> don't want to serve as an oracle for the people whose malware they are trying to block
Those people don't have a registered business; The people contacting Microsoft do.
There are probably a bunch of excuses we can come up with that would make sense... but I think most people know the real reason, it's the same as with Google and Apple... they don't do customer support, and they don't take responsibility for any negative effects their services might have on others, at least not until someone big enough makes a fuss or lawyers get involved.
He's not saying there is. He's saying that it's pretty unlikely that the malware authors are going to phone Microsoft and ask why their site is flagged, so putting in some reasonable road blocks that a legitimate business would definitely jump over (e.g. talking to real people) would be plenty to remove the oracle issue.
Sure, maybe not display it in the publicly visible warnings, but if the admins of a domain email you from the same domain as the flagged site, then maybe providing more detail at that point is an acceptable method of fixing the issue.
Saying "we know you are compromised and know exactly where, but we're not going to tell" is very childish. Now, if they said for a nomial fee, we'd be happy to share the results of our work, would be another thing totally.
Not sure what you are saying here. I've only ever used TXT DNS records by copying&pasting whatever the original certbot told me to do or when setting up custom domain with 3rd party email. I have no idea what they do, who can read them, when, where, why, etc.
Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance? What does law enforcement do with this info?
> but if the admins of a domain email you from the same domain as the flagged site
Email domains aren't always match with domains running the web-site (don't forget only ten years ago www. was still expected and people redirected you there from non-www. name).
But having access to DNS zone you can prove 'ownership' (at least technical) of the domain (even if it doesn't have the associated MX records for e-mail), precisely why LE is doing it.
> by copying&pasting whatever the original certbot
> I have no idea what they do, who can read them, when, where, why, etc
Oh my...
> Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance?
More like "to prove you are the one responsible for tailspintoys.com - create a TXT record under that domain with 'dylan604 is admin here'".
> I have no idea what they do
TXT records are just plain text strings (in ASCII), nothing more, nothing less.
> who can read them, when, where, why
Everyone, anytime, anywhere, because it is you who placed it there in a system of Public DNS servers
Except that it could help attackers beefen up their tools. A certain amount of obscurity is good to keep the attackers from having too much information.
I've been in the situation where a company kinda 'ghosts' me before. And found out I was indeed the bad player (unintentionally, of course).
In this case, that sure would be helpful. Now imagine that you're running a website that is intentionally trying to trick people into installing malware. You've successfully evaded tools like Smart Screen but now you've ended up on the list.
You're not sure which one of your virus payloads set off their screen so you open a ticket. And Microsoft is supposed to tell you exactly how to get off their list again?
If you're hosting it on purpose, then you already know that it's the culprit and would've tried to change it anyways. I don't really see a scenario where telling the person who opened the ticket what the issue is would weaken the security measures or detection strategy.
That's not what is being said here, the domain is blacklistes and my comment was about MS not the bad guy telling the site owner the malicious URL. If you tell them the URL, they will change it and claim it was a compromise so they can increase campaign lifetime.
... MS is telling everyone that the root domain is on a black list. A malicious actor doesn't need more than that, they already know the exact URL that malware resides at.
A non-malicious actor doesn't know, so telling them the exact URL at least tells them where the compromised asset might be.
Yes a malicious actor needs more than that because compromised domains are valuable and keeping them alive longer means more money...
A non-malicious actor who needs the URL isn't monitoring or responding to the incident properly. Threat actors do take advantage of this and simulate a fake cleanup. Actually they exclude certain ips and asns on phishing kits so that visiting the url gives you a 404 or a webhosts "cleanup" page.
Easy. Scenario: Malicious attacker looks for exactly what Microsoft detected, and fixes each specific detection while keep operating the undetected ones. The end result would be operational malicious site, without being detected.
If I put malware at xyz.com/mybadpage and MS starts flagging xyz.com, how on earth do I "maximize campaign life" by being told xyz.com/mybadpage has malware?
Imagine that you have put malware in xyz.com/mybadpage1, xyz.com/mybadpage2, and xyz.com/mybadpage3 pages. MS flags you, and you query MS. They tell you they see malware on the first two urls. Now you gained information about their blindspots.
