badmojr / 1Hosts

World's most advanced DNS filter-/blocklists!
https://o0.pages.dev
Mozilla Public License 2.0
1.55k stars 90 forks source link

Unblock URL shortener bitly.cx #1832

Closed zhg7 closed 1 month ago

zhg7 commented 2 months ago


Submit Form

Get your issue resolved quickly! Fill in the form accurately.

Lists in use:

Client: NextDNS


Domains:

bitly.cx


Details: False positive - URL shortener.

Thank you for supporting 1Hosts.

It’s people like you who make these lists great! ❤
spirillen commented 2 months ago

It is tagged as phishing by the phishing.database, so it seems to be in the right place

Search result from External Hosts-Sources

@mypdns's External Hosts-Sources can be found here

data/1Hosts.csv:bitly.cx
data/phishing_database/ALL-phishing-links.csv:bitly.cx

Sorted result

Search result from easylist

Search in Matrix

Search results from Matrix blacklist project

source/redirector/wildcard.list:bitly.cx
source/tracking/wildcard.list:bitly.cx

Found these RPZ records from My Privacy DNS

id      domain records  type    content
33539819        *.bitly.cx.redirector.mypdns.cloud      CNAME   .
33540189        bitly.cx.redirector.mypdns.cloud        CNAME   .
33542509        *.bitly.cx.tracking.mypdns.cloud        CNAME   .
33550991        bitly.cx.tracking.mypdns.cloud  CNAME   .

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ + Thanks to My Privacy DNS for this knowledge + +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

zhg7 commented 2 months ago

I don't see anything inherently malicious about that domain. It's just another URL shortener that could have been used to redirect to some malicious site and therefore ended up listed in a phishing list.

Vardorien commented 1 month ago

I don't see anything inherently malicious about that domain. It's just another URL shortener that could have been used to redirect to some malicious site and therefore ended up listed in a phishing list.

It's flagged by multiple security vendors for phishing. While yes abuse is probably one reason it's on there another one is most likely because it's ripping off Bitly's name, and is going to be considered phishing.