Welcome to the Cumulus Support forum.

Latest Cumulus MX V4 release 4.4.2 (build 4085) - 12 March 2025

Latest Cumulus MX V3 release 3.28.6 (build 3283) - 21 March 2024

Legacy Cumulus 1 release 1.9.4 (build 1099) - 28 November 2014
(a patch is available for 1.9.4 build 1099 that extends the date range of drop-down menus to 2030)

Download the Software (Cumulus MX / Cumulus 1 and other related items) from the Wiki

If you are posting a new Topic about an error or if you need help PLEASE read this first viewtopic.php?p=164080#p164080

Sites blocked by malware scanner

Discussion of the Cumulusutils tool and website generator.

Moderator: HansR

Post Reply
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Sites blocked by malware scanner

Post by HansR »

@PaulMy, @Dador:

Please note that both your sites are blocked by my malware scanner. And from the CUtils sites you are the only two which are blocked. This has happened before in the past, it seemed to be resolved but has recurred. It may be that the shared IP causes the detection. You could ask your provider to be changed to another pool? I don't know.

Please also see my remark at the end of this post.
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Re: Sites blocked by malware scanner

Post by HansR »

Oh and the effect is there since about 5 days so let's say around the 12th (+/- a day or 2)
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
User avatar
Dador
Posts: 352
Joined: Thu 24 Nov 2011 2:22 pm
Weather Station: Davis VP2 Plus & Ecowitt
Operating System: Windows 10
Location: Rybnik, Poland
Contact:

Re: 7.4.2 - extrasensorscharts.txt

Post by Dador »

Could you send me a screenshot of what Malwarebytes says? I will write to the hosting provider about this.
User avatar
Dador
Posts: 352
Joined: Thu 24 Nov 2011 2:22 pm
Weather Station: Davis VP2 Plus & Ecowitt
Operating System: Windows 10
Location: Rybnik, Poland
Contact:

Re: Sites blocked by malware scanner

Post by Dador »

If you can, please delete cookies for my website in your browser.

I just had my Let's Encrypt https certificate renewed about 5 days ago.
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Re: Sites blocked by malware scanner

Post by HansR »

Dador wrote: Mon 17 Feb 2025 10:38 am If you can, please delete cookies for my website in your browser.

I just had my Let's Encrypt https certificate renewed about 5 days ago.
Unfortunately it does not work (I first thought it did but I had switched off MB)
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Re: 7.4.2 - extrasensorscharts.txt

Post by HansR »

Dador wrote: Mon 17 Feb 2025 10:29 am Could you send me a screenshot of what Malwarebytes says? I will write to the hosting provider about this.
Translation: Website blocked because of infection.
If you do not want to block this enter it as an exception. (Alas, that does not work)
I will definitely also contact MB.
Schermafbeelding 2025-02-17 113104.png
You do not have the required permissions to view the files attached to this post.
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Re: Sites blocked by malware scanner

Post by HansR »

Note: this has happened before with more sites but now it has recurred only with yours and Pauls
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
freddie
Posts: 2870
Joined: Wed 08 Jun 2011 11:19 am
Weather Station: Davis Vantage Pro 2 + Ecowitt
Operating System: GNU/Linux Ubuntu 24.04 LXC
Location: Alcaston, Shropshire, UK
Contact:

Re: Sites blocked by malware scanner

Post by freddie »

Didn't MB flag the forum at one time? I remember it making me feel a bit panicked! But IIRC it was a false positive.
Freddie
Image
broadstairs
Posts: 1184
Joined: Thu 14 Aug 2008 7:17 am
Weather Station: Ecowitt GW2000/GW3000
Operating System: Linux openSUSE LEAP
Location: Broadstairs, Kent, UK
Contact:

Re: Sites blocked by malware scanner

Post by broadstairs »

False positives with Malwarebytes is a common issue in my experience. Neither of the reported sites give me an issue.

Stuart
Currently running CMX V4.4.2 4085 on Linux openSUSE Leap
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Re: Sites blocked by malware scanner

Post by HansR »

freddie wrote: Mon 17 Feb 2025 11:31 am Didn't MB flag the forum at one time? I remember it making me feel a bit panicked! But IIRC it was a false positive.
and @broadstairs:

I agree MB is sensitive yes. But all problems last time referred to Highcharts as an advertising site. As a result nobody (with MB) was able to access sites which included the Highcharts libraries. I managed to resolve that and convince MB that including the libraries is different from accessing a website. Now Highcharts can be accessed without problems.

This seems to be different. I am far from sure this is a false positive, more that the sites use cross reference to multiple CMXs, Multiple themselves, multiple CUtils. And somewhere there I believe lies the problem (I think).

I may well be that it is a false positive, but it may also be that MB detects a weakness which makes access for malware easy.

Note that it even does not work by putting the sites on my 'allow'-list.
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Re: Sites blocked by malware scanner

Post by HansR »

Fwiw: I contacted MB and we are in discussion about the false positives (and why).
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Re: Sites blocked by malware scanner

Post by HansR »

And in addition: the blockage is only on laptop/Windows.
Phone or tablet have no problem.
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Re: Sites blocked by malware scanner

Post by HansR »

I received info by MalwareBytes:
  1. komokaweather.com is OK they say:
    that the website has been cleaned up and that the block on this website will be lifted soon. Please allow an hour or so for the updated definitions to be processed
    I can confirm your site is working again @Paul :D
  2. pogodarybnik.pl is more complex:
    Please note that in this case, it's not the website itself that is being blocked but it is the IP address of the server where the website is hosted that's causing the issue.

    The server at the IP address 77.55.253.208 has been compromised and is currently being used for brute force attacks and other malicious acts against other networks and computers.

    To learn more about the IP address in question, you can visit this link: https://www.abuseipdb.com/check/77.55.253.208
    If you know the site owner then please share the link with them.

    This site is on a shared server with other websites on the server It is important to note the risks associated with having a website on a shared server. You can learn more about these risks by visiting the following page: https://wp-wingman.com/the-dangers-of-u ... vent-them/


    If you are the site owner then It's highly recommended that you speak to your hosting provider to get this issue resolved as soon as possible. Alternatively, you may want to consider changing your hosting company.
    @Dador: I would advise you to request your provider being moved to another server
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
User avatar
PaulMy
Posts: 4355
Joined: Sun 28 Sep 2008 11:54 pm
Weather Station: Davis VP2 Plus 24-Hour FARS
Operating System: Windows8 and Windows10
Location: Komoka, ON Canada
Contact:

Re: Sites blocked by malware scanner

Post by PaulMy »

Thanks Hans, great follow up!
I did have a similar 'blocked IP' on my GoDaddy shared hosting last year but that eventually got cleaned up. So glad to hear it is now still fine.

Your advice to @Dador is good, but if the provider is like GoDaddy, then easier said than done.

Enjoy,
Paul
VP2+
C1 www.komokaweather.com/komokaweather-ca
MX https://komokaweather.com/cumulusmx/index.htm /index.html /index.php
MX https://komokaweather.com/cumulusmxwll/index.htm /index.html /index.php
MX https:// komokaweather.com/cumulusmx4/index.htm
Image
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Re: Sites blocked by malware scanner

Post by HansR »

PaulMy wrote: Tue 18 Feb 2025 4:00 pm Thanks Hans, great follow up!
I did have a similar 'blocked IP' on my GoDaddy shared hosting last year but that eventually got cleaned up. So glad to hear it is now still fine.

Your advice to @Dador is good, but if the provider is like GoDaddy, then easier said than done.
If a provider does not act properly he is part of the problem so a good reason to move.
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
Post Reply