Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | thedivadeveloper.com #1120

Open
spottykay opened this issue Feb 9, 2025 · 3 comments
Open

False Positive | thedivadeveloper.com #1120

spottykay opened this issue Feb 9, 2025 · 3 comments
Assignees
Labels
bug Something isn't working false positive Should not be listed

Comments

@spottykay
Copy link

What are the subjects of the false-positive (domains, URLs, or IPs)?

  • thedivadeveloper.com

Why do you believe this is a false-positive?

I believe this is a false-positive because I have checked the website. It is secured and has a firewall and there is nothing malicious in the website.

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

I discovered this false-positive by...

Have you requested a review from other sources?

No

Do you have a screenshot?

Screenshot

Additional Information or Context

I have also noticed that...

@phishing-database-bot
Copy link
Member

Verification Required

@spottykay, thank you for submitting a false positive report! To help us verify your ownership of the affected domain(s), please complete the following steps:

  1. Set a DNS TXT record for the domain(s) listed in this issue with the following details:

    • Record Name: _phishingdb
    • Record Value: antiphish-d75546b5c2f5b64e26574b0d9d32f9c9c4cd9c05

    Your Verification ID: antiphish-d75546b5c2f5b64e26574b0d9d32f9c9c4cd9c05

  2. Wait for DNS propagation (this may take a few minutes to a few hours).

  3. Reply to this issue once the TXT record has been set.

Important Notes

  • Verification does not guarantee whitelisting. The Phishing.Database team will review your report after verifying ownership, but the decision to whitelist depends on further investigation and analysis.
  • If the record cannot be set or you need alternative methods of verification, please contact us at contact@phish.co.za - preferably from the domain's official email address.

How to Check the TXT Record ?

You can verify that the TXT record is properly set using:

Thank you for your cooperation! We will address your issue as soon as possible after verification.

The Phishing.Database Project Team.

@spirillen
Copy link
Contributor

known records

https://thedivadeveloper.com/img.html
curl -IL https://thedivadeveloper.com/img.html
HTTP/2 404

@spirillen
Copy link
Contributor

spirillen commented Mar 10, 2025

Comments

This domain was whitelisted in #1220 with Phishing-Database/phishing@90cd3e6

Please stop opening new + new + new + new issues, This is the issue regarding this domain, we don't really needs fifty issues regarding this domain.. we only lose the thread in what is happening.

And right now, you seems to have managed to return to the list for the third time in a very short period of time, which leads me to have little to no trust in your capabilities to manage a web server securely.

And then... here is something that do not adds up, and that ain't you, it's the repository versus hosted list floating around the net, and I doubt they are in control of what is happening... miss-managed systems are bad and dangerous.

Your domain is easily found in the hosted csv files from phish.co.za. A related bug report Phishing-Database/dev-center#21 and searching this repo, gives nothing...

spent 22m investigating

List source are equal, how are the lists distributed??

https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/ = https://phish.co.za/latest/ = https://raw.githubusercontent.com/Phishing-Database/Phishing.Database/refs/heads/master/

Which of the sources should we trust??

phishing_database/ALL-phishing-links.csv:thedivadeveloper.com
phishing_database/phishing.database/domain.csv:thedivadeveloper.com

DNS Check

Known phishing records

What can you tell me about these records, known to us from the PD project?

Subject                                                                                              Status      Source     Expiration Date   HTTP Code  Checker       Tested At          
---------------------------------------------------------------------------------------------------- ----------- ---------- ----------------- ---------- ------------- -------------------
https://thedivadeveloper.com/img.html                                                                INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  10. Mar 2025 11:36:49

Execution Time: 00:00:00:1.958546

Verdict

Upgrading this issue to a BUG that should be handled by @funilrys

Known Issues


Thank you for reaching out. I want to clarify that I am not the owner of this project nor user of it. I assist with the whitelisting of domains to the best of my ability, but I do this as an unpaid volunteer in my free time. Your understanding and patience are greatly appreciated.
Additionally, I would like to share that I occasionally struggle with a mild degree of PTSD, which means I tend to forget even small details, like did I have breakfast this morning. So please bare with me, if I'm loosing the thread sometimes. Your understanding and patience in this matter are greatly appreciated.

If you feel inclined to buy me a cup of coffee, it would certainly help speed up the process, but please know that it will not influence my decisions or verdicts in any way.

Additionally, I want to be very clear: I do not access any Cloudflare, CloudFront, or Google networks. This is a matter of principle for me, as I believe in upholding human rights, the right to online privacy, and network security. These services often intercept traffic to collect personally identifiable information (PII), which I believe compromises our autonomy and makes us all puppets to the big tech puppeteers.

Thank you for your understanding!

Best regards.

@spirillen spirillen added bug Something isn't working false positive Should not be listed labels Mar 10, 2025
@spirillen spirillen moved this from 🆕 New to 🚫 Blocked / Waiting in Phishing Database Backlog Mar 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working false positive Should not be listed
Projects
Status: 🚫 Blocked / Waiting
Development

No branches or pull requests

6 participants