doing it) they will blacklist you. What's worse is that providers like bitly, facebook, etc. use the SURBL blacklist. So what happens ? Well, one day someone goes and spams your domain on internet forums, etc. SURBL picks up on it. Then, suddenly all your facebook links, bitly links shared on twitter, etc. start showing warning pages. Basically someone clicks on your link on facebook and gets a page saying "This site may harm your computer". Ditto for Bitly as well. I tried to get delisted but no one at SURBL would respond. I kept trying to get in touch through their online form but no one responded for 2-3 weeks. Finally, I did a whois on the domain, found the admin contact and emailed him. I also sent him a text on his phone. At last after about 4 weeks of being on SURBL I managed to get delisted. That. Was. An. Ordeal. This in my opinion is absolutely unacceptable. Spam blacklists do have a responsibility to be correct in their assessments. And if they do have a false positive for any reason, they should have a streamlined resolution process. Unfortunately, the internet is the wild west and shooting before asking questions appears to be quite acceptable in these parts. I recognize that a lot of this is an attempt to protect users but when I open my mom's PC, I still see a bunch of browser toolbars, bookmarking widgets, etc. etc. (malware, right ?) Folks are still getting phished. This fight needs to be rethought.
- AliEzer 13y agoThe domain name looks like that of a spam website. You should avoid hyphens when possible.
- softmodeling 13y agoA slightly related problem is that we cannot use WordPress as part of the domain name which would probably make easier to distinguish ourselves (and all other WordPress related products) from other kinds of sites
- swatkat 13y agoAlso (slightly OT): * Link to homepage is on the right-side!? * Somehow, content text feels too thin/dull. Little bit difficult to read :)
- softmodeling 13y agoThanks for the input. We´ll look into it (the link to the homepage is just because the menu starts from the right and now there is only one menu item)
- deleted 13y ago[deleted]
- fphhotchips 13y agoIs it possible that false positives like this open Google to defamation lawsuits? They're making an assertion that is false (and that their webmaster tools show they know to be false), and broadcasting that in a way that definitely has a financial impact on the businesses involved.
- softmodeling 13y agoGood point. I don't have the knowledge to answer this but what is true beyond any doubt is that a false statement like this causes financial damage to the site
- adventured 13y agoYes. The very hard part is the actual legal battle.
- JohnTHaller 13y agoThe domain that was blacklisted was not demos.shapingrain.com (I checked), shapingrain.com itself was blacklisted as you can see from the Google Safe Browsing report here: http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=shapingrain.com http://safebrowsing.clients.google.com/safebrowsing/diagnost... The theme currently in use on http://wp-abtesting.com/ http://wp-abtesting.com/ has a main stylesheet called style.css which contains the URL http://www.shapingrain.com http://www.shapingrain.com in its comments in the header. It looks like shapingrain.com itself was infected on 2013-08-19 but cleaned by 2013-08-20. It was likely infected with a JavaScript injection vulnerability linking to the site lartedio.com which served the actual payload (likely something trying to self-install, break out of the box, etc.). After shapingrain.com was infected and flagged by Google Safe Browsing, wp-abtesting.com would then have been flagged when Google analyzed the CSS file and saw what appeared to be a resource link to an infected site. This would appear to be a limitation via the scanner which is scanning CSS comments and treating them as valid code, though this is not without precedent and certain browsers will evaluate what is contained in comments under certain circumstances (see IE conditional comments). So, in the end, it looks like shapingrain.com was infected yesterday and Google blacklisted that site as well as any sites pulling resources from the infected site, erring on the side of caution (possibly) and interpreting URLs within comments in CSS as possible resource links.
- softmodeling 13y agoHi John, Thanks a lot for your detailed response. Really appreciated. Probably both sites were infected at some point. Again, I never saw the malware message myself but the guy that alerted us first copied the message he got and it was explicitly mentioning the demo site: “Content from demos.shapingrain.com, a known malware distributor, has been inserted into this web page. Visiting this page now is very likely to infect your Mac with malware.” And now, we’re going to immediately clean the CSS since this is something that had not occurred to us could be the cause of the problem. Let’s make sure we are not blacklisted again!
