Welcome, Guest. Please login or register.
March 11, 2010, 11:40:54 PM

Login with username, password and session length

370143 Posts
40950 Topics
93346 Members

Latest Member: Raman

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  InstantSSL flagged as "Engaged in malware distribution" by hpHosts
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: InstantSSL flagged as "Engaged in malware distribution" by hpHosts  (Read 2378 times)
dominumds
Newbie
*
Offline Offline

Posts: 21



WWW
« on: December 12, 2009, 01:03:23 PM »

Hi there,
I noticed today at an AV company's forums that they were not recommending COMODO Firewall due to it installing HopSurf toolbar, (blah blah blah...)
They also quoted an article from hpHosts blog...
And when I took a look at hpHosts database...
Quote
Database Record
IP On Record:    91.199.212.132 (3)
IPOR PTR:    secure.comodo.net
Added:    Not recorded
Added By:    hpHosts
Updated:    12-12-2009
Classification:    EMD (What is this?)

I honestly don't know what to think of Comodo, Melih and everyone now...

(But I'm gonna stick with my beloved COMODO Personal Firewall, and nothing is going to change that)
Logged
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 1069


Reality is subordinate to perception


WWW
« Reply #1 on: December 12, 2009, 02:06:02 PM »

Well I just took a look at hpHosts database too.



After reading your post I believe they updated their DB very quickly! (hpHosts query on secure.comodo.net)
« Last Edit: December 12, 2009, 02:17:07 PM by Endymion » Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
dominumds
Newbie
*
Offline Offline

Posts: 21



WWW
« Reply #2 on: December 12, 2009, 02:20:10 PM »

I supposed you'd say that  Grin
Comodo.com is NOT listed.
secure.comodo.com is listed indirectly because it is the reverse pointer for the sites in the screenshots  Huh
« Last Edit: December 12, 2009, 02:23:36 PM by dominumds » Logged
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 1069


Reality is subordinate to perception


WWW
« Reply #3 on: December 12, 2009, 03:17:00 PM »

I supposed you'd say that  Grin
Comodo.com is NOT listed.
secure.comodo.com is listed indirectly because it is the reverse pointer for the sites in the screenshots  Huh
Thanks for pointing that out.

Yet secure.comodo.com is not listed as EMD in hphosts too.

EDIT 1: InstantSSL.com and trusttoolbar.com appear to be listed as EWD.

EDIT 2: InstantSSL.com and trusttoolbar.com are not listed as EWD anymore.

EDIT 3: I've seen your screenshoots.

Yet strange I'm not able to find any application that can be downloaded on InstantSSL.com though I found a trusttoolbar topic in these forums and I come to understand was confirmed to be perfectly safe...

...thus the related trusttoolbar.com domain appear to have bee erroneously classified probably like instantssl.com.

Out of curiosity I checked hopsurf.com as well since you mentioned the related toolbar in you first post...

...and I was not surprised to find no EMD classification for that domain as well.
« Last Edit: December 12, 2009, 05:39:16 PM by Endymion » Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
dominumds
Newbie
*
Offline Offline

Posts: 21



WWW
« Reply #4 on: December 12, 2009, 03:20:36 PM »

That was exactly what I was thinking =)
For you, me and everyone here, that app may be perfectly safe, but for some people (aka hpHosts) it is malware/spyware/adware.
Do take a look at hpHosts blog, it seems to have quite a lot of articles about COMODO Wink
Logged
AyeAyeCaptain
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 318


« Reply #5 on: December 12, 2009, 03:35:49 PM »

That was exactly what I was thinking =)
For you, me and everyone here, that app may be perfectly safe, but for some people (aka hpHosts) it is malware/spyware/adware.
Do take a look at hpHosts blog, it seems to have quite a lot of articles about COMODO Wink

It's in other peoples interests (other companys) to bad mouth, find fault, or just plain put down another business. Can't say I've seen/heard COMODO do the same, after all they help others in the security iindustry.

Regardless of anything, I'm happy with COMODO and will continue to trust them in their efforts to keep me safe.

Kind of off topic (don't see it as a rant) but just as a general reply of opinion, I can't go too technical like you can too much....yet.

 Thumb Up
Logged

Film Scum Remake
Comodo: Where is your Tool
User: What Tool?
Comodo: This f****** Tool.
Protect Yourself With Comodo...... lol
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 1069


Reality is subordinate to perception


WWW
« Reply #6 on: December 12, 2009, 03:35:49 PM »

That was exactly what I was thinking =)
For you, me and everyone here, that app may be perfectly safe, but for some people (aka hpHosts) it is malware/spyware/adware.
Do take a look at hpHosts blog, it seems to have quite a lot of articles about COMODO Wink

Well I hope many will at least be aware of the difference between malware, spyware and adware before listening to anything they're told anywhere by anybody.  Thumb Up

I'm quite selective about my sources of informations but I might have taken a look hpHosts blog like you suggested if you would have considered it to be authoritative enough in that regard  Wink

Meantime I'll get some spare time to read http://giveupinternet.com/ sure a noteworthy source of humor (IMHOGrin
« Last Edit: December 12, 2009, 04:16:55 PM by Endymion » Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 1069


Reality is subordinate to perception


WWW
« Reply #7 on: December 12, 2009, 04:33:06 PM »

That was exactly what I was thinking =)
EDIT: Interesting enough instantssl.com and trusttoolbar.com featured in your screen-shots appear to be removed from hphosts.


