Q&A Netcraft false positive or not ?

JB007

Level 24
Verified
May 19, 2016
1,349
5,536
Hello,
Netcraft blocks a page in a well known French site "La Poste".
I'm wondering if it is a false positive or not :unsure:
VT : clean : VirusTotal
Sucuri : Medium Security Risk : Sucuri Security

Netcraft.PNG
 
Last edited by a moderator:

TairikuOkami

Level 31
Verified
Content Creator
May 13, 2017
2,048
10,351
It's weird for Netcraft, maybe it depends on the country ? :unsure:
I'm sorry, here is still the same: nothing of website content is "blocked" by Netcraft 🤷‍♂️
I see no cookie notice on your screenshot, so maybe it is related to that script?
capture_02182021_152503.jpg

Netcraft does not report anything, when scripts are blocked, with scripts I get this:
capture_02182021_154004.jpg

Code:
Well it definitelly looks like cross site scripting, which can be potentionally malicious.

<script type="text/javascript" src="//cdn.tagcommander.com/1491/tc_LaboutiqueLaPoste_6.js"></script>
<noscript><iframe src="http://redirect1491.tagcommander.com/utils/noscript.php?id=6&amp;mode=iframe" width="1" height="1" rel="noindex,nofollow"></iframe></noscript>

<script type="text/javascript" src="//cdn.tagcommander.com/1491/tc_LaboutiqueLaPoste_17.js"></script>
<noscript><iframe src="http://redirect1491.tagcommander.com/utils/noscript.php?id=17&amp;mode=iframe" width="1" height="1" rel="noindex,nofollow"></iframe></noscript>
 
Last edited:

silversurfer

Level 76
Verified
Trusted
Content Creator
Malware Hunter
Aug 17, 2014
6,594
71,726
I see no cookie notice on your screenshot, so maybe it is related to that script?
View attachment 254327

Of course, I had to allow/accept this cookie-information before able to enter this website.
Scripts are allowed by default on my Edge, as I said Netcraft is the only one browser-extension and even a fresh user-profile on my Edge.

I see you got the block by Netcraft, that's a good info for @JB007 (y)

Anyway, I'm done here as I cannot confirm anything is blocked by Netcraft on my Edge 🤷‍♂️
 

JB007

Level 24
Verified
May 19, 2016
1,349
5,536
I see no cookie notice on your screenshot, so maybe it is related to that script?
View attachment 254327

Netcraft does not report anything, when scripts are blocked, with scripts I get this:
View attachment 254328

Code:
Well it definitelly looks like cross site scripting, which can be potentionally malicious.

<script type="text/javascript" src="//cdn.tagcommander.com/1491/tc_LaboutiqueLaPoste_6.js"></script>
<noscript><iframe src="http://redirect1491.tagcommander.com/utils/noscript.php?id=6&amp;mode=iframe" width="1" height="1" rel="noindex,nofollow"></iframe></noscript>

<script type="text/javascript" src="//cdn.tagcommander.com/1491/tc_LaboutiqueLaPoste_17.js"></script>
<noscript><iframe src="http://redirect1491.tagcommander.com/utils/noscript.php?id=17&amp;mode=iframe" width="1" height="1" rel="noindex,nofollow"></iframe></noscript>
Thanks @TairikuOkami
I deleted all cookies on Edge and then I try again but I did not get the same screenshot (your first) with the choice of blocking the cookies on the site; and so Netcraft continues to block.
 

JB007

Level 24
Verified
May 19, 2016
1,349
5,536
Hello,

I have disabled javascript in Edge settings and Netcraft no longer blocks any page of this site.

I'm not sure if this is the right solution and if now I can use this site "La Poste" with an optimal security ? :unsure:

java.PNG

la poste.PNG
 
Last edited by a moderator:

oldschool

Level 63
Verified
Mar 29, 2018
5,245
38,279
Top