Showing posts with label Security False Positive. Show all posts
Showing posts with label Security False Positive. Show all posts

Thursday, March 31, 2016

CloudFlare, Custom Domain Publishing, And HTTPS

A few blog owners, who publish blogs published to custom domains, are becoming impatient, waiting for Blogger Engineering to finish the Blogger upgrade to support HTTPS / SSL.
If I get a domain through Google Domains, will I be able to get HTTPS?
Unfortunately, no. HTTPS / SSL is simply not available, to blogs published to custom domains.

HTTPS is not available, for non BlogSpot published blogs.

Whether registered by eNom, GoDaddy, or Google Domains, it simply is not possible to publish a non BlogSpot URL as a supported custom domain, and make HTTPS / SSL available. CloudFlare, a supposed alternative, does not produce a supported custom domain.

A proxied CloudFlare domain looks like malicious redirection.

In some cases, a CloudFlare DNS "solution" tried by some blog owners, will look like dangerous / malicious redirection. Some blogs will show up as "Deceptive sites", aka "phishing".


Some blogs using CloudFlare, for custom domain publishing, will be classified as "Deceptive" sites.



Others will produce alarming warnings about malware.


"This blog is not hosted by Blogger and has not been checked for spam, viruses and other forms of malware."




Click on "Details".



Look at the warning.

Phishing sites pretend to be other websites to trick you.

And there is the typical Dig log, with a redirecting proxy service, like CloudFlare.

kireisubs.id. 300 IN A 104.27.133.198
www.kireisubs.id. 300 IN A 104.27.133.198

or

topmovies21.biz. 300 IN A 104.28.0.106
www.topmovies21.biz. 300 IN A 104.28.0.106

This is the basis for malware / phishing classification.

Any observed malware warning is generally a false positive - most custom domain published blogs do not contain malware. Even so, it's not likely that the "Deceptive site" classification will be easily corrected - or the malware warning interstitial display removed.

And this is one more blog owner, who must next be provided instruction to correct the DNS addresses.

Having corrected as instructed, DNS addresses will be asymmetrical, and righteous.

kireisubs.id. 86400 IN A 216.239.32.21
kireisubs.id. 86400 IN A 216.239.34.21
kireisubs.id. 86400 IN A 216.239.36.21
kireisubs.id. 86400 IN A 216.239.38.21
www.kireisubs.id. 86400 IN CNAME ghs.google.com.

With DNS corrected, Google shows "Not dangerous" - but the warning still displays.


"Not dangerous".




Note "CloudFlare" is still seen as the host.




You can report an error, to SafeBrowsing.



False classification now requires time consuming site review.

Use "Report Incorrect Phishing Warning", if you believe the site is safe.

Finally, get the site reviewed, from the Security Issues page in Security Console (Webmaster Tools) - Security Issues.

And while the blog remains offline, search reputation - and the owner - will suffer.



Some #Blogger blog owners want to provide blogs published to custom domains - and offer HTTPS connectivity. Since Blogger cannot provide custom domains with HTTPS right now, the blog owners are using CloudFlare, which provides an HTTPS proxy.

Unfortunately, a CloudFlare proxy looks like malicious redirection - and blogs using CloudFlare are being labeled as "Deceptive" sites.

https://productforums.google.com/forum/#!category-topic/blogger/ApuJ58a4-kg

https://productforums.google.com/forum/#!category-topic/blogger/-LoJCeX6DEA

https://productforums.google.com/forum/#!category-topic/blogger/DhAFOtJFoCw

Thursday, March 10, 2016

Please, Don't Try Guessing Your Account / Password!

We see too many problem reports, in Blogger Help Forum: Get Help with an Issue, about locked accounts and deleted blogs.

My Google account was suspended because of 'suspicious activities'. Last month, I realized that my two connected blogs, to that account, were also put offline!

Somebody else was unable to use the supplied account / blog recovery tools - and tried guessing what could not be remembered.

The first would be a blog owner, whose only mistake was having a Blogger account with a name similar to another account, owned by the second.

The second would be someone who could not remember her (his) account name / password, could not use account or password recovery, and who got well meaning advice.

Just do the best you can - try what may be your account name, and any passwords that you can remember!

One blog owner must suffer, because another cannot remember login details.

And owner #1 is suffering, because of owner #2. Owner #1 is now anxiously waiting for action by the security experts (with the blind queue of unknown length) to examine his blogs - and possibly, waiting while not knowing why.


Owner #1 may be seeing this - and not know why.



Password guessing may be necessary, in extreme cases - but it can cause misery - and owner #2 will never realise the pain caused to owner #1. Even if owner #2 recovers access to her / his blogs, innocent brute force attempts can cause account lock / blog security lock, to owner #1.

Protect yourself against the anguish, using Google 2-Step Verification.

