Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add heylink.me domains to falsepositives #539

Conversation

modgahead
Copy link
Contributor

@modgahead modgahead commented Dec 20, 2024

Phishing Domain/URL/IP(s):

heylink.me
app.heylink.me
heyl.ink

Impersonated domain

heylink.me
app.heylink.me
heyl.ink

Describe the issue

Greetings!

Our website https://heylink.me/ is currently marked as a "phishing" in Phishing.Database.
Requested domains are properties of our company

Our web application provides convenient tools for about 8M registered users worldwide to create their public pages. Some of them are publishing inappropriate stuff from time to time and our tech team is doing a lot of things to moderate the user content and clean it from spam, phishing and other inappropriate behaviours that breach our T&C.

We support your vision of a clean and safe Internet. We will be glad to cooperate with you in order to sort it out.

Thank you for your kind attention,

Serg HeyLink.me Tech Team Lead

[email protected]

@modgahead modgahead marked this pull request as ready for review December 20, 2024 13:05
spirillen added a commit to mypdns/matrix that referenced this pull request Dec 21, 2024
spirillen added a commit to mypdns/matrix that referenced this pull request Dec 21, 2024
@spirillen
Copy link
Contributor

Some problematic uri's within/using your domain

https://heylink.me/att
https://heylink.me/websamazons?=hcbRHvHf (Solved by you)
http://whatsapps7.duckdns.org/login/?utm_medium=social&utm_source=heylink.me
https://heyl.ink/XSlp3 (Solved by you)

Conclusion: need more info about https://heylink.me/att

Time spend, 32 min

@kyrylo1
Copy link

kyrylo1 commented Dec 21, 2024

@spirillen https://heylink.me/att
When you open it you will receive deactivation page: "This account has been suspended due to violation of HeyLink.me terms & policies"
So it was already deactivated; can you please kindly review?

@modgahead
Copy link
Contributor Author

@spirillen

Thank you for reviewing these entries.
As @kyrylo1 mentioned, https://heylink.me/att has already been deactivated.

Regarding the URL http://whatsapps7.duckdns.org/login/?utm_medium=social&utm_source=heylink.me, that domain (whatsapps7.duckdns.org) is not under our control nor is it associated with our platform. It merely appears that someone used heylink.me as part of the utm_source parameter in their query string. We've also blocked whatsapps7.duckdns.org within our application to prevent anyone from adding links referencing it.

If you have any additional questions, please let us know. We'll be happy to provide further clarifications.

@spirillen
Copy link
Contributor

@spirillen https://heylink.me/att When you open it you will receive deactivation page: "This account has been suspended due to violation of HeyLink.me terms & policies" So it was already deactivated; can you please kindly review?

Well I got a time out on the connection..., that's why I need more info as I gets/got suspicious to what's happening.

Thinking 🤔 I'll get back when I've been looking a bit deeper in your domains as I personally would prefer NOT to whitelist url_shortners of any kind, as they tent to be abused.

I would rather like to have this project + @PyFunceble + you to cooperate to make rules for PyFunceble by making special rules like this one funilrys/PyFunceble#411 and as mentioned in #538 using the right HTTP code's, you can all benefit from this.

@kyrylo1
Copy link

kyrylo1 commented Dec 21, 2024

@spirillen with all due respect, we are not a URL shortener. We are link in bio platform with over 8M customers globally.
For example, this is my page: https://heylink.me/kyrylo
We monitor every link and every page and react on it.

Regarding https://heylink.me/att => it redirects to https://heylink.me/deactivated/
Screenshot 2024-12-21 at 7 01 15 PM

@modgahead please jump in on the tech part
On the business part we need to resolve it asap please as we have complaints from partners.

@kyrylo1
Copy link

kyrylo1 commented Dec 21, 2024

@spirillen
Could you kindly review this matter again?
From my perspective, all the links in question have been deactivated, and none of the other security vendors appear to be flagging them. Security remains a priority for us, and we continually work on it.

Given the increased volume of customer queries during the festive season, I’ve stepped in to assist with this as COO. Your support is greatly appreciated.
All my details here: https://heylink.me/kyrylo (if I can assist somehow)

@spirillen
Copy link
Contributor

we are not a URL shortener.

OK, not just that clear from the top of you site, but I understand now, that you are more like a link in, thing-ish., will solve this later in @mypdns.

However, the feature of adding link to what ever, is where the potential problem can arise. and the reason I personally would prefer setting up a special rule in PyFunceble, to have the backend taking care of these things.

So If you foe example add a HTTP code 410 to the deleted/removed account pages before redirecting, then PyFunceble can pick this on up, and remove links/domains from this project. If you are open to work out a way we can do this, I'm open to make a temporary whitelisting of your domain til a special rule are merged and distributed (Released) with the next version of PyFunceble

@kyrylo1
Copy link

kyrylo1 commented Dec 21, 2024

@spirillen ok; if that's your recommendation - we will implement it.
@modgahead will update once done; fingers crossed today.

@modgahead
Copy link
Contributor Author

@spirillen Hello! We've deployed a fix so that any deactivated pages now respond with an HTTP 410 Gone status code. Thank you for bringing this to our attention.

Example: https://heylink.me/att

@spirillen spirillen merged commit 0d43a78 into Phishing-Database:master Dec 21, 2024
spirillen added a commit to foreign-affairs/PyFunceble that referenced this pull request Dec 21, 2024
When this riles are merged and deployed we should remove whitelisting from Phishing-Database/phishing#539
@spirillen
Copy link
Contributor

Your welcome, special rule are added to the merge basket funilrys/PyFunceble@7a39a11 Please check if the domains are currently typed

Merry Christmas

spirillen added a commit to foreign-affairs/PyFunceble that referenced this pull request Dec 21, 2024
When this riles are merged and deployed we should remove whitelisting from Phishing-Database/phishing#539

Copy paste error
@kyrylo1
Copy link

kyrylo1 commented Dec 22, 2024

@spirillen thanks! Merry Christmas!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants