Resend my activation email : Register : Log in 
BCF: Bike Chat Forums


Sophos Web Protection bawwwing about my web site

Reply to topic
Bike Chat Forums Index -> The Geek Zone
View previous topic : View next topic  
Author Message

Rogerborg
nimbA



Joined: 26 Oct 2010
Karma :

PostPosted: 13:42 - 15 Jan 2013    Post subject: Sophos Web Protection bawwwing about my web site Reply with quote

Any of you chaps into bondage security?

Sophos Web Protection is reportedly spitting its dummy over images hosted on:

https://rogerborg.dnsd.me

The squawk is about "mal/HTMLgen-a". Top Google hit is (of course) "False positive mal/HTMLgen-a - SophosTalk community". I've had a moan in there, but any suggestions would be welcome.

Sophos cagily wrote:
Mal/HTMLGen-A is the threat name associated with web pages that have been classified as malicious by SophosLabs.

Web pages blocked by Sophos products as Mal/HTMLGen-A are likely to be used in an infection chain used to infect users with malware.


So, not actually infected, it just looks dodgy for some unspecified reason.

1) It's a free dynamic sub-domain got via dnsdynamic.org

2) It's hosted on my Raspberry Pi running Debian and lighttpd (along with other dodgy sites like YouTube and Wikipedia). At the moment, that's exposed in its raw nekkidness to the intardtubes because of reasons, but there's not much going on there (nmap away). I had a squid proxy briefly exposed, but that should be tucked away now.

3) There's a robots.txt that denies all.

4) There's nothing there but images (for forum linkage, not those sort), plus a bare index.html with one <img> tag.

Actually, https://validator.w3.org/ is grumping about " A fatal error occurred when attempting to decode response body from https://rogerborg.dnsd.me/index.html. Either we do not support the content encoding specified ("bzip2"), or an error occurred while decoding it.

The error was: Don't know how to decode Content-Encoding 'bzip2' "

Bzip2? Thinking

I've moved the robots.txt aside for now and ensured that only port 22 is exposed. Anyone got any ideas what else I can try?
____________________
Biking is 1/20th as dangerous as horse riding.
GONE: HN125-8, LF-250B, GPz 305, GPZ 500S, Burgman 400 // RIDING: F650GS (800 twin), Royal Enfield Bullet Electra 500 AVL, Ninja 250R because racebike
 Back to top
View user's profile Send private message You must be logged in to rate posts

P.
Red Rocket



Joined: 14 Feb 2008
Karma :

PostPosted: 15:22 - 15 Jan 2013    Post subject: Reply with quote

Sophos died a death last year and starting giving out false positives.

My Sophos here isn't complaining Thumbs Up
 Back to top
View user's profile Send private message Send e-mail You must be logged in to rate posts

jeddy11
Traffic Copper



Joined: 06 Jul 2012
Karma :

PostPosted: 15:27 - 15 Jan 2013    Post subject: Reply with quote

You can come and suck my sophos you big gay bear Wink
____________________
Fuelly My Z1000SX
cbt 06/08/11 mod1 (second go) 01/08/12 mod2 21/09/12
Varadero Viking YBR125>Varadero125>ER6F>Z1000SX !!!
 Back to top
View user's profile Send private message Send e-mail You must be logged in to rate posts

Rogerborg
nimbA



Joined: 26 Oct 2010
Karma :

PostPosted: 16:18 - 15 Jan 2013    Post subject: Reply with quote

##Paddy## wrote:
My Sophos here isn't complaining Thumbs Up

Hmm, maybe I've pushed the correct secret button by accident then. Thumbs Up
____________________
Biking is 1/20th as dangerous as horse riding.
GONE: HN125-8, LF-250B, GPz 305, GPZ 500S, Burgman 400 // RIDING: F650GS (800 twin), Royal Enfield Bullet Electra 500 AVL, Ninja 250R because racebike
 Back to top
View user's profile Send private message You must be logged in to rate posts

Spudly
World Chat Champion



Joined: 04 Apr 2012
Karma :

PostPosted: 19:03 - 15 Jan 2013    Post subject: Reply with quote

You enabled server side compression mebbe?
____________________
The Old Apprentice
 Back to top
View user's profile Send private message You must be logged in to rate posts

Rogerborg
nimbA



Joined: 26 Oct 2010
Karma :

PostPosted: 21:35 - 15 Jan 2013    Post subject: Reply with quote

inksmithy wrote:
You enabled server side compression mebbe?

Winner, mod_compress was enabled by default. Hark at lighttpd, wearing Big Boy pants.

https://www.w3.org/Icons/valid-html401
____________________
Biking is 1/20th as dangerous as horse riding.
GONE: HN125-8, LF-250B, GPz 305, GPZ 500S, Burgman 400 // RIDING: F650GS (800 twin), Royal Enfield Bullet Electra 500 AVL, Ninja 250R because racebike
 Back to top
View user's profile Send private message You must be logged in to rate posts

Jayy
Mr. Ponzi



Joined: 08 Jun 2009
Karma :

PostPosted: 01:26 - 16 Jan 2013    Post subject: Reply with quote

Why no HTML5?
 Back to top
View user's profile Send private message You must be logged in to rate posts

Rogerborg
nimbA



Joined: 26 Oct 2010
Karma :

PostPosted: 07:45 - 16 Jan 2013    Post subject: Reply with quote

ZX Jay wrote:
Why no HTML5?

I only have 4 fingers, you insensitive clod.
____________________
Biking is 1/20th as dangerous as horse riding.
GONE: HN125-8, LF-250B, GPz 305, GPZ 500S, Burgman 400 // RIDING: F650GS (800 twin), Royal Enfield Bullet Electra 500 AVL, Ninja 250R because racebike
 Back to top
View user's profile Send private message You must be logged in to rate posts
Old Thread Alert!

The last post was made 12 years, 107 days ago. Instead of replying here, would creating a new thread be more useful?
  Display posts from previous:   
This page may contain affiliate links, which means we may earn a small commission if a visitor clicks through and makes a purchase. By clicking on an affiliate link, you accept that third-party cookies will be set.

Post new topic   Reply to topic    Bike Chat Forums Index -> The Geek Zone All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

Read the Terms of Use! - Powered by phpBB © phpBB Group
 

Debug Mode: ON - Server: birks (www) - Page Generation Time: 0.09 Sec - Server Load: 2.14 - MySQL Queries: 16 - Page Size: 60.32 Kb