Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FALSE-POSITIVE] #952

Closed
Imanolmanu opened this issue Dec 20, 2024 · 19 comments
Closed

[FALSE-POSITIVE] #952

Imanolmanu opened this issue Dec 20, 2024 · 19 comments
Assignees
Labels
false positive Should not be listed WIP

Comments

@Imanolmanu
Copy link

My site is www.lurvirun.com
I have scanned and cleaned the site thoroughly, and added anti-malware plugins.
Please delist from the phising.database blacklist.
Thanks,

@Imanolmanu Imanolmanu added the false positive Should not be listed label Dec 20, 2024
@Imanolmanu
Copy link
Author

www.lurvirun.com appears in total virus in Phishing Database as positive (phishing). It has been fully scanned and cleaned. Please remove it from the list, it is a false positive.

@Imanolmanu
Copy link
Author

Captura de pantalla (278)

Captura de pantalla (277)

@g0d33p3rsec
Copy link

The last indication I have of malicious activity was on April 8th 2023. https://urlscan.io/result/2f9e2b7a-b5be-4412-a9d9-4668dce4177f/

I have scanned and cleaned the site thoroughly, and added anti-malware plugins.

This does appear to be the case. I am not seeing any other indications of more recent activity.
https://urlscan.io/result/2f9e2b7a-b5be-4412-a9d9-4668dce4177f/

@spirillen
Copy link
Contributor

What does urlscan say to these url from the DB? can't test as they are trying to force me to use google spyware (capcha PII cacher)

https://www.lurvirun.com/cache/html/lbosta/web
https://www.lurvirun.com/cache/html/lbosta/web/7tmruut193fhll54b1wvnlclhc248e/login.php?login_id=
https://www.lurvirun.com/cache/html/lbosta/web/8zxxtnma76xdcx2rwhi43wz5oz66ua
https://www.lurvirun.com/cache/html/lbosta/web/8zxxtnma76xdcx2rwhi43wz5oz66ua/login.php?login_id=
https://www.lurvirun.com/cache/html/lbosta/web/iux74cmz2zvn0v0lk8ltbshutwmmh0
https://www.lurvirun.com/cache/html/lbosta/web/iux74cmz2zvn0v0lk8ltbshutwmmh0/login.php?login_id=
https://www.lurvirun.com/cache/html/lbosta/web/nn0etw4x349attur7ebem22bd9h04l
https://www.lurvirun.com/cache/html/lbosta/web/nn0etw4x349attur7ebem22bd9h04l/login.php?login_id=
https://www.lurvirun.com/cache/html/lbosta/web/zc9wt6urfnet3e19k81ockavb3iw9k
https://www.lurvirun.com/cache/html/lbosta/web/zc9wt6urfnet3e19k81ockavb3iw9k/login.php?login_id=
https://www.lurvirun.com/templates/web/lurvirun/fonts/serallo/web/f6529r24vhweukibxflrdvrfkk4cle/login.php?login_id=

@g0d33p3rsec
Copy link

What does urlscan say to these url from the DB? can't test as they are trying to force me to use google spyware (capcha PII cacher)

all return 500s

@spirillen
Copy link
Contributor

What does urlscan say to these url from the DB? can't test as they are trying to force me to use google spyware (capcha PII cacher)

all return 500s

Hat the same here... but a 500 makes me suspicious... I would expect 404 or 410

@Imanolmanu
Copy link
Author

Captura de pantalla (284)
Captura de pantalla (282)
Captura de pantalla (283)

@Imanolmanu
Copy link
Author

The website was cleaned and is correct.
Anti malware and anti phishing were installed.
Please remove it from the list, it is a false positive.

@Imanolmanu
Copy link
Author

The error was in 2023 and that is why we changed the server. Now it is totally clean.

@spirillen
Copy link
Contributor

The error persist. HTTP code 500 means the server is trying ti respond to the request, but some internal coding prevent it from succeed, So we need to see some HTTP code 4xx before moving on

curl -IL https://www.lurvirun.com/cache/html/lbosta/web/7tmruut193fhll54b1wvnlclhc248e/login.php?login_id=
HTTP/2 500 
server: nginx
date: Fri, 27 Dec 2024 14:08:43 GMT
content-type: text/html; charset=iso-8859-1
strict-transport-security: max-age=31536000;

@g0d33p3rsec
Copy link

image

The website was cleaned and is correct.
Anti malware and anti phishing were installed.
Please remove it from the list, it is a false positive.

