Roll out of new web filtering

Discussion in 'Prevx Releases' started by aieie, Oct 15, 2013.

Thread Status:
Not open for further replies.
  1. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
  2. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
  3. The Seeker

    The Seeker Registered Member

    Joined:
    Oct 24, 2005
    Posts:
    1,339
    Location:
    Adelaide
    My wife is a crochet fan. Quite often, she clicks on a link to a crochet blog from Facebook only to be met with a Webroot 'Malicious URL' screen. I too have experienced this which required me to submit the URLs to Webroot.

    Even as an advanced user, I don't want to be submitting URLs to Webroot; I want to browse the Internet without worrying about such things. Such screens create nothing but ambiguity and lead to a poor decision which compromises the end-user.
     
  4. kdcdq

    kdcdq Registered Member

    Joined:
    Apr 19, 2002
    Posts:
    815
    Location:
    A Non-Sh*thole State
    The Seeker has a good point with his last post. My wife has been Christmas shopping via the Net and has hit a bunch of Webroot 'Malicious URL' screen messages in the process. Now I have to look at each one and submit them?? :eek: I'm not sure what the right answer is, but it seems like there must be a better way... o_O
     
  5. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Could you both send me a scan log to my username at gmail.com? It will show what engine is blocking the pages which should help identify the cause.

    Thank you!

    Also, this reminds me I need to start my Christmas shopping...
     
  6. Techfox1976

    Techfox1976 Registered Member

    Joined:
    Jul 22, 2010
    Posts:
    749
    Joe,

    A quick examination of a selection of Brightcloud stuff shows that they are being exceptionally paranoid and very prone to FPs. The -REAL- Battle.net site for WoW was blocked for instance, I've seen cases where real bank sites for smaller banks were listed as Phishing, and all of these items that people are describing are easy enough to find on Google.

    Somebody needs to head down to the Gritty Waffle city (Sandy Eggo) and poke the Brightcloud crew and ask them "OMWTFBBQ Guys?!". It seems that including -ONE- copy of a legitimate link with a low visit rate in an email that is otherwise phishing will blacklist the legitimate link on Brightcloud too. This is embarrassing and very inconvenient and annoying and even some of my consumer users have started to complain.

    It sucks.
    Make it less-so.
     
  7. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Thanks - I will definitely escalate this up and see what we can do.
     
  8. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Hi Joe

    I have to say that I am surprised by the reports of all these FPs as I have only come across one; related to a major bank's online banking portal, which I have reported in the required manner...but I am not seeing any interruptions in Xmas shopping ( ;) ) activities.

    However, as the functionality is new it is bound to have some rough edges, so perhaps some focus could be put on the suggestions to improve the ease of reporting such FPs or allowing users to whitelist sites locally, etc.?

    Have great weekend

    Regards, Baldrick
     
  9. bwb1

    bwb1 Registered Member

    Joined:
    Mar 20, 2010
    Posts:
    113
    Location:
    UK
    @Sturgess....Thanks for that, it was helpful. Just done deep scan as in your post, and when I tried Lloyds Bank it worked OK. :thumb:
     
  10. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Hi bwb1

    Yup, can confirm that having submitted an FP report and, having allowed Support sometime to action, I have then run a Deep Scan and the FP reported seems to have disappeared.

    Regards


    Baldrick
     
  11. hayc59

    hayc59 Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    2,841
    Location:
    KEEP USA GREAT
    I gave up even hoping!!
     
  12. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    It is coming...but there are 30+ million users to update. :D
     
  13. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    My father-in-law just called me and asked about a weird pop-up when visiting his bank online.

    One of the largest banks of Sweden is blocked by Webroot (I don't think he or I have the new web filtering).

    I, before I told him he could click 'allow', visited the site as well (with IE) and it seems like it's a false positive. I had the same problem as well.

    It's not blocked when browsing with Chrome but it is when Internet Explorer is used.

    The website is www.swedbank.se

    I'll contact support as well with this. Just a heads up to all the swedes out there. :)
     
  14. SweX

    SweX Registered Member

    Joined:
    Apr 21, 2007
    Posts:
    6,429
    Hi Shadek! :)

    We use Swedbank too. And indeed it is blocked not only by Webroot in your case, but also by OpenDNS that I use. (I was going to check if ESET would block it but OpenDNS blocked it first)

    OpenDNS message......
    Perhaps Webroot have a partnership with OpenDNS/PhisTank so they are using their phishing data.

    Edit: I have reported this to OpenDNS as a phishing FP.
     
    Last edited: Nov 16, 2013
  15. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
  16. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    Could someone please give me an opinion of the description for this workaround-install of filtering ext into FF browser, posted by explanoit here at the Community. Is it accurate, and described in enough detail? Just that I couldn't get it to work with Pale Moon browser, but it works fine for Firefox only (I haven't tried)?
     
  17. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    It's not being blocked now but this the first time I checked and I have the New Web Shield or is the problem with the old Web Shield? Also BrightCloud is showing as good.

    Daniel

    16-11-2013 4-24-08 PM.png
     
  18. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    Your link is broken as it shows page 3 and there is no page 3. https://community.webroot.com/t5/We...-Internet-Explorer-11/td-p/67173#.UofjO-IZlOc

    Daniel
     
  19. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    Does this link work? Top of page 3: https://community.webroot.com/t5/We...k-with-Internet-Explorer-11/td-p/67173/page/3
     
  20. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
  21. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    His link works for me and takes me to page 3...
     
  22. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    I tried 3 browsers and I don't see a page 3 o_O

    16-11-2013 5-02-19 PM.png

    Daniel
     
  23. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    Is it possible that e.g. TH is subscribed to that thread, and then only sees as far as solution on P2? Or a forum software bug?
     
  24. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    It's my settings on the Community as I signed out there are 3 pages I set mine to allow more posts per page in settings.

    Daniel :blink:

    16-11-2013 5-08-14 PM.png
     
  25. zfactor

    zfactor Registered Member

    Joined:
    Mar 10, 2005
    Posts:
    6,102
    Location:
    on my zx10-r
    i have a client who finally got the new web filtering (i STILL have not go the update and this includes a total of 11 different keys between me and family waiting) but he has had it block some sites that we checked and not one other av i have (which is MANY) flagged so i did send it in. but he left his laptop for me and i did some surfing and it is VERY sensitive while i EAGERLY await this update i am kind of worried about fp's not for me but for family and friends and clients being concerned what to do when they see the pop up.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.