Support

Admin Tools

#38603 Issue with site being flagged as dangerous resided with rochen.com

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
4.2.8
PHP version
8.0
Admin Tools version
7.2.2

Latest post by tampe125 on Wednesday, 22 February 2023 02:02 CST

tmichel

Just wanted to let you know that after all the work to make sure that lucianrex.com was not propagating anything that could be construed as malicious code by Google had nothing to do with the Joomla installation. It was an issue with the rochen.com code that maps requests to a domain name/IP to the server IP where that website resides. For some reason another website on the same server that hosted lucianrex.com was delivering content that caused Google Search to flag the IP of that server as "Dangerous" resulting in all websites on that server being flagged as "Dangerous."

This is the reply rochen.com gave me.

Thanks for your patience here. I have looked into this and found the problem was caused by your server's IP address being blocked at CloudMark, which the remote email server for dactyl.org uses as a blacklist. We identified the root issue responsible which was caused by another client on your same server and we have taken action to prevent this from recurring, as well as submitted a delisting request to CloudMark. Please allow around 24-48 hours for this to be processed, then you should be able to email the affected recipient successfully

This was important because I got hammered on Mattermost for bringing up the fact that there was a problem with rochen.com. Brian Teeman had to weigh in and quell the flames.

rochen.com corrected the problem and got lucianrex.com dismissed from CloudMark's list. It was through this process that rochen.com was able to identify that a problem actually existed.

tampe125
Akeeba Staff

Hello,

thank you for the update. What you described is one of the perils of being on a shared host: if another website is compromised, the full server could be flagged as "dangerous", so you end up with a notice.

Sadly there's nothing that we can do, this is host responsibility to always check that everything is working smoothly and keep their own servers out of blacklists.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

tmichel

Yes, I understand that, my website is housed on one of many folders on a server managed by Apache or NGINX or both..

I just provided this as an FYI. rochen.com said that they resolved the IP mapping issue and that the problem won't present itself again going forward.

tampe125
Akeeba Staff

Ok, thank you for the update!

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!