Jump to content

Welcome to TheMalibuCrew!

As a guest, you are welcome to poke around and view the majority of the content that we have to offer, but in order to post, search, contact members, and get full use out of the website you will need to Register for an Account. It's free and it's easy, so don't hesitate to join the TheMalibuCrew Family today!

Site blocked at work?


Badger

Recommended Posts

I've been a member since 2006 and never had an issue. About 3 weeks ago, my access to TMC Has been blocked both at the office and through the VPN. Error says:

Threat type: othermalware

Threat reason: IP address is either verified as a bot or has a misconfigured DNS

Am I done for good?

Link to comment

Sounds like the site's reputation score has gone down and caused proxy to block it based on some threshold. If the site is on shared hosting, there could be another site on the same ip hosting malware and since we're on that host, we get flagged as well. I'll look into a few things tomorrow and see if I can see what vendors are flagging the site and why. Chances are it might be a false positive and it'll work itself out in a few days.

Edited by boardjnky4
Link to comment

or they just see too many people "wasting time" on TMC vs working. But then again, if they visited the site, they would see it is time well spent :)

I'd be inclined to agree, except that the error code being spit out is specific to being malware related, which makes me think it's a signature update.

Link to comment

Tis indeed a Cisco Web Security Appliance. Here is the reputation information:

Look_Up_for_www_themalibucrew_com_-_Send

Note the blocklist at the bottom is where Cisco's intelligence is coming from. On that site, I found the following, related to the IP address this site is hosted on.

IP Address 104.28.16.72 is listed in the CBL. It appears to be infected with a spam sending trojan, proxy or some other form of botnet.

It was last detected at 2014-08-18 20:00 GMT (+/- 30 minutes), approximately 8 days, 17 hours ago.

So yeah, either this site is infected, or a different site is infected and is sending crap. Site admins should probably contact CloudFlare.

Edited by boardjnky4
Link to comment

OK, I found the compromised site on the shared hosting. It's NOT themalibucrew.com and it does appear to have since been fixed. The bad site is/was alshahidalmustakel.tv.

I put a request in with the blocklist to have the IPs removed. That might take some time to propagate down to Cisco and to your company's appliance, so try to be patient.

Edited by boardjnky4
Link to comment

You're a miracle worker! I just posted this from my desk at work!

Hello TMC at work again!

Goodbye productivity! (To any IT guys secretly spying on me at work: Just kidding!)

Seriously, boardjnky4, whoever you really are, thank you very much for doing this. I don't understand any of the stuff you had to do, but I appreciate you making my lunchtime reading much more enjoyable!

:cheers: I owe you one!

Link to comment

This thread makes me lolz. Heaven forbid anyone be reduced to viewing this site on their smartphone at work like I'm doing right now! This is really just me being jealous that you spend all day here rather than actually working.

Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...