OpenCRE icon indicating copy to clipboard operation
OpenCRE copied to clipboard

zeljkoobrenovic.github.io - reported as unsafe

Open 5t00g1t opened this issue 1 year ago • 10 comments

Issue

This site has been reported as unsafe Hosted by zeljkoobrenovic.github.io Microsoft recommends you don't continue to this site. It has been reported to Microsoft for containing phishing threats which may try to steal personal or financial information.

What is the issue?

When clicking "Explore our catalog in one list" on the homepage that links to this page: zeljkoobrenovic.github.io am getting a Microsoft warning page.

Expected Behaviour

What should have happened?

Should link to a safe page.

Actual Behaviour

What actually happened?

Links to a page that has been flagged as containing phishing threats.

Steps to reproduce

How can we reproduce the error?

  • Go to homepage of opencre
  • Click Explore

5t00g1t avatar Jul 17 '24 13:07 5t00g1t

thank you for the issue! we are recreating the explorer here but haven't published it yet, it will be published soon

northdpole avatar Jul 21 '24 12:07 northdpole

My pleasure. Glad to help!

On Sun, 21 Jul 2024, 13:53 Spyros, @.***> wrote:

thank you for the issue! we are recreating the explorer here https://opencre.org/explorer but haven't published it yet, it will be published soon

— Reply to this email directly, view it on GitHub https://github.com/OWASP/OpenCRE/issues/528#issuecomment-2241600952, or unsubscribe https://github.com/notifications/unsubscribe-auth/AG74GPDTEOXUX3YA5NLUT5LZNOVM3AVCNFSM6AAAAABLAS5F26VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDENBRGYYDAOJVGI . You are receiving this because you authored the thread.Message ID: @.***>

5t00g1t avatar Jul 22 '24 17:07 5t00g1t

zeljkoobrenovic.github.io is @zeljkoobrenovic 's personal GitHub page. We can't update it.

dlicheva avatar Jul 23 '24 15:07 dlicheva

Hi All,

If you need any help with internalizing the explorer, please let me know. It is probably best if I archive my repository and website, and contribute to your developments.

Regarding the unsafe alert, I am curious if you have more details. I cannot reproduce it via Chrome or Safari. All the links in the site should be from the OpenCRE database only.

Thanks!

zeljkoobrenovic avatar Jul 23 '24 17:07 zeljkoobrenovic

Hi there,

I am only seeing the error when trying to access using MS Edge. I have clicked the link to report as safe. Perhaps others can do the same, including the page author?

See image below for error page.

image

All the best!

5t00g1t avatar Jul 24 '24 10:07 5t00g1t

zeljkoobrenovic.github.io is @zeljkoobrenovic 's personal GitHub page. We can't update it.

Completely understand, but given that this is one of the first links a user may click after arriving at the OpenCRE page it doesn't give the best first impression, especially given the nature of the OpenCRE project.

5t00g1t avatar Jul 24 '24 10:07 5t00g1t

Hi @zeljkoobrenovic , thanks for having a look! We're working on internalising the explorer, and your original work is important for reference, so please don't archive it yet :pray: For now, maybe we can move the link elsewhere in the page and have a look why Defender flags it up. This is a common issue for GitHub pages and we can mark it as false positive as described here.

dlicheva avatar Jul 25 '24 14:07 dlicheva

No problem, @dlicheva. I will keep it open until needed. FYI, I also put now a copy on my website https://obren.io/tools/opencre/, which may be a better link if GitHub pages are more frequently flagged as dangerous

zeljkoobrenovic avatar Jul 25 '24 14:07 zeljkoobrenovic

I've just opened the original link https://zeljkoobrenovic.github.io/opencre-explorer/ via Edge, and I do not get a red Defender screen anymore (yesterday it was there). Can you doublecheck?

zeljkoobrenovic avatar Jul 25 '24 15:07 zeljkoobrenovic

Not getting a warning on Edge on MacOS for that URL @zeljkoobrenovic

robvanderveer avatar Jul 28 '24 19:07 robvanderveer