Chrome is blocking wired.com
wired.com
wired.com
Added: Looks like it was an actual hack, not just a bad ad. The Wired folks will want to make sure there's no more iframes from hxxp://zlu bob.org. Folks can use our free Fetch as Google tool to see what we see when we try to fetch a page. You can find out more about the Fetch as Google tool here: https://support.google.com/webmasters/answer/158587?hl=en
If they leave their WordPress un-patched, or have a crappy plugin installed with security holes, or their FTP info is guessed, etc, hackers drop some malicious Javascript on their sites, and the next thing you know, their site cannot be accessed in Chrome, and usually Firefox as well. Depending on what services pick-up on the bad javascript.
For me, it usually takes a day(ish) from the time we are notified of the issue, update the sites, remove the malware, install webmaster tools from Google, submit and wait for the review to be unblocked.
On one hand, this is very frustrating, but on the other hand, many small businesses would have no idea their site had been hacked without it being blocked.
The only thing I'd like to see personally is if Google were somehow able to notify the domain registrant of the block via email so they find out right away, and not after a few weeks (or longer) in some cases. Some small business owners don't check their sites very often. We like to monitor our client sites, but sometimes new clients come to us with these problems and have no idea how long they've been down.
I get notified via email when Google finds any issues on my site.
We can sometimes label sites as hacked in the search results, but Webmaster Tools is definitely the preferred channel for communication of stuff like this.
For example, if we manually detect that a subdirectory of a site is hacked, we may remove only that subdirectory from our search results. If your entire site is hacked, then your entire site may be demoted or removed until the site is clean.
Ironic since the original reason for the tech contact was exactly to be notified for issues like this.
Would like to add that as a registrar though we get a reasonably good response to emails that we send. [1]
Perhaps there is something about getting an email from google that says "it's probably spam". Or any large well known company that is often the subject of spam attempts.
Even given that though it's hard for me to believe that the results were close to zero.
[1] We also find that when a domain is deleted for non payment the person frequently claims they received no email notice but then proceeds to make some reference to something that was on the email notice.
The main page is not blocked but anything I click on is blocked.
Here is the Why page:
Safe Browsing Diagnostic page for wired.com/2014/04
What is the current listing status for wired.com/2014/04?
Site is listed as suspicious - visiting this web site may harm your computer.
What happened when Google visited this site? Of the 135 pages we tested on the site over the past 90 days, 0 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2014-04-05, and suspicious content was never found on this site within the past 90 days.
This site was hosted on 12 network(s) including AS31377 (AKAMAI-BOS), AS701 (UUNET), AS12989 (HWNG).
Has this site acted as an intermediary resulting in further distribution of malware? Over the past 90 days, wired.com/2014/04 did not appear to function as an intermediary for the infection of any sites.
Has this site hosted malware? No, this site has not hosted malicious software over the past 90 days.
How did this happen? In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.
Next steps: Return to the previous page.
If you are the owner of this web site, you can request a review of your site using Google Webmaster Tools. More information about the review process is available in Google's Webmaster Help Center. http://www.wired.com/playbook/wp-content/uploads/2013/07/soccer_w.jpg
http://www.wired.com/playbook/wp-content/uploads/2013/06/bike-press-w.jpg
Both return actual images, so perhaps at some point in the past when wired.com was scanned these URLs redirected to somewhere malicious?Screenshot: http://cl.ly/image/1m3g3L2v3w3C
"WIRED: @Freakonomicss @hoffin205 Yeah, we had a technical issue this morning, but our tech team fixed. Waiting for @googlechrome to clear us"
The page essentially says "We believe this page is suspicious, and we have no evidence to back up that claim."
EDIT: They must have updated it/ busted a cache. The page is now reporting some evidence.
Second, this is what it says at the above link:
--SNIP--
What happened when Google visited this site?
Of the 26 pages we tested on the site over the past 90 days, 4 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2014-04-05, and the last time suspicious content was found on this site was on 2014-04-05.
Malicious software is hosted on 1 domain(s), including zlubob.org/.