You can capitalise on this multiple ways. You can remove the first two and hope they remove the flag. You can design your next attack better so it is more like mybadpage3. Etc
Disagree: $Evil_Site_Owner can easily test MS's blind spots by putting malware on numerous web sites, then seeing which of those sites are flagged. And if MS is not systematically scanning all the URLs...well, "MS failed to notice malware at $URL, which my web server logs say MS has not visited" is pretty useless information.
(Not that I think MS should enumerate malicious URL's, unless $Site_Owner is paying for scanning service. A "we noticed malware at $URL" is generally 95% of the possible value of such disclosures.)
You move it to xyz.com/anotherbadpage and tell MS it has been cleaned up. They do this all the time. Speaking from first hand experience. This is a very simple topic, why are there so many people not understanding this?!
I considered that but it didn't seem logical. If it's on purpose, it would be trivial to change the URL and then go "ok it's clean now please remove the flag"
How does keeping secret (from the bad guys) where the malware is thwart the bad guys?
MS is already stopping the bad guys by blocking the domain. You are supposed to do proper IR and clean up after yourseld including finding out the cause of the compromise which MS can't help with. What happens in the real world is people delete the file or webshell and think the bad guys are gone and if MS unblocks them then the campaign continues.
Or the bad guys themselves do that pretending to be the site owner. MS analysts can only inspect the normal site and the malicious URL that has now been removed in order to unblock it.
This is how abuse and IR works, I am surprised at the naivette of the responses here.
What happens is a website is blocked and the site operator has no idea why. The defense of "we can't share any information as to why you got punished as it might help bad actors avoid punishment" should not be an acceptable stance. It's the equivalent of being thrown to prison without due process and just ignoring false positives. It's a very "natural" way of acting, but that does not make it the right one.
IR is incident response, it means you find out everything the bad guys did and how it was compromised and fix it all. You should contact a security company or professional to help you if you don't know. I have used the webshells of compromised sites where the owner tries to cleanup but the webshell is still there hosting different campaigns.
You should secure your site better and have someone who knows what they are doing (there are paid WAF and web security vendors) monitor and respond to security incidents. You are not being punished, MS is protecting its customers. You should blame the hacker not MS for the impact of the hack. It's like someone messed with your car tank and tires and the police stop you from driving it because it is unsafe to other drivers, they are not punishing you but protecting other people from being hurt by your property.
> It's like someone messed with your car tank and tires and the police stop you from driving it because it is unsafe to other drivers, they are not punishing you but protecting other people from being hurt by your property.
The police says why they stopped you though! Which implies what you have to change in order to be able to drive again. They will not say "you have to figure it out on your own or the guys who messed with your car would have it more easy."
I live in the USA. Victim blaming "they did something to deserve it" is at best unethical. In court theoretically I would have the right to demand to see evidence. "Hold my beer" is not likely to be sufficient except in egregious circumstances.
With that said, there is an epidemic of muppet thinking right now. It's not just the intertubes. Suppose a credit card company pulls your credit report because they say you applied for credit with them. No funds are stolen. You demand they show proof. They say nope, because TTPs. So: how do I know it's a one-off, and not data theft by fraud at scale? Off goes a letter to the FTC...
TEMPORIZING FOUND NOT TO BE A FORM OF LYING
"Temporizing", which is speculating from what we know now as to the
motives of actors in the past and presenting that as historical fact,
has been found not to be a form of lying. "Social proof demonstrates
that temporizing is not lying" said a social commentator.
The news was greeted optimistically as a good day for humanists and
levels the playing field because "now the standards of proof we need
to meet for the existence of society are the same as for religion".
"People must have known about this in the past because it seems
like they should have" said a man in the street. "Everybody who
believes in science trusts society" said another.
I have no idea what your post is about but from MS's perspective it isn't the site owners but MS's users around the world that are victims of thr threat actor that need protection. If it truly is a compromised site then the site owner is also a victim but as owners it is also their duty to secure and cleanup their site that is currently endangering the public.
