Virus/malware on website?

Hello,

We are currently experiencing a problem when trying to access the website/documentation/…, everything under the ardupilot.org/xxx link.

The problem I am experiencing is due to an antivirus feature implemented in our company’s firewall. For security reasons, our IT department is not allowed to disable this feature. Unfortunately, the ardupilot website is listed as “malicious” by several firewall and security vendors.
For example, CRDF Threat Center: Check the status of a URL in our databases reports: “The domain name ‘ardupilot.org’ is known to violate our detection criteria”.

A colleague of mine from the IT department has already sent an email to admin@ardupilot.org (20.9.2023, 14:31 CEST), but since there was no response until now, I hope someone here can help or point me to a contact person with whom we can discuss this problem.

Thanks
Felix

1 Like

Hello,

Thanks for the report. Sometimes ago we were wrongly blacklisted as phishing website by some adblocker … I wonder what trigger that as I cannot find any report or evidence of such behavior.

We will give biggest look at this. Thanks for the report

1 Like

from other tools, we aren’t marked as malicious :
Ardupilot.org Safe? Check it Now | URLVoid only CRDF is blocking us

1 Like

Thanks for looking into this!

We found a few more that mark this site as malicious using virus total: VirusTotal

I’m 99% sure you’re aware of this, but I’m posting it anyway, just in case: There is a delisting process at crdf: CRDF Threat Center: False positive procedure
Can you or someone else in charge start this process?

I will probably do it unless somebody beat me. But before I need to inspect back our website just in case. We can be missing something link an url redirecting to an armfull website

1 Like

I’m having problems with kaspersky antivirus in my personal computer too.

I tried several ways to unblock ardupilot websites but until now I couldn’t figure out how to do it.

do you have a details of what they found suspicious on our website ?

is https://firmware.ardupilot.org/ blocked too ?

hi @khancyr

I addedd .ardupilot. and .github. as trusted site and now the web browser can access the firmware and all other related websites, but if I open mission planner I’m getting a lot of blocks and the options to update firmware is not available:

INFO MissionPlanner.ArduPilot.APFirmware - https://firmware.ardupilot.org/manifest.json.gz
ERROR MissionPlanner.ArduPilot.APFirmware - System.Net.Http.HttpRequestException: An error occurred while sending the request. —> System.Net.WebException: A conexão subjacente estava fechada: Erro inesperado em um envio. —> System.IO.IOException: Unable to write data to the transport connection: Foi forçado o cancelamento de uma conexão existente pelo host remoto. —> System.Net.Sockets.SocketException: Foi forçado o cancelamento de uma conexão existente pelo host remoto at System.Net.Sockets.Socket.BeginSend(Byte[] buffer, Int32 offset, Int32 size, SocketFlags socketFlags, AsyncCallback callback, Object state)

Mission planner is addedd as a trusted application,

Unfortunately no, our IT department tried to ask the software manufacturer, but they are not able or willing to provide additional information - I don’t know why and I don’t understand why…

firmware.ardupilot.org is not blocked. As far as I know, no other subdomain is blocked, but maybe I’ve missed one.

Korean official portal site “naver.com” big file mail system is also recognized as phising site sometimes.

it is not accurate.

The CRDF lisiting is now gone, but according to Virustotal (VirusTotal) there are still 5 security vendors that flagged this URL as malicious.
Unfortunately our firewall seams to use data from at least one of these vendors, so if you can take a look at it, it will be highly appreciated. If I can help in any way please let me know.