EDIT: The "This site is not listed ....." notice, applied to instantssl.com only, it didn't apply to www.instantssl.com




Though I still see an EMD classification like that in your screenshot mentioned...
EDIT: It didn't last long...  Thumb Up

I'll check again later:
http://hosts-file.net/default.asp?s=trusttoolbar.com
http://hosts-file.net/default.asp?s=instantssl.com

EDIT: the appropriate query should have been http://hosts-file.net/default.asp?s=www.instantssl.com
« Last Edit: December 13, 2009, 03:53:11 PM by Endymion » Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 1069


Reality is subordinate to perception


WWW
« Reply #8 on: December 12, 2009, 05:09:04 PM »

Trustoolbar.com got a red mark again...
Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
MysteryFCM
Comodo Member
**
Offline Offline

Posts: 34

Phishin' Phanatic!


WWW
« Reply #9 on: December 12, 2009, 08:15:43 PM »

Let's clear this up shall we?

1. comodo.com, comodo.net, secure.* aren't listed in hpHosts (and haven't been for well over 12 months if memory serves)

2. If you look at the information provided, it clearly states "www.instantssl.com is listed with the WWW prefix only", which means it is NOT listed as simply "instantssl.com".

Quite why this is, I've no idea as both instantssl.com and trusttoolbar.com, were added prior to my taking over the project in 2006 (as shown by the lack of an "Added" date), however, I am satisfied that instantssl.com should not be listed, and it will be removed as soon as I've posted this.

3. trusttoolbar.com and www.trusttoolbar.com are both listed in hpHosts (quite why you've got a screenshot showing otherwise, is puzzling), as shown here;

http://hosts-file.net/?s=91.199.212.132&view=matches

The reason they've not been removed is due to;

http://www.virustotal.com/analisis/71497cf61838fd9c9164dec931615c2c6053513a1793e803313dfb962793b236-1260649565

4. Unless it states "This site is currently listed in hpHosts", the site is NOT listed.

5. IP PTR's aren't listed unless querying it explicitly states otherwise (i.e. the IP PTR for trusttoolbar.com is secure.comodo.net, but secure.comodo.net is NOT listed in hpHosts, as shown by this).

Which means, the following, quoted from a post above, is incorrect, there is no "indirectly" with hpHosts, it's either listed, or it isn't (in which case, see #4).

Quote
secure.comodo.com is listed indirectly because it is the reverse pointer for the sites in the screenshots

6. If a domain is listed, but the "Added" field states "Not recorded", then it was added before I took over the project, in which case, do feel free to point me to it.

I'm curious as to why no-one felt it necessary to contact me with these queries, and instead decided to speculate, but never the less, if you've got any further queries regarding this, or indeed, any other site listed in hpHosts, I'll be happy to answer them.
Logged

Regards
Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
dominumds
Newbie
*
Offline Offline

Posts: 21



WWW
« Reply #10 on: December 12, 2009, 08:36:32 PM »

Honestly, I never knew that hpHosts was not originally your project... that explains the weird "not recorded" about the adding date.
I could have contacted you when I got to know about this, but I didn't know if I could PM you at MBAM's forums about this (MBAM was how I got to know about instantssl.com's blocking). That was the easiest way for me to do it  Grin

My sincere apologies to you and everyone here for this situation.  Angel
Logged
MysteryFCM
Comodo Member
**
Offline Offline

Posts: 34

Phishin' Phanatic!


WWW
« Reply #11 on: December 12, 2009, 08:39:23 PM »

No apology necessary.

hpHosts was originallu ran by hpGuru.
Logged

Regards
Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 1069


Reality is subordinate to perception


WWW
« Reply #12 on: December 12, 2009, 08:40:20 PM »


Are the critera for inclusion publicly documented somewhere?

According to trusttoolbar.exe certificate the toolbar has been available since 2005.  Yet 37 out of 41 virustotal featured Antiviruses still don't list it yet. Wouldn't be that a reason for removal?
« Last Edit: December 12, 2009, 09:00:20 PM by Endymion » Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
MysteryFCM
Comodo Member
**
Offline Offline

Posts: 34

Phishin' Phanatic!


WWW
« Reply #13 on: December 12, 2009, 08:44:27 PM »

The FSA criteria is published in the hpHosts forums, but I've not published the rest, other than here as I thought the rest were self explanatory.

I'll make a note to test it on Monday and will base the removal decision on the results.
Logged

Regards
Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 1069


Reality is subordinate to perception


WWW
« Reply #14 on: December 12, 2009, 08:57:36 PM »

2. If you look at the information provided, it clearly states "www.instantssl.com is listed with the WWW prefix only", which means it is NOT listed as simply "instantssl.com".
Though looks that while the query was run against instantssl.com the result matched www.instantssl.com.

EDIT: The "This site is not listed ....." notice, applied to instantssl.com only, it didn't apply to www.instantssl.com

Can you please clarify further? was that match not supposed to occur?  Huh
« Last Edit: December 13, 2009, 03:38:31 PM by Endymion » Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.087 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com