Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 10-31-2018, 11:43
ZeNiX's Avatar
ZeNiX ZeNiX is offline
Administrator
 
Join Date: Feb 2009
Posts: 735
Rept. Given: 177
Rept. Rcvd 772 Times in 259 Posts
Thanks Given: 226
Thanks Rcvd at 910 Times in 247 Posts
ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899
Yes, this is an annoying problem.
Any suggestion?
Reply With Quote
The Following User Says Thank You to ZeNiX For This Useful Post:
Megin (11-03-2018)
  #2  
Old 10-31-2018, 12:47
TechLord TechLord is offline
Banned User
 
Join Date: Mar 2005
Location: 10 Steps Ahead of You
Posts: 759
Rept. Given: 384
Rept. Rcvd 247 Times in 112 Posts
Thanks Given: 789
Thanks Rcvd at 2,022 Times in 571 Posts
TechLord Reputation: 200-299 TechLord Reputation: 200-299 TechLord Reputation: 200-299
Quote:
Originally Posted by ZeNiX View Post
Yes, this is an annoying problem.
Any suggestion?
Any sites which either contain downloadable exploits (as attachments to posts or within the database) or provide links to downloadable exploits would be potentially flagged.

Earlier on (you can check if you don't believe me), there were no EXPLOITS or MALWARE per se or links to them seen in the forum.

When these links were permitted around 2 months ago, I guess the problem started.

Solution:
Ban malware or EXPLOITS (or links to the same) on this forum.
Reply With Quote
The Following User Says Thank You to TechLord For This Useful Post:
Megin (11-03-2018)
  #3  
Old 11-01-2018, 03:23
atom0s's Avatar
atom0s atom0s is offline
Family
 
Join Date: Jan 2015
Location: 127.0.0.1
Posts: 431
Rept. Given: 26
Rept. Rcvd 130 Times in 67 Posts
Thanks Given: 54
Thanks Rcvd at 837 Times in 306 Posts
atom0s Reputation: 100-199 atom0s Reputation: 100-199
Quote:
Originally Posted by ZeNiX View Post
Yes, this is an annoying problem.
Any suggestion?
Generally it happens from Google marking your site malicious due to a download that is available on it. Easiest way to get around it is to password any download that is publicly visible to their scrapper bot.

I had to do it for my personal sites a few times already as well to get rid of the blocks.

Afterward, once the files are passworded you can tell Google to rescan the site to fix the errors. (Once you claim the domain on Google's site tools, you can see the specific files causing the problems as well, they generally give you decent information about what's causing it.)
__________________
Personal Projects Site: https://atom0s.com
Reply With Quote
  #4  
Old 11-01-2018, 12:40
TechLord TechLord is offline
Banned User
 
Join Date: Mar 2005
Location: 10 Steps Ahead of You
Posts: 759
Rept. Given: 384
Rept. Rcvd 247 Times in 112 Posts
Thanks Given: 789
Thanks Rcvd at 2,022 Times in 571 Posts
TechLord Reputation: 200-299 TechLord Reputation: 200-299 TechLord Reputation: 200-299
Quote:
Originally Posted by atom0s View Post
Generally it happens from Google marking your site malicious due to a download that is available on it. Easiest way to get around it is to password any download that is publicly visible to their scrapper bot.

I had to do it for my personal sites a few times already as well to get rid of the blocks.

Afterward, once the files are passworded you can tell Google to rescan the site to fix the errors. (Once you claim the domain on Google's site tools, you can see the specific files causing the problems as well, they generally give you decent information about what's causing it.)
This worked for your site as yours does not have any "cracks" or other PUPs on it.
In other words whatever had been flagged on your site were all (I understand) false positives.

On this site unfortunately, it is.. Ermm... cough... Different.

If links to malware/cracks/exploits/cracks are allowed on the site, then there is no way to get around it other than to get them removed from your site, OR, remove them to hidden sections of the site not accessible to the web spiders.

Even then, if someone takes a sccreenshot of the hidden area and "reports" it, then once again, the site will be flagged.

The best way would be to ban links to malware, RATs and other such stuff in the forum.
These items in any case were not there for many years prior in this forum...
Reply With Quote
The Following User Says Thank You to TechLord For This Useful Post:
Megin (11-03-2018)
  #5  
Old 11-02-2018, 10:55
chants chants is offline
VIP
 
Join Date: Jul 2016
Posts: 826
Rept. Given: 47
Rept. Rcvd 50 Times in 31 Posts
Thanks Given: 737
Thanks Rcvd at 1,140 Times in 529 Posts
chants Reputation: 51
This problem has had a very old solution that was even used here in older times.

Removal of information has never been a solution for all of life's problems except maybe by authoritarians and ruling class thugs.

But we can simply post links using
Quote:
http:// www <dot> google <dot> com
or using other notations so that bots will not crawl them and mark them as such. This notation and style should be used for any links which are in those categories that could be marked as dangerous by services such as those VT lists.

As for the RATs in question, I have already edited the post to do just that so that baseless accusations that these particular links are the ones which caused the flagging can be thrown in the wastebasket.

Perhaps it is another post with another link containing a crack, etc. No one knows for sure. But this recommendation provides a forum with full expression, information sharing and gives an extra indicator when caution should be exercised (which is pretty much always in a reverse engineer's context).
Reply With Quote
The Following User Says Thank You to chants For This Useful Post:
p4r4d0x (11-03-2018)
  #6  
Old 11-03-2018, 02:07
atom0s's Avatar
atom0s atom0s is offline
Family
 
Join Date: Jan 2015
Location: 127.0.0.1
Posts: 431
Rept. Given: 26
Rept. Rcvd 130 Times in 67 Posts
Thanks Given: 54
Thanks Rcvd at 837 Times in 306 Posts
atom0s Reputation: 100-199 atom0s Reputation: 100-199
Quote:
Originally Posted by TechLord View Post
This worked for your site as yours does not have any "cracks" or other PUPs on it.
In other words whatever had been flagged on your site were all (I understand) false positives.

On this site unfortunately, it is.. Ermm... cough... Different.
It's not any different. Googles tools do not attempt to open passworded archives. You can zip anything up and password it and it's automatically deemed safe to Google. You can also block their bot from accessing those parts of the site entirely with the robots.txt and that'll also fix the issues.

Please don't assume shit you don't know about. I've dealt with this on multiple sites, not just one public facing site you know about.
__________________
Personal Projects Site: https://atom0s.com
Reply With Quote
The Following User Says Thank You to atom0s For This Useful Post:
chants (11-03-2018)
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Site down? nikre General Discussion 32 03-14-2026 15:41
Unwanted code added while assembling on Olly RaptorX General Discussion 3 02-18-2011 03:49


All times are GMT +8. The time now is 02:28.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )