# Parts of website blocked by Google Safe Browsing?

**URL:** <https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365>\
**Category:** SWI-Prolog web site and services\
**Created:** [October 7, 2019, 4:56pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365 "2019-10-07T16:56:01Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![fnogatz](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/fnogatz/32/19_2.png) [@fnogatz](https://swi-prolog.discourse.group/u/fnogatz)\
**Post date:** [October 7, 2019, 4:56pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/1 "2019-10-07T16:56:01Z")

</div>

Since today, parts of the SWI-Prolog website seem to be recognised as unsafe by Google Safe Browsing. The Google Safe Browsing report for Jan’s PhD (which I am sure will not install anything) can be found here: [https://transparencyreport.google.com/safe-browsing/search?url=https:%2F%2Fwww.swi-prolog.org%2Fdownload%2Fpublications%2Fjan-phd.pdf](https://transparencyreport.google.com/safe-browsing/search?url=https:%2F%2Fwww.swi-prolog.org%2Fdownload%2Fpublications%2Fjan-phd.pdf)

In Firefox, currently visiting the website results in a red alert message:

 ![Screenshot%20from%202019-10-07%2018-53-14](https://global.discourse-cdn.com/free1/uploads/swiprolog/original/1X/6d45e81e97ef762190954c2543769eb074074db5.png)

Is anyone familiar with this and how to get the false-positive fixed?

---

<div class="post-metadata">

**Author:** ![jamesnvc](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/jamesnvc/32/14_2.png) [@jamesnvc](https://swi-prolog.discourse.group/u/jamesnvc)\
**Post date:** [October 7, 2019, 5:51pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/2 "2019-10-07T17:51:05Z")

</div>

Following the various links on Mozilla’s page gets to [here](https://support.mozilla.org/en-US/kb/how-does-phishing-and-malware-protection-work?as=u&utm_source=inproduct#w_iaove-confirmed-that-my-site-is-safe-how-do-i-get-it-removed-from-the-lists) which says to use [this link](http://www.stopbadware.org/home/reviewinfo) to request removal of incorrect malware or [this one](http://www.google.com/safebrowsing/report_error/?tpl=mozilla) for phishing.

Unfortunately, the malware one says that if the report is from Google, you have to create a Google webmaster account to validate it, which seems pretty shakedown-y to me 😕

---

<div class="post-metadata">

**Author:** ![jan](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/jan/32/4_2.png) [@jan](https://swi-prolog.discourse.group/u/jan)\
**Post date:** [October 7, 2019, 7:05pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/3 "2019-10-07T19:05:50Z")

</div>

No fun. I got an alert from the university that Google found a malware file on the site. It didn’t specify which file. I checked that the .exe files were not compromised (that is not easy: on first upload the server takes an SHA256 hash for the file and regularly validate this still matches while the file and checksums are maintained under different accounts). Nothing wrong. So, it appears to me my PhD thesis which was generated in 2009 and the download file is still the same (says SHA256 comparing to the copy that is still on my machine).

For short, this is false alarm. How do we get rid of this?

---

<div class="post-metadata">

**Author:** ![jan](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/jan/32/4_2.png) [@jan](https://swi-prolog.discourse.group/u/jan)\
**Post date:** [October 7, 2019, 7:12pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/4 "2019-10-07T19:12:29Z")

</div>

I filed a complaint at [https://safebrowsing.google.com/safebrowsing/report\_error/?hl=en](https://safebrowsing.google.com/safebrowsing/report_error/?hl=en)

---

<div class="post-metadata">

**Author:** ![jan](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/jan/32/4_2.png) [@jan](https://swi-prolog.discourse.group/u/jan)\
**Post date:** [October 7, 2019, 8:50pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/5 "2019-10-07T20:50:49Z")

</div>

Registered as owner of the site. This reveals the culprits are supposed to be (added spaces not  
to create a link and get this blocked too).

- [https://www.swi-prolog.org/](https://www.swi-prolog.org/) download/devel/bin/swipl-8.1.13-1.x86.exe
- [https://www.swi-prolog.org/](https://www.swi-prolog.org/) download/devel/bin/swipl-8.1.14-1.x86.exe

Both files are fine. I complained trough the web interface, but the form doesn’t seem to suggest the option they may be wrong. We’ll see …

---

<div class="post-metadata">

**Author:** ![jan](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/jan/32/4_2.png) [@jan](https://swi-prolog.discourse.group/u/jan)\
**Post date:** [October 8, 2019, 7:24am UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/6 "2019-10-08T07:24:16Z")

</div>

The site is still black (well, red). Google still reports these files as malware. [https://www.stopbadware.org/clearinghouse/search](https://www.stopbadware.org/clearinghouse/search) however (which seems behind FFs alert) says it knows nothing about [https://www.swi-prolog.org](https://www.swi-prolog.org), with or without `/download/devel`

I recall there is some site where you can get an overview of all malware scanners for a url. Does anyone know about this?

---

<div class="post-metadata">

**Author:** ![richard.siddall](https://avatars.discourse-cdn.com/v4/letter/r/e0b2c6/32.png) [@richard.siddall](https://swi-prolog.discourse.group/u/richard.siddall)\
**Post date:** [October 8, 2019, 12:32pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/7 "2019-10-08T12:32:42Z")

</div>

VirusTotal runs a URL through a slew of anti-virus products:  
[https://www.virustotal.com/gui/home/url](https://www.virustotal.com/gui/home/url)

---

<div class="post-metadata">

**Author:** ![jan](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/jan/32/4_2.png) [@jan](https://swi-prolog.discourse.group/u/jan)\
**Post date:** [October 8, 2019, 1:56pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/8 "2019-10-08T13:56:48Z")

</div>

Thanks Richard. That was what I was looking for. Says 2 out of 71 scanners do not like the 8.1.14 exe and classify it as _phishing_ and _malicious_. That (to me) confirms there is no real problem.

I don’t seem to be able to get Google to listen though. I have claimed ownership on the site. That allows to report, but not really that they got it wrong ☹ I tried to add a fair description on the process, but that was apparently too long. So I just asked them to properly review the file ASAP.

This is really bad. Except for stopping with Windows binaries I see no option to fix this for once and forever though ☹

---

<div class="post-metadata">

**Author:** ![jan](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/jan/32/4_2.png) [@jan](https://swi-prolog.discourse.group/u/jan)\
**Post date:** [October 9, 2019, 7:40am UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/9 "2019-10-09T07:40:23Z")

</div>

Seems somehow something/someone corrected this! I fear it will happen again ☹

---

<div class="post-metadata">

**Author:** ![damons](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/damons/32/430_2.png) [@damons](https://swi-prolog.discourse.group/u/damons)\
**Post date:** [October 11, 2019, 4:10pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/10 "2019-10-11T16:10:20Z")

</div>

It’s back. At least for 8.1.15 dev release on OS X.

---

<div class="post-metadata">

**Author:** ![BenEngbers](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/benengbers/32/95_2.png) [@BenEngbers](https://swi-prolog.discourse.group/u/BenEngbers)\
**Post date:** [October 11, 2019, 4:22pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/11 "2019-10-11T16:22:42Z")

</div>

Probably related to this…  
While building swi from source, I saw a warning that the location of the config file has moved. For further information, I should look to “[https://swi-prolog.org/modified/config-files.html](https://swi-prolog.org/modified/config-files.html)”.  
When browsing to this page, I first got a notification that it was insecure. And after ignoring that warning, nginx reproted " 502 Bad Gateway"

Ben

---

<div class="post-metadata">

**Author:** ![fnogatz](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/fnogatz/32/19_2.png) [@fnogatz](https://swi-prolog.discourse.group/u/fnogatz)\
**Post date:** [October 14, 2019, 9:11am UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/12 "2019-10-14T09:11:42Z")

</div>

This looks more like a configuration mistake for me. @jan, adding `swi-prolog.org` as a server alias for `www.swi-prolog.org` in nginx should be enough to fix this. (Note: hopefully your SSL certificate was created for `swi-prolog.org` with as well as without `www`, otherwise you need an additional server configuration…)

---

<div class="post-metadata">

**Author:** ![richard.siddall](https://avatars.discourse-cdn.com/v4/letter/r/e0b2c6/32.png) [@richard.siddall](https://swi-prolog.discourse.group/u/richard.siddall)\
**Post date:** [October 14, 2019, 3:34pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/13 "2019-10-14T15:34:41Z")

</div>

There are several things going on:

- [www.swi-prolog.org](http://www.swi-prolog.org) is served via the content delivery network that  
Fastly donates to the project. [swi-prolog.org](http://swi-prolog.org) is not.

- [swi-prolog.org](http://swi-prolog.org) is serving up a TLS certificate that does not contain  
[swi-prolog.org](http://swi-prolog.org) as a SAN, resulting in a mismatch warning in the browser.

- If you ignore the mismatch warning and continue to the site, you get  
an Nginx 502 “Bad Gateway” error, i.e. the [swi-prolog.org](http://swi-prolog.org) web site is down.

- While [https://swi-prolog.org/modified/config-files.html](https://swi-prolog.org/modified/config-files.html) does not work,  
[https://www.swi-prolog.org/modified/config-files.html](https://www.swi-prolog.org/modified/config-files.html) does

---

<div class="post-metadata">

**Author:** ![richard.siddall](https://avatars.discourse-cdn.com/v4/letter/r/e0b2c6/32.png) [@richard.siddall](https://swi-prolog.discourse.group/u/richard.siddall)\
**Post date:** [October 14, 2019, 3:35pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/14 "2019-10-14T15:35:36Z")

</div>

Wikipedia says Virustotal is owned by Google, so it is possible they use  
Virustotal as part of Safe Browsing.

We could upload new Windows binaries to Virustotal for scanning. There’s  
an API, so potentially uploading could be automated. (There’s a slight  
complication for files greater than 32MB…)

The API also has a domain report. We may be able to use that to find  
problems with [www.swi-prolog.org](http://www.swi-prolog.org) before Falco does ;\>

---

<div class="post-metadata">

**Author:** ![jan](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/jan/32/4_2.png) [@jan](https://swi-prolog.discourse.group/u/jan)\
**Post date:** [October 15, 2019, 1:40am UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/15 "2019-10-15T01:40:06Z")

</div>

That is an interesting thought. I wonder how vendors deal with this in general. Produce a random Windows binary and it seems it is likely that a couple of virus/malware scanners trigger. I vaguely recall that checking at Google, it was claimed MacAffe was one of the two complaining scanners, while virustotal had two others. Our binary is only 12Mb, so that is fine 🙂

If someone knows how to deal with this, please share!

---

<div class="post-metadata">

**Author:** ![anniepoo](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/anniepoo/32/12_2.png) [@anniepoo](https://swi-prolog.discourse.group/u/anniepoo)\
**Post date:** [October 24, 2019, 3:48am UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/16 "2019-10-24T03:48:16Z")

</div>

for what its worth, we’ve had our first confirmed case of someone using something else because of this. It’s certainly not the actual first time - I’m sure we’re hemmorhaging users - but found a user on twitter who reports he used GNU-Prolog as a result of the warning. Ran into multiple issues, and got a copy of SWI-Prolog by using MS Edge, Microsoft’s new name for Internet Explorer.

---

<div class="post-metadata">

**Author:** ![jan](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/jan/32/4_2.png) [@jan](https://swi-prolog.discourse.group/u/jan)\
**Post date:** [October 25, 2019, 2:08am UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/19 "2019-10-25T02:08:11Z")

</div>

That was to be expected. In the days before a CDN when we kept track of downloads there were over 500 per day. Probably more now. If you hit a red alert page it will be less ☹

---

<div class="post-metadata">

**Author:** ![jan](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/jan/32/4_2.png) [@jan](https://swi-prolog.discourse.group/u/jan)\
**Post date:** [October 25, 2019, 2:19am UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/20 "2019-10-25T02:19:31Z")

</div>

Seems we are blocked again, now all three download pages ☹ I can’t do much as my internet connection is _really_ slow ☹

---

<div class="post-metadata">

**Author:** ![peter.ludemann](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/peter.ludemann/32/48_2.png) [@peter.ludemann](https://swi-prolog.discourse.group/u/peter.ludemann)\
**Post date:** [October 25, 2019, 2:42am UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/21 "2019-10-25T02:42:02Z")

</div>

Does it make sense to delete all the \*.EXE files and point to another site ([swi-prolog-win.org](http://swi-prolog-win.org)) containing them (with an explanation that some virus scanners incorrectly flag them)?

---

<div class="post-metadata">

**Author:** ![damons](https://yyz2.discourse-cdn.com/free1/user_avatar/swi-prolog.discourse.group/damons/32/430_2.png) [@damons](https://swi-prolog.discourse.group/u/damons)\
**Post date:** [October 25, 2019, 3:22pm UTC](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365/22 "2019-10-25T15:22:35Z")

</div>

This will kill swi-prolog. Is there any way others can help with this?

[Next page](https://swi-prolog.discourse.group/t/parts-of-website-blocked-by-google-safe-browsing/1365.md?page=2)