--SNIP--
They're doing a good thing with this, and they're helping webmasters who can't help themselves.
It's still blocked for me, with Google branding wired.com as "a known malware distributor."
Try:
chrome://net-internals/#dns Click "Clear host cache"
As to the technically correct statement, don't you think that saying a site is a "known malware distributor" is a bit more sweeping than saying something more accurate like "we discovered malware on this site"?
In other words, they are using the same language I would expect to see directed towards sites that have malicious intent and should never be visited.
https://support.mozilla.org/en-US/kb/how-does-phishing-and-m...
So it makes sense the error would show up both places.
------- The website at www.wired.com contains elements from sites which appear to host malware – software that can hurt your computer or otherwise operate without your consent. Just visiting a site that contains malware can infect your computer.
Below is a list of all the unsafe elements for the page. Click on the Diagnostic link for more information on the thread for a specific element.
Malware http://www.wired.com/playbook/wp-content/uploads/2013/07/soc... Safe Browsing diagnostic page
Malware http://www.wired.com/playbook/wp-content/uploads/2013/06/bik... Safe Browsing diagnostic page -------
I wonder what's wrong with these two pictures?
The safe browsing diagnostic page shows no negative current or previous reports for wired.com despite describing it as suspicious:
http://safebrowsing.clients.google.com/safebrowsing/diagnost...
> What is the current listing status for www.wired.com? This site is not currently listed as suspicious.
> Has this site hosted malware? No, this site has not hosted malicious software over the past 90 days.
http://www.incapsula.com/blog/world-largest-site-xss-ddos-zo...
Security company found a vulnerable Alexa Top 50 site where someone was able to inject XSS code in the comments section creating "DDoS Zombies" of the visitors.
Blocked in Chrome Version 33.0.1750.154 m
Not blocked in ie11, Firefox 20
In my Mobile (HTC One M7 4.4.2):
Neither blocked in Chrome(33.1) nor in the stock browser
Doesn't Android Chrome support malware detection?
Is this typically through Java Applets/other plugins?
There are in number of ways for nasty things to happen just by visiting a page.
specially crafted jpgs and gifs have also been used to exploit overflows in image handling code.
Because browsers are written in very unsafe programming languages (C++), bugs are regularly exploitable so that by specially crafting the bug-triggering input data they can be fooled to scribble content-controlled data inside the browser's memory space. For example, a memory handling bug might let the page overwrite some of the browser's code with data coming from the web page.
This lets the web page break into your computer, running arbitrary code of its choosing on your box.
Browser plugins can be similarly targeted instead of the browser itself.
My point was that it's not a C specific problem, though. Most browsers are in fact built on C, I agree. This is due primarily to the speed and performance of the language that is harder to reach with other languages.
It is definitely a more difficult language to write, as it is much more "raw," but that doesn't make it inherently unsafe to use, or any more unsafe than other languages.
If you vote because you think C is unsafe, carry on. You're wrong, though.
And it's not a "potentially" thing, as is apparent to anyone following news about browser vulnerabilities. For a recent public performance, see pwn2own - http://nakedsecurity.sophos.com/2014/03/14/pwn2own-day-two-c...
ps: Mozilla Firefox 31.0a1 is ok with wired.com
Google could lose enormous market share if any major browser decided to change the default search engine. So they created their own major browser.
Chrome is not an information source for Google, it's a way to maintain Google as a default search engine.
They fund Mozilla for the same reason.
Similarly, a major reason for Android could be seen to be preventing a hostile mobile-platform monopoly which would either block or extract monopoly rents from (and thus limit the value of) Google services reaching mobile users.
You should turn all Google networking activities in your browser off. By default, there are at least five or so enabled which will happily send every request you make to Google. Some services even go as far as logging every keystroke you make.
https://www.google.com/intl/en/chrome/browser/privacy/
If you don't trust what they are saying there, you shouldn't be using Chrome at all.
Perhaps you should actually fact-check such assumptions before passing them along as "friendly reminders"?
Here's more information in case you want to read more: https://code.google.com/p/google-safe-browsing/wiki/SafeBrow...