- JohnTHaller 13y agoSure thing. I've had some experience with the blacklist detection due to a JS file hosted on a trusted 3rd party site that had another section of their site hacked (meaning their site was blacklisted and anything pulling resources from their site was similarly blacklisted). I researched more about how things worked then and have been sharing when I can since then. I hadn't seen your specific situation before but it is my guess based on an understanding of how similar scanning setups work. For future reference, another useful tool is Sucuri SiteCheck, which will show you the results of multiple website malware blacklists on one page: http://sitecheck.sucuri.net/scanner/ http://sitecheck.sucuri.net/scanner/ (I checked and http://wp-abtesting.com/ http://wp-abtesting.com/ is clean)
- thehme 13y agoI think the situation is unfortunate because of their new launch, but the real problem is, as the author mentioned it, that Google webmaster tools did not alert them of the problem, so they were not able to address it on time. I also think their vendor should have alerted them (their clients) about Google flagging them and that perhaps this should be considered immediately, which would have saved them some headaches. Therefore, if the two previous problems has been taken care of, then I think we would mostly all agree it is good to be alerted of potential malware, which noone wants on their machines.
- yeldarb 13y agoWe had the same thing happen to us yesterday (our launch day) by Facebook. We launched our application, announced it to the world, got a flood of users that was apparently "abnormal" and were flagged by their ban bot. Our app was summarily deleted (without warning or notification). All links to the application were flagged as "abusive". And all data published by users of our application was deleted. The only reason we discovered this was because we were alerted by our users that the application had disappeared from their bookmarks and that they were unable to access it. Of course, when we brought this to Facebook's attention they restored the application within a couple of hours. Unfortunately, significant damage had already been done: everything published by our users was (apparently) permanently deleted, our open graph stories and actions were completely deleted, and our subscriptions to the payments apis were deleted. The particularly insidious one is the deletion of the payments subscription. For the last 12 hours, anyone who has tried to make an in-app purchase has been charged by Facebook but not had their purchase relayed to us for fulfillment.
- softmodeling 13y agoReading your experience I think I should be happy about what happened to us today. Could have been much worse :-)
- abbott 13y agoWhen I saw the headline, I immediately thought, "they must be using WordPress". WP is a giant exploitable target, and I've personally told Matt this. Automattic saw an opportunity long ago and started VaultPress for WP security. He argued it's not a WP problem, and I frankly disagree, but he obviously understands the situation better than anyone. WP is free, but security is not because self hosted WP is so exploitable. A launch for a client also went through the same problem in 2010, and that was after 5 years of managing other WP installs (including 2 VIP WP sites). I've seen it happen too many times for it not to be Automattic's problem to address more so than they're doing now. Stay away from self hosted WP unless your install is absolutely bullet proof, and cross linking, especially to resource files from other WP sites is the last thing you should ever do because you do not control their security which can directly affect yours, or at least your black list vulnerability due to associated content. Our office used to be above Automattic's in SF, and I love those guys, and what Matt has done for the web, but with great power comes with great responsibility.
- RobGR 13y agoI'm a great promoter of Drupal, including in those cases where it competes with WordPress. However in all honesty I can't really play the security card against WP. I think WP itself meets generally accepted security standards; the 3d party code loaded into it sometimes does not, but that's the same case with any framework that allows modules. WP probably gets a bit of a bad rap because the types of sites made with it often don't have the budget to bring high quality development. When you serve 20% of the web, and people choose you precisely because they can get cheap developers, there will be some problem sites out there running WP. In this particular case, it seems to me that they would have been flagged if they had been running anything, Drupal or Jekyll or a static site - they had an external theme provider who referred to a domain in CSS comments that was listed by google. The problem seems to be the accuracy of Google's flagging, not WordPress.