Microsoft is not the Guardian of the World. If they take it upon themselves to act as such without being a responsible Netizen (cooperating with other site operators to provide a higher quality Net) then they are more interested in cementing their own position rather than being a part of a civilized Net.
Imagine if I just suddenly started spreading around rumors of your malfeasance and shadyness, and untrustworthyness.
They are not guarding the world but their windows users that don't use chrome but edge and IE (MS browsers) in this case, google and firefox also do this by default.
If it truly is a compromised site then the site owner needs to clean it up; but starting the sentence with "If.." doesn't make it so.
Alex Pinto's classic research into the (lack of) overlap among threat indicator feeds should be a shot across the bow; I worked with threat indicators for a decade. To fend off muppet thinking I would like to remind everybody that they're selling threat indicator feeds; nobody that I know of sells not-a-threat feeds. A false positive means a site was falsely reported as a threat [sp]; a false negative does not mean that it is good, it simply means it is omitted from the list of threats.
In my experience vendors are a lot more worred about false positives than dropping something which is a threat on the floor (false negatives in context). However, moral hazard pushes them to publish things which turn out to be false positives anyway, because at the end of the day they're selling FUD.
My network, my rules. Something doesn't have to be a threat for it to be blocked from a private network in my opinion; there are lots of reasons for that, including minimizing potential threats. Something could be hosted on stinky infrastructure, but it's unknown or hasn't been demonstrated to be a threat. Profiles for operational security vary, and so does the appetite for proactively blocking (and whitelisting necessary resources): just because it's legal doesn't mean it doesn't put me at a competitive disadvantage if people know what I'm doing. I have no problem with people sharing and discussing such indicators, but there has to be attribution to the sharer: they have a reputation to be considered with equal concern as that of the indicators they publish.
If you're going to do something public with such information, you can't point fingers at "AI" and indicators you found in a paper bag on the bus: you do that, then you own it. Saying the victim deserves it is something you'd better be prepared to defend in court.
In many of these extreme cases where it's non-obvious what is wrong, the victim IS often the one responsible.
Example: Viral video shows police pulling unarmed (and allegedly innocent) suspect out of a parked car that sparks outrage. It's later found out that the victim was previously evading police pursuit just minutes before, and was trying to blend in with the other cars in a lot.
No, because they would cause the following scenario: Malicious attacker looks for exactly what Microsoft detected, and fixes each specific detection while keep operating the undetected ones. The end result would be operational malicious site, without being detected.
So what? Just leave legit users in the dark because assholes exist? This type of logic needs to die. Assholes continue to exist because we enable them to by not raising the bar high enough that compromise is impractical, and no longer easy money.
People underestimate the extent to which a bunch of opaque "anti-abuse" algorithms control things. Everyone is given a risk score and if you exceed an internal threshold they will never respond to your support requests until your complaint gets on the HN frontpage. Then as justification to continue their pointless cat and mouse game the abuse department types will come in and say "well if we told you why we arbitrarily decided to <steal your money/delete your 20 year old email account/prevent you from logging in with a weird error message> then the real criminals would know how we detected them!"
I believe they will if you use their vulnerability management offering it should come up with such details.
We can not expect companies to give free security advice. Secondly, providing such info without consent might result in legal actions from not so smart companies.
should? probably. But I also get, from a capitalist perspective, why they don't: they probably get enough "we swear our website is actually fine" tickets each day that they would need a sizable dedicated team to offer that kind of assistance. I don't think any of the browser vendors, Google and Mozilla included, will go to any real effort to help the reporter. At least I haven't seen them do so. I think they take the view, and I don't totally blame them, that securing your website is your problem, and they aren't going to offer security consulting for free.
They're already checking where the malware is when reviewing a report or unlisting request. The email template would need exactly one value: the URL they found.
Likely they already store this info somewhere so that the next time anyone reviews the domain, the reviewer cannot overlook it. In that case, the system could be completely automated, sending the info to the hostmaster or tech-c of the domain or something.
If they provided proof they wouldn't get "we swear our website is actually fine" tickets. Or if they did, it would be easy to resolve them: Post the proof.
If you launch a product that targets other businesses and has the capability of destroying them, you better take responsibility for that.
Not saying that isn't shit or frustrating.