Re: php.net - The Website Ahead Contains Malware

From: Date: Thu, 24 Oct 2013 11:16:28 +0000
Subject: Re: php.net - The Website Ahead Contains Malware
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-69837@lists.php.net to get a copy of this message
On 10/24/2013 1:04 AM, Konstantin Leboev wrote:
I have only this email to contact, but when I opened today php.net in Google Chrome I've got next message "The Website Ahead Contains Malware". Link for details: http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http%3A%2F%2Fphp.net%2F&client=googlechrome&hl=en-US
I've had experience with dealing with cleanup for this. It can take upwards of 48 hours for the site to be removed globally after the issue has been fixed. How you get onto the list in the first place is via Firefox's "Report Web Forgery..." option under the "Help" menu (Chrome might have a similar feature). Some idiot on the Internet chose to use that to report an issue on the PHP website instead of locating a contact. The issues go into a central clearinghouse for malware sites that, upon confirmation of the issue, immediately blocks access to the entire website, negatively affects Google search results, and offers limited options to website operators. Website operators are not warned or notified in advance of being blacklisted because the clearinghouse system apparently can't be bothered to look up WHOIS records for a domain and send a couple of e-mails. The clearinghouse website is also vague and difficult to navigate for the website operator who wants to be removed from the blacklist. Therefore, when I find malware on a host, I attempt to seek out a contact before using that Help menu option because I know how difficult it is to identify the actual issue and then get removed from the list. Usually I find a human contact and they reply in a timely fashion, are grateful for the notice, and work to quickly clean up the issue, which is a much better solution. https://www.stopbadware.org/clearinghouse/search?url=http://php.net/ Important note: Six to eight months from now the entire php.net domain will likely be declared to have malware again. However, at that time it will be from anti-virus vendors. Some of them grab outdated information (for some reason) from the clearinghouse database on an irregular basis and integrate it into their products. Getting removed from those requires hunting down buried contact information for each anti-virus product and again waiting up to 48 hours to be removed globally. -- Thomas Hruska CubicleSoft President I've got great, time saving software that you might find useful. http://cubiclesoft.com/

« previous php.internals (#69837) next »