Live data from Hacker News

Diagnostic page for Google.com

google.com

51–60 of 75 posts

Re: Diagnostic page for Google.com

#51
post #22
post #3

Earlier quoted context omitted.

Safe Browsing Diagnostic page for google.com What is the current listing status for google.com? This site is not currently listed as suspicious. Part of this site was listed for suspicious activity 12 time(s) over the past 90 days. What happened when Google visited this site? Of the 6815255 pages we tested on the site over the past 90 days, 1686 page(s) resulted in malicious software being downloaded and installed wi…

I'm not sure re-posting the site answers the OP's question. This its likely the result of user generated content running on a google.com subdomain.

"Would some kind soul please describe to me what this does, my corporate eager beaver network admins seem to consider this some kind of problem site and it's URL is BLOCKED by our gateway proxy."

Re: Diagnostic page for Google.com

#52
post #4

Would some kind soul please describe to me what this does, my corporate eager beaver network admins seem to consider this some kind of problem site and it's URL is blocked by our gateway proxy.

It's google eating its own tail and doing a 'malware report' on google.com.

http://www.googlewilleatitself.com/

Re: Diagnostic page for Google.com

#53
post #42

AS36040 (YOUTUBE), AS43515 (YOUTUBE), AS15169 (GOOGLE), AS54113 (FASTLY), AS36459 (GITHUB), AS16509 (AMAZON-02), AS14618 (AMAZON-AES), AS16509 (AMAZON-02), AS38895 (AMAZON-AS-AP) and so on. Could someone tell me more about those network codes ? Where do they come from ? Specifics to Google or following some standard ?

AS numbers is part of the BGP protocol, when you are a large organization with multiple presence points on the internet you need to advertize your prefixes (routes), i.e. the IP blocks that you host behind your routers, and to do that you need to be an "Autonomous System" and to be one you need to register with IANA (it costs $500 I think and you need to prove that you actually need one) and you get an AS number. The techincal details are here: https://tools.ietf.org/html/rfc4271

Re: Diagnostic page for Google.com

#55
Few honest questions:

1. If Google detects something as malware, i.e. google software knows that it can be dangerous to users, then why it cannot prevent itself from acting as intermediary? Also, why it does not stop hosting malware?

2. >>> Malicious software is hosted on 279 domain(s), including 24corp-shop.com/, abu-farhan.com/, soaksoak.ru/.

These web domains do not belong to Google. It seems google is downloading several pages onto its server for various purposes. Is it legal in all countries?

From the architecture point of view, is it difficult to sandbox/protect user facing google.com search engine from the above websites all the time so that if malware is there, do not let it effect search engine or other major parts. Users are not security-literate.

3. What should I do as user? Just ignore this assuming that this is for webmasters and not for ordinary users?

Honestly, for me personally, malware on google is unimaginable, since we consider it as gold standard on the web.

Re: Diagnostic page for Google.com

#57
post #7

How can google.com be used to serve malicious content?

Since a couple of years, google redirects you when you click on a hit URL via google.com/something (you only notice this on a slow connection like an EDGE/2G network).

It might very well be that the malware scanner picked up a link to such a "redirector" which leads to malware and then took the TLD google.com for malicious.

Another reason why one should never ever host user-generated files (or links/redirects) on the primary domain. Github did this with github.io for the same reason.

Re: Diagnostic page for Google.com

#59
post #55

Few honest questions: 1. If Google detects something as malware, i.e. google software knows that it can be dangerous to users, then why it cannot prevent itself from acting as intermediary? Also, why it does not stop hosting malware? 2. >>> Malicious software is hosted on 279 domain(s), including 24corp-shop.com/, abu-farhan.com/, soaksoak.ru/. These web domains do not belong to Google. It seems google is downloading…

My theory: People search for stuff on Google. The search results page has a result with a download from abu-farhan.com. People click that link on the search results page, the download starts. Now google.com has "hosted" a malware download.

Re: Diagnostic page for Google.com

#60
post #55

Few honest questions: 1. If Google detects something as malware, i.e. google software knows that it can be dangerous to users, then why it cannot prevent itself from acting as intermediary? Also, why it does not stop hosting malware? 2. >>> Malicious software is hosted on 279 domain(s), including 24corp-shop.com/, abu-farhan.com/, soaksoak.ru/. These web domains do not belong to Google. It seems google is downloading…

It's important for us (I work at Google on web-search) to be transparent about these reports, and we use them to remove / block content that is malicious too (just like other sites can use the Safe-Browsing API to get information about sites they host). With regards to where it's hosted, there are two main elements involved: a site that actually hosts the exploit (which could be a Windows EXE file, etc), and a site that sends the user to that exploit. Often these are separate. Sometimes it's not even a direct embedding of a known malicious site, for example, it could be that a counter/analytics-tracking site is hacked, which could result in all other sites that use those counters/scripts unknowningly sending users to malicious content.

From talking with webmasters, I have seen almost no false-positives in this flagging, but it's sometimes very hard to find the actual exploit. It sometimes hides from some visitors (direct visitors - like the webmaster - might not see it, it might only be visible for those coming from search), sometimes is limited to geographies or devices. This makes finding the exploit hard sometimes, and fixing the website so that it's no longer vulnerable to the attack that dropped the exploit isn't easy in many cases either.

I take these warnings very seriously when I see them in the browser, even when accessing a site with a fairly locked-down & up-to-date browser. I would recommend never skipping them, even to diagnose an issue (use other tools for that).

Post reply on HN