PDA

View Full Version : Safe Online false positive: fhm.com


pkidza
April 29th, 2010, 12:00 PM
I followed a link to the FHM top 100 sexiest woman article on fhm.com from www.theregister.co.uk. Prevx claims that the domain has been blocked because it spreads malware. Mcafee Siteadvisor and Norton Safeweb report that it is safe. Could you take a look at it? I think that it might be needlessly blocked.

I have PM'd the full address to PrevxHelp.

Thanks.

DavidCo
April 29th, 2010, 12:34 PM
Maybe PrevX folk think that it will drive you blind;D

Confirmed by the way:'(

Triple Helix
April 29th, 2010, 01:00 PM
-{ Quote: "I followed a link to the FHM top 100 sexiest woman article on fhm.com from www.theregister.co.uk (http://www.theregister.co.uk). Prevx claims that the domain has been blocked because it spreads malware. Mcafee Siteadvisor and Norton Safeweb report that it is safe. Could you take a look at it? I think that it might be needlessly blocked.

I have PM'd the full address to PrevxHelp.

Thanks." }-

You should send the link and give details to report@prevxresearch.com as they don't want threads here about possible False Positives even if it is a PSO FP as PrevxHelp will probably close this thread also!

More Details: http://www.wilderssecurity.com/showthread.php?t=245129 Joe maybe you can update this thread to add PSO FP reporting also?

TH

pkidza
April 29th, 2010, 01:12 PM
-{ Quote: "You should send the link and give details to report@prevxresearch.com as they don't want threads here about possible False Positives even if it is a PSO FP as PrevxHelp will probably close this thread also!

More Details: http://www.wilderssecurity.com/showthread.php?t=245129 Joe maybe you can update this thread to add PSO FP reporting also?

TH" }-

Ah okay. I will send an e-mail to that address.

Triple Helix
April 29th, 2010, 01:17 PM
-{ Quote: "Ah okay. I will send an e-mail to that address." }-

It is the fastest way to get it fixed as Joe is not around 24 hours a day ;D

TH :thumb:

Page42
April 29th, 2010, 01:27 PM
Hey TH
What do you think of the way MBAM forum handles false positives?
I like their method alot... they've devoted a sub-forum to the topic, and it is widely used and quite efficient.
And the biggest plus (in my opinion) is that it allows other users a place to see what has been reported, thus helping them make a decision on what to do when they get a suspected false positive. It's always been helpful to me to go to a forum and see if others have reported a file. I miss that here.
:)

Triple Helix
April 29th, 2010, 01:36 PM
-{ Quote: "Hey TH
What do you think of the way MBAM forum handles false positives?
I like their method alot... they've devoted a sub-forum to the topic, and it is widely used and quite efficient.
And the biggest plus (in my opinion) is that it allows other users a place to see what has been reported, thus helping them make a decision on what to do when they get a suspected false positive. It's always been helpful to me to go to a forum and see if others have reported a file. I miss that here.
:)" }-

They did try it here in a FP Thread http://www.wilderssecurity.com/showpost.php?p=1534535&postcount=384 when they first came here to Wilders but things got out of control and allot of flames IMO and they stopped it and they want users to report via this thread only now http://www.wilderssecurity.com/showthread.php?t=245129

You must remember that thread? http://www.wilderssecurity.com/showthread.php?t=252417

TH

Page42
April 29th, 2010, 01:56 PM
-{ Quote: "They did try it here in a FP Thread http://www.wilderssecurity.com/showpost.php?p=1534535&postcount=384 when they first came here to Wilders but things got out of control and allot of flames IMO and they stopped it and they want users to report via this thread only now http://www.wilderssecurity.com/showthread.php?t=245129
You must remember that thread? http://www.wilderssecurity.com/showthread.php?t=252417" }-
I certainly do remember it, TH. Thanks for posting the link.
And if you look at Joe's first response to that thread, you'll note that when I said that I wished the False positives / Missing detections thread could have remained open, and that I get the feeling that if members had used it strictly for what it was meant for, rather than for discussion, it might still be open, and that I think it was a tremendous benefit when used in the manner in which it was intended... Joe's response was (with my boldings)...
-{ Quote: "I agree, but because it generally only takes a minute or so to fix an FP, we feel the usefulness of the thread is diminished, especially when most of the posts require us to just get a scan log from the user anyway.

We may end up changing this but currently it seems like the thread largely outlived its usefulness.

Of course, this won't negatively impact our reaction times at all - quite the contrary as it will improve them by us being able to have more "hands on deck" to analyze each file as it comes in.

We're definitely interested in any feedback on this, so feel free to comment further!" }-
So I'm just reiterating my opinion that a false positive section, when handled properly (like MBAM), can be a popular asset. :)

Triple Helix
April 29th, 2010, 02:08 PM
-{ Quote: "I certainly do remember it, TH. Thanks for posting the link.
And if you look at Joe's first response to that thread, you'll note that when I said that I wished the False positives / Missing detections thread could have remained open, and that I get the feeling that if members had used it strictly for what it was meant for, rather than for discussion, it might still be open, and that I think it was a tremendous benefit when used in the manner in which it was intended... Joe's response was (with my boldings)...

So I'm just reiterating my opinion that a false positive section, when handled properly (like MBAM), can be a popular asset. :)" }-

I understand your point believe me but it is up to the Prevx Team as they want to do and I think that every FP thread started since has been closed by them! But in the last post by Joe here http://www.wilderssecurity.com/showpost.php?p=1534535&postcount=384 he said:
-{ Quote: "You can also send one of us a PM but that isn't as optimal as sending an email as it is then limited to only the Wilders support staff to analyze it, while an email submission can be viewed by any of our researchers.

For now, I'm going to close this thread. Feel free to continue any discussions outside in another thread within our forum, or contact us by PM/email/inbox and we will be happy to discuss anything further." }-

TH

Page42
April 29th, 2010, 02:17 PM
I just wanted the opportunity to go on record once again as someone who would appreciate a FP sub-forum. As noted, it's always been helpful to me to go to a forum and see if others have reported a file. I miss that here. :)

Triple Helix
April 29th, 2010, 02:18 PM
-{ Quote: "I just wanted the opportunity to go on record once again as someone who would appreciate a FP sub-forum. As noted, it's always been helpful to me to go to a forum and see if others have reported a file. I miss that here. :)" }-

Understood! ;)

Regards,

TH

PrevxHelp
April 29th, 2010, 05:29 PM
Hello,
Thank you for the report. We're looking to see the cause of it (it may have been that there was a malicious ad involved) but either way the website certainly deserves some closer inspection ;)

Regarding false positives - we currently don't see a need to open a subforum for FP reports because of the extremely low volume that we receive due to database improvements over the last three-four months.