Hacker News new | ask | show | jobs
by iforgotpassword 1400 days ago
If you're hosting it on purpose, then you already know that it's the culprit and would've tried to change it anyways. I don't really see a scenario where telling the person who opened the ticket what the issue is would weaken the security measures or detection strategy.
1 comments

That's not what is being said here, the domain is blacklistes and my comment was about MS not the bad guy telling the site owner the malicious URL. If you tell them the URL, they will change it and claim it was a compromise so they can increase campaign lifetime.
... MS is telling everyone that the root domain is on a black list. A malicious actor doesn't need more than that, they already know the exact URL that malware resides at.

A non-malicious actor doesn't know, so telling them the exact URL at least tells them where the compromised asset might be.

Yes a malicious actor needs more than that because compromised domains are valuable and keeping them alive longer means more money...

A non-malicious actor who needs the URL isn't monitoring or responding to the incident properly. Threat actors do take advantage of this and simulate a fake cleanup. Actually they exclude certain ips and asns on phishing kits so that visiting the url gives you a 404 or a webhosts "cleanup" page.

Easy. Scenario: Malicious attacker looks for exactly what Microsoft detected, and fixes each specific detection while keep operating the undetected ones. The end result would be operational malicious site, without being detected.
That's exactly what I am saying...