I believe you but our scripts are looking for particular codes. See https://github.com/Phishing-Database/Phishing.Database/blob/master/README.md

https://serverfault.com/questions/399973/nginx-500-error-instead-of-404 may help

Automated Testing

The testing of the domains and URLs is automated using the awesome PyFunceble Testing Suite written by Nissar Chababy (AKA @funilrys). Over many years in development, this tool has become a robust and reliable source of domain and URL status. We use it in an automated environment which actively retests domains and URLs on a regular basis.
Who do we define an active status?

We define an active status as a domain or URL that is currently active and serving phishing content. The status is determined by the HTTP status code returned by the server.
Active Status Codes

 100, 101, 200, 201, 202, 203, 204, 205, 206

Potentially Active Status Codes

 000, 300, 301, 302, 303, 304, 305, 307, 403, 405, 406, 407, 408, 411, 413, 417, 500, 501, 502, 503, 504, 505

Any of the status codes above are considered active until further investigation.
Potentially Inactive Status Codes

 400, 402, 403, 404, 409, 410, 412, 414, 415, 416

@g0d33p3rsec g0d33p3rsec added the WIP label Jan 4, 2025
@spirillen spirillen moved this from 📋 Backlog to 🚫 Blocked / Waiting in Phishing Database Backlog Jan 4, 2025
@Imanolmanu
Copy link
Author

Hello,
I have spoken with the creators and maintenance of the lurvirun.com website and they have told me that everything is fine. What does that matter because it doesn't exist. Please remove me from the list or tell me what to do so I don't appear. The server is totally clean and protected.

@spirillen
Copy link
Contributor

answered in #952 (comment) && #952 (comment)

if you don't understand what we are trying to tell you, please say that.

@Imanolmanu
Copy link
Author

Hi, yes, I don't understand it, please could you give me details so I can give it to the server? Thanks

@spirillen
Copy link
Contributor

Hi there,

Thank you for bringing this issue to our attention. After investigating the matter, we have determined that the homepage is currently returning an HTTP status code in the 5xx range for a URL that you claim does not exist.

To clarify, a 5xx error indicates that there is a problem with the server hosting the website, while a 4xx error indicates that there is a problem with the client's request. In this case, since the URL in question does not exist, we would expect the homepage to return a 4xx error, such as a 404 (Not Found) or a 410 (Gone), rather than a 5xx error.

Returning a 4xx error for nonexistent URLs is important for several reasons. Firstly, it helps to prevent users from accidentally accessing URLs that do not exist, which can lead to frustration and a poor user experience. Secondly, it helps to reduce the load on the server, as the server does not need to waste resources attempting to process nonexistent URLs. Finally, returning a 4xx error for nonexistent URLs can help to improve the website's search engine optimization (SEO), as search engines may penalize websites that return 5xx errors for nonexistent URLs.

Therefore, we would recommend that you update your homepage to return a 4xx error for nonexistent URLs, such as the URL in question. This will help to improve the user experience, reduce the load on the server, and improve the website's SEO.

Thank you for your understanding and cooperation.

Best regards,
@spirillen

@Imanolmanu
Copy link
Author

hello good morning.
I have spoken with the person in charge of the website and they have told me that the problem has been solved.
Can you remove me from the list please?

@spirillen
Copy link
Contributor

you can just press the unsubscribe in the right column

Image

@github-project-automation github-project-automation bot moved this from 🚫 Blocked / Waiting to ✅ Done in Phishing Database Backlog Jan 31, 2025
@Imanolmanu
Copy link
Author

Hello,
When will it be removed from the list? It keeps showing up.

Image

@spirillen
Copy link
Contributor

When you solves your server issues, you can ask again...

#952 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
false positive Should not be listed WIP
Projects
Archived in project
Development

No branches or pull requests

5 participants