The best way to protect against this sort of abuse is to use one or more Google Two Step Verification options. This will leave owner #2 seeing (for instance).

Insert your USB security key, and tap the lighted button.

And having no security key, owner #2 will simply have to try guessing a different account name. It may be an inconvenience (for owner #1), carrying a never used USB security key - but the one time it's needed (and available), it will make up for the inconvenience.



One #Blogger blog owner, unable to remember a necessary account name or password, may try guessing what cannot be remembered. Guessing an account name can leave one trying an account that somebody else owns - and can cause account lock and blog deletion for somebody who they will never know.

Tuesday, March 8, 2016

Train Security Products, And Keep Your Blog Clean

Everybody who uses a computer - and expects to use their computer for any amount of time - has one or more protective products on their computer.

Anybody who publishes a blog, with an audience that has any need for security, is going to receive occasional reports from would be readers.

I can't read your blog! My computer displays an "Unsafe website!" warning!

All computer security products, unfortunately, will occasionally generate false positives. Analysing false positive malware reports is as much a part of every security product, as identifying the actual malware.

If you publish a blog, you need to know how to handle reader malware alert reports.

Know online tools, for researching reported problems.

Google provides 2 websites, for analysis of blog / website malware alerts. Both Google SafeBrowsing, and VirusTotal, are Google products that can help to identify actual problems with blogs and websites.

Besides the two Google products above, I use 3 security analysis websites, which can identify specific security problems in blog / website code. Quttera Online Website Malware Scanner, and Sucuri SiteCheck, and Trend Micro SIte Safety Center, have been useful at various times, when a security problem is reported.

You may, from time to time, use all of these - and possibly others - in identifying and verifying a security problem with your blog, or with blogs and websites that you link. For best results, always specify the canonical blog URL, when requesting security analysis - and when sharing the blog, or individual posts.


Specify the canonical URL.




Not a country local domain.



Know what you need to do, to keep your blog healthy.

As a blog publisher, you will occasionally have 2 jobs to do, when receiving a malware alert report which references your blog.

  1. Verify / identify / remove any actual malicious content.
  2. Report false positives, to the protective service displaying a false positive.


Everybody who publishes a blog, with any reader audience, has seen this advice, or something similar, when surfing their blog.



Know how to keep your blog clean - and your reputation clean.

You have to use online malware analysis services, to identify any problem which you may have created, by installing the latest "gotta have this!" accessory on your blog. And, you have to report any false positive alert, to the owners of any security product, that falsely identifies your blog as a problem.

You do both, to support your readers. You do not want your readers computers hacked, through your inappropriately accessorising your blog - but at the same time,you want your readers to be able to read your blog.

  1. Keep your blog content clean.
  2. Keep your blog reputation clean.

Do both - or you may not have readers, to read your blog.



Any #Blogger blog owner needs to support the blog readers, by publishing a blog clean of any malware, and with a good reputation with the various security products that prevent malicious action by dangerous blogs and websites. Your readers need the ability to use their computers to read your blog - and they need their security to not falsely identify your blog as a problem.

Wednesday, January 11, 2012

Publishing Your Blogger Blog Post To FaceBook Fails, With Open Refusal By FaceBook

Late last year, Blogger blog owners seeking to publicise their blog posts using their FaceBook Wall, were denied that possibility, silently. That problem was recently resolved, though still in silence.

Recently, Blogger blog owners started reporting a new symptom of problems with FaceBook.
I try to share my blog address on FaceBook, and I receive this message
The content you're trying to share includes a link that's been blocked for being spammy or unsafe:
Now what do I do?
This symptom is most likely a problem which the individual blog owners will need to discuss, with FaceBook Support.

Each Internet service has the right, and the responsibility, to block and interfere with spammy or unsafe content, on its service - to protect the legitimate users of its service.

Blogger has been blocking and interfering with spammy and unsafe content for several years - not always well received, but they are doing their best. FaceBook has the same right, and the same responsibility.

This problem appears to involve blog posts that contain pictures hosted on "2.bp.blogspot.com". I'll note that I posted, yesterday, a FaceBook Wall post referencing a Blogger blog post which contains a picture hosted on "4.bp.blogspot.com", with no problem. You can find my test post on my Wall - but you'll have to hunt for it on my FaceBook Wall, since I have not yet learned the technique to extracting and sharing, FaceBook Wall posts, outside FaceBook.

If you, a Blogger blog owner, believe that this is an unjust decision, you need to complain to FaceBook Support. FaceBook Support issues, like Blogger Support issues, are best solved with collaboration. You, and millions of other Blogger blog owners, seeking to publicise your blogs on your FaceBook Wall, can change this recent decision by FaceBook - if and only if everybody affected complains.

But you must complain to FaceBook Support. Not Blogger Support.

>> Top

Navigate» Become author for this Blog