Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | kilpatrickexecutive.com #1128

Open
WasimAlhalabi opened this issue Feb 12, 2025 · 16 comments
Open

False Positive | kilpatrickexecutive.com #1128

WasimAlhalabi opened this issue Feb 12, 2025 · 16 comments
Assignees
Labels
bug Something isn't working

Comments

@WasimAlhalabi
Copy link

What are the subjects of the false-positive (domains, URLs, or IPs)?

Why do you believe this is a false-positive?

I believe this is a false-positive because... we have checked the website with many tools and our technical team reviewed the website there is no issue even when you used www.kilpatrickexecutive.com there were no issues such as this:
https://www.virustotal.com/gui/url/4548124669f45c1bd6f5b8cb46b2128dec8ecee8467a890feb23a442645218c1

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

I discovered this false-positive by...

Have you requested a review from other sources?

I have requested a review from... https://www.phishtank.com/index.php but we didn't find any issue

Do you have a screenshot?

Screenshot Image Image

Additional Information or Context

I have also noticed that...

@phishing-database-bot
Copy link
Member

Verification Required

@WasimAlhalabi, thank you for submitting a false positive report! To help us verify your ownership of the affected domain(s), please complete the following steps:

  1. Set a DNS TXT record for the domain(s) listed in this issue with the following details:

    • Record Name: _phishingdb
    • Record Value: antiphish-e82e2a1999dc18d0d3a90bc197a897e34e54ffea

    Your Verification ID: antiphish-e82e2a1999dc18d0d3a90bc197a897e34e54ffea

  2. Wait for DNS propagation (this may take a few minutes to a few hours).

  3. Reply to this issue once the TXT record has been set.

Important Notes

  • Verification does not guarantee whitelisting. The Phishing.Database team will review your report after verifying ownership, but the decision to whitelist depends on further investigation and analysis.
  • If the record cannot be set or you need alternative methods of verification, please contact us at [email protected] - preferably from the domain's official email address.

How to Check the TXT Record ?

You can verify that the TXT record is properly set using:

Thank you for your cooperation! We will address your issue as soon as possible after verification.

The Phishing.Database Project Team.

@WasimAlhalabi
Copy link
Author

WasimAlhalabi commented Feb 12, 2025 via email

@spirillen
Copy link
Contributor

@funilrys, this is a very good example of what is happening when you misconfiguration the issue templates... and using value where only placeholder should have been used


ptcheck kilpatrickexecutive.com antiphish-e82e2a1999dc18d0d3a90bc197a897e34e54ffea
The test value matches the DNS TXT record.

Thanks for using my tools.
Please consider a sponsor ship at https://www.mypdns.org/donate

@spirillen spirillen added the bug Something isn't working label Feb 12, 2025
@spirillen
Copy link
Contributor

Search results

Lookup provided by My Privacy DNS

Hosts-Sources

External Hosts-Sources can be found here

phishing_database/ALL-phishing-links.csv:kilpatrickexecutive.com
phishing_database/phishing.database/domain.csv:kilpatrickexecutive.com

Sorted result

EasyList

Matrix blacklist project

Matrix blacklist project, Filtered

Response Policy Zone - RPZ

Did not find any matching RPZ records

Known Issues

rgxRecord: kilpatrickexecutive.com

DNS lookup

ns1.dns-parking.com.
ns2.dns-parking.com.

HTTP header

HTTP response, click to expand

@spirillen
Copy link
Contributor

Hmm, can see you are using dns-parking.com, isn't those DNS server solely used to serve hijacked expired domains?

@spirillen
Copy link
Contributor

spirillen commented Feb 12, 2025

curlx -IL kilpatrickexecutive.com
HTTP/1.1 403 Forbidden

And since the domain ain't public available we can't test or verify is classification status.

write back, if you decide to make your intranet domain a public available website.

@WasimAlhalabi
Copy link
Author

The DNS Server we are using is Hostinger, also the website is public https://www.kilpatrickexecutive.com

Image

@spirillen
Copy link
Contributor

The access to the domain is still prohibited, I'll pass the issue to the next in line. To whom think they can access your intranet site, I only have access to public domains.

curlx -IL kilpatrickexecutive.com
HTTP/1.1 403 Forbidden
Date: Thu, 13 Feb 2025 13:42:44 GMT
Content-Type: text/html
Content-Length: 4792
Connection: keep-alive
Vary: Accept-Encoding
Cross-Origin-Embedder-Policy: require-corp
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Permissions-Policy: accelerometer=(),autoplay=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=()
Referrer-Policy: same-origin
X-Frame-Options: SAMEORIGIN
Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Server: hcdn
alt-svc: h3=":443"; ma=86400
x-hcdn-request-id: 7eaf0188975232baf91e620e71c956cc-srv-edge4
kilpatrickexecutive.com.        172800  IN      NS      ns1.dns-parking.com.
kilpatrickexecutive.com.        172800  IN      NS      ns2.dns-parking.com.
kilpatrickexecutive.com.        60      IN      A       77.37.83.177

@spirillen spirillen removed their assignment Feb 13, 2025
@WasimAlhalabi
Copy link
Author

I have disable the firewall temporary, now you can check the website public, please let me know when you fix the issue for phishing database, thanks
Image

@spirillen
Copy link
Contributor

spirillen commented Feb 13, 2025

Please enable the firewall once again...

do you have some script running in the ISS that are turning your website into a intranet site, preventing the whitenet of TOR, while allowing the SpyNet full access?

