Traditional Chinese medicine believes that qi and blood stasis are caused by congestion in the body and obstruction of the vein. The symptoms of qi and blood stasis indicate fatigue, numbness, or cold. If a Web server is compromised by search engines and its access is restricted, it is like a congestion in the meridian, making the Web server unable to be normally accessed and providing services.
The following is a case:
Ms. Q is the CIO of an enterprise, but she is not happy at the moment, because she has just been reprimanded by the General Manager: users search for company sites on Google, "The website may contain malware that may harm your computer ". As a public enterprise, the website is the company's image on the Internet. It was prompted that malicious software was an intolerable mistake. So Ms. Q quickly recruited a security expert for analysis, according to experts' suggestions, the website vulnerability was fixed and the tip "little tail" was canceled. In order to avoid the "Small Tail", Ms. Q also purchased the website Trojan Detection Service, regularly checked the website pages, and deployed intrusion defense products as defense lines to block attacks.
Okay, so what is Google's little tail? Many people have seen this prompt. What does this prompt mean? This is a website warning that Google has partnered with stopbadware.org to identify malware as being published in the StopBadWare published guide StopBadWare.org malware website guide in the search results: this website may damage your computer.
When a website has a small Google tail, you need to take two steps to solve this problem. One is to enhance the system defense capability and avoid further attacks. The second is to apply to Google to remove this little tail.
Google's little tail is the most common form of XSS attacks. For more information about its defense methods, see XSS defense techniques. In this article, we mainly focus on step 2, how to apply for removing this little tail.
Note: StopBadware.org malware website Guide
The purpose of this Guide is to identify websites with malware problems, regardless of whether the problem is generated intentionally or through poor malware storage techniques. At the same time, some websites listing third-party links and programs are not overly criticized, because some bad links or software are obtained from well-designed networks.
1. General situation
A website is a malware website, if it stores or transmits malware and does not comply with the exceptions described in section 2. This includes, but is not limited to, websites that have any of the following actions:
◆ Directly store or spread malware on the website;
◆ Automatically redirects to a website hosting or spreading malware;
◆ Executable files linked to malware, whether stored on your own website or other websites;
◆ Link to another website that attempts to automatically install malware on the user's computer;
◆ Enable the browser to automatically load code from another website, and then attempt to install malware on the user's computer;
◆ A large number of links, whether in nature or quantity, to other websites that primarily store or spread malware.
2. Exceptions
◆ Exceptions of the preceding website Guide include, but are not limited:
◆ Download center that makes unremitting efforts to detect and delete malware;
◆ Websites or webpages engaged in legal and non-profit malware research or education;
◆ Automatic and Comprehensive Indexing websites
As an ordinary user, if you see that the site you are about to visit is hung with such a small tail and you are not sure you want to continue accessing the site, you may still have a shadow: the website is so insecure, product/service estimation is not good? This has a profound negative impact on enterprises.
What should I do if my tail appears? Because this small tail is caused by the existence of a website page or automatic jump/connection to a malicious software site, the most critical operation step is to clean up malicious code and links.
Note: clear malicious code and links
By searching the website source code, you can generally find embedded malicious code or malicious links. Note that these codes or links are usually displayed in hexadecimal notation and must be converted to a standard string for manual analysis and identification. In terms of selecting analysts, generally, website code developers can check malicious code or malicious links, as long as they find code unrelated to website functions, you can analyze it by converting it to a standard string.
After cleaning is completed, it does not mean that the work is completed. You need to perform the following two steps to completely remove the tail:
1. Apply for re-indexing at StopBadware.org.
2. Click "apply for review" in the "google website administrator tool"> "Cut off" option and fill in relevant information.
Note: The Link for re-indexing is http://stopbadware.org/home/reviewinfo. Google website administrator tool link: http://www.google.cn/webmasters.
Remove the tail corresponding to the case above, just as traditional Chinese medicine uses the method of promoting blood circulation and Removing Blood Stasis to restore the human body to normal, so that the website resumes normal. Of course, it is not enough to remove blood stasis. We also need to combine diet therapy, sports therapy, and other methods to enhance our physique. We are not enough to apply for removal of small tails by Google for Web servers, you also need to find the cause of the problem and enhance it accordingly. You can entrust a professional to provide comprehensive and professional security services.
Edit recommendations]