|
|
|
|
|
by _8j50
1400 days ago
|
|
MS is already stopping the bad guys by blocking the domain. You are supposed to do proper IR and clean up after yourseld including finding out the cause of the compromise which MS can't help with. What happens in the real world is people delete the file or webshell and think the bad guys are gone and if MS unblocks them then the campaign continues. Or the bad guys themselves do that pretending to be the site owner. MS analysts can only inspect the normal site and the malicious URL that has now been removed in order to unblock it. This is how abuse and IR works, I am surprised at the naivette of the responses here. |
|
What happens is a website is blocked and the site operator has no idea why. The defense of "we can't share any information as to why you got punished as it might help bad actors avoid punishment" should not be an acceptable stance. It's the equivalent of being thrown to prison without due process and just ignoring false positives. It's a very "natural" way of acting, but that does not make it the right one.