I'm in a bit of a quandary over Norton Safe Web's rating of my company's website.
My question is: is it possible for someone to fool Norton Safe Web into thinking that our website has PHP files which don't exist? Could there be some sort of Spoofing going on, or could someone be manipulating a Norton tool on their machine to tell Norton Safe Web that our site has malicious files?
We host our own website on our in-house web server, and have properly configured firewalls up to layer 7. Mcafee scans our site every day for vulnerabilities and has found no such files, and Google Transparency Report does not report anything malicious.
None of the reported threatening links exist or (to my knowledge) have ever existed on our website. We stopped using PHP a long time ago, and yet Safe Web reports them on our website.
I've included the Threat Report below. I've only replaced my website with "MYWEBSITE" and removed the HTTP and WWW so it would not post as a link:
Drive-By Downloads: Threats found: 5
Threat Name: Web Attack: Wordpress Arbitrary File Download 4 Location: MYWEBSITE.com/wp-content/themes/TheLoft/download.php?file=../../../wp-config.php
Threat Name: Web Attack: Wordpress Arbitrary File Download 4 Location: MYWEBSITE.com/wp-content/plugins/history-collection/download.php?var=../../../wp-config.php
Threat Name: Web Attack: Wordpress Arbitrary File Download 4 Location: MYWEBSITE.com/wp-content/plugins/google-mp3-audio-player/direct_download.php?file=../../../wp-config.php
Threat Name: Web Attack: Joomla Component Local File Inclusion Location: MYWEBSITE.com/news/index.php?option=com_macgallery&view=download&albumid=../../web.config.txt
Threat Name: Web Attack: Wordpress Arbitrary File Download 4 Location: MYWEBSITE.com/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
Viruses: Threats found: 1
Threat Name: Web Attack: Joomla Component Local File Inclusion Location: MYWEBSITE.com/news/index.php?option=com_macgallery&view=download&albumid=././web.config.txt
Notice they are all PHP and mention WordPress and Joomla, NONE of which we have nor use.
We are in the process of disputing the report with Norton, but this is the second time that this has happened, and the dispute process is taking quite a while. Meanwhile people are being told that our website is not safe and we are losing customers. I know there is nothing more I can do to speed up the process with Norton, but I would like to understand how this is even possible and I would like to be able to prevent this type of thing reoccurring in the future.
So in summary, what I'm trying to understand is: is it possible for Norton Safe Web to have been tricked into giving a false report of our site, or is the only possibility that someone put a file on our site in time for Norton to scan then took it off before we found it?
I'll greatly appreciate any input. Thanks!