PS: still get 403 with curl over tor-network

If you prefer we can take this talk more privately for keeping security in mind at @spirillen:matrix.org or https://mypdns.youtrack.cloud OR https://mypdns.youtrack.cloud/issue/PD-1273 (can set acl on who can read comments there)

@WasimAlhalabi
Copy link
Author

WasimAlhalabi commented Feb 14, 2025

@spirillen no we do not have any script running in the ISS that is turning our website, PLease remove our website from your Database, that was an old issue for 4 years and we don't have such a thing right now.

CRDF Labs confirmed removed as well
Image

https://www.urlvoid.com/scan/kilpatrickexecutive.com/

@WasimAlhalabi
Copy link
Author

One more thing the website is clean with www as you can see in the following:
https://www.virustotal.com/gui/url/ee4ffcf4402f4422d5ea8952f9a78b2149b690553edd8547da11cd776e88c31

@spirillen
Copy link
Contributor

no we do not have any script running in the ISS that is turning our website

I would like to challenge that 100%

curlx is just a alias for alias curlx='curl -x socks5h://localhost:9050 '= Tor proxy

curlx -IL kilpatrickexecutive.com
HTTP/1.1 403 Forbidden
Date: Fri, 14 Feb 2025 09:33:39 GMT
Content-Type: text/html
Content-Length: 4792
Connection: keep-alive
Vary: Accept-Encoding
Cross-Origin-Embedder-Policy: require-corp
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Permissions-Policy: accelerometer=(),autoplay=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=()
Referrer-Policy: same-origin
X-Frame-Options: SAMEORIGIN
Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Server: hcdn
alt-svc: h3=":443"; ma=86400
x-hcdn-request-id: c0d564426768a9b439dbe46baab681fd-int-edge3

This proves you are blocking the tor network 100%, weather you are aware about it, despite my earlier proves. But as it turns out you are using WordPress, you might have a addon blocking your visitors from enter your website, costing you money at the end of the day.

curl -IL kilpatrickexecutive.com
HTTP/1.1 301 Moved Permanently
Date: Fri, 14 Feb 2025 09:33:43 GMT
Content-Type: text/html
Content-Length: 795
Connection: keep-alive
location: https://kilpatrickexecutive.com/
platform: hostinger
panel: hpanel
content-security-policy: upgrade-insecure-requests
Server: hcdn
alt-svc: h3=":443"; ma=86400
x-hcdn-request-id: 3b1a9285d579a5ef6a76029201d97392-srv-edge3
x-hcdn-cache-status: MISS
x-hcdn-upstream-rt: 0.029

HTTP/2 301 
date: Fri, 14 Feb 2025 09:33:43 GMT
content-type: text/html; charset=UTF-8
content-length: 0
location: https://www.kilpatrickexecutive.com/
x-powered-by: PHP/7.4.33
x-dns-prefetch-control: on
expires: Thu, 13 Feb 2025 15:42:10 GMT
cache-control: max-age=3600
x-redirect-by: WordPress
x-litespeed-cache: hit
platform: hostinger
panel: hpanel
content-security-policy: upgrade-insecure-requests
age: 67842
server: hcdn
alt-svc: h3=":443"; ma=86400
x-hcdn-request-id: e5be6046a22112f60ae7afd05213729e-srv-edge3
x-hcdn-cache-status: HIT

HTTP/2 200 
date: Fri, 14 Feb 2025 09:33:43 GMT
content-type: text/html; charset=UTF-8
vary: Accept-Encoding
x-powered-by: PHP/7.4.33
x-dns-prefetch-control: on
link: <https://www.kilpatrickexecutive.com/wp-json/>; rel="https://api.w.org/"
link: <https://www.kilpatrickexecutive.com/wp-json/wp/v2/pages/4>; rel="alternate"; title="JSON"; type="application/json"
link: <https://www.kilpatrickexecutive.com/>; rel=shortlink
x-litespeed-cache: hit
platform: hostinger
panel: hpanel
content-security-policy: upgrade-insecure-requests
age: 38069
server: hcdn
alt-svc: h3=":443"; ma=86400
x-hcdn-request-id: d831967146daffd1e07c74e3d7c9b039-srv-edge5
x-hcdn-cache-status: HIT

@spirillen
Copy link
Contributor

Fingerprinting?? sure looks like it

Image

I have to parse this issue to someone else. I do not have possibilities to test your site, as I literately concerned about my privacy and network security doing so

@WasimAlhalabi
Copy link
Author

WasimAlhalabi commented Feb 14, 2025

Yes we have a plugin to protect our WordPress website, All In One WP Security and Firewall, what is the issue if this is protecting the Tor network, we are asking about the phishing database, if there is no phishing now please remove the website from the database
Thanks

@spirillen
Copy link
Contributor

what is the issue if this is protecting the Tor network

You’re not protecting anything; you’re actually preventing human rights, freedom, and democracy by only letting the big five surveillance companies’ meta sheep's in.
I’m a legitimate user of the privacy-focused Tor network, and when you lock the door, I can’t access your domain or website. So, you’re just waiting for a big tech sheep to access your compromised network. I refuse to do that unless you disable and uninstall your anti-democracy add-on.

You’ve withheld information about blocking access to a network that stands for freedom, and I’ve asked you about it directly!

You're right; I'm done playing nice. I feel like I've wasted an hour of my free, unpaid time trying to help you solve your issue, and it's incredibly frustrating.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
Status: 🆕 New
Development

No branches or pull requests

6 participants