jianjianai / ms-copilot-play

Cloudflare Worker 的 Microsoft Copilot 加速服务。Microsoft Copilot 是基于 OpenAI GPT-4 的强大 AI 并且能够使用 Bing 搜索来解答问题。简单部署即可在国内高速访问原滋原味的 Microsoft Copilot 的几乎全部功能,聊天,笔记本,插件,图像生成,分享等等..
https://copilot.6m6c.cn/?dpwa=1
MIT License
245 stars 320 forks source link

本项目部署后被cloudflare报钓鱼网站 #6

Closed chengtx809 closed 5 months ago

chengtx809 commented 5 months ago

如题,部署后我登陆了自己的账号,没过多久就收到了来自cloudflare的邮件,全文如下

您好,

Cloudflare 收到了一份关于以下区域的 phishing report:chengtx007.workers.dev

我们收到的信息如下:

报告者:匿名

报告 URL:

    https://microsoft-copilot-porxy.chengtx007.workers.dev/login.srf?wa=wsignin1.0&rpsnv=153&id=298156&wreply=https%3A%2F%2Fcopilot.microsoft.com%2Fsecure%2FPassport.aspx%3Fedge_suppress_profile_switch%3D1%26requrl%3Dhttps%253a%252f%252fcopilot.microsoft.com%252f%26sig%3D16AA0892E01D6E2C3CA01C0EE1C06F98%26nopa%3D2&wp=MBI_SSL&lc=1033&CSRFToken=a312a2ce-4635-4390-b840-1cccd3a052ec&aadredir=1&nopa=2

滥用日志或证据:Hello,

We have discovered a phishing attack located on your network:

https://microsoft-copilot-porxy.chengtx007.workers.dev/login.srf?wa=wsignin1.0&rpsnv=153&id=298156&wreply=https%3A%2F%2Fcopilot.microsoft.com%2Fsecure%2FPassport.aspx%3Fedge_suppress_profile_switch%3D1%26requrl%3Dhttps%253a%252f%252fcopilot.microsoft.com%252f%26sig%3D16AA0892E01D6E2C3CA01C0EE1C06F98%26nopa%3D2&wp=MBI_SSL&lc=1033&CSRFToken=a312a2ce-4635-4390-b840-1cccd3a052ec&aadredir=1&nopa=2

This attack targets our customer, Microsoft, website URL https://www.microsoft.com/.

Would it be possible to have the fraudulent content, and any other associated fraudulent content, taken down as soon as you are able to?

Additionally, please keep the fraudulent content safe so that our customer and law enforcement agencies can investigate this incident further once the site is offline.

More information about the detected issue is provided at https://incident.netcraft.com/604ab6571372/

Many thanks,

Netcraft

Phone: +44(0)1225 447500
Fax: +44(0)1225 448600
Netcraft Issue Number: 57110315

注释:

我们已将此投诉转发给您的托管提供商。
谢谢,
Cloudflare 团队

不知道是否会有影响?

jianjianai commented 5 months ago

这就不知道了,我演示站部署很久了也没收到类似的邮件。

chengtx809 commented 5 months ago

目前暂未发现影响

b1ghawk119 commented 3 months ago

目前暂未发现影响

暂未发现影响指的是什么?你的站点继续存活,还是指站点挂了,但是CloudFlare账户还可以正常使用?