-
-
Notifications
You must be signed in to change notification settings - Fork 227
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update falsepositive.list #291
Conversation
**Domains or links** pitch.com **More Information** How did you discover your web site or domain was listed here? Found it on virustotal.com **Have you requested removal from other sources?** CRDF - removal was approved **Additional context** Pitch is a presentation platform that allows users to publish content on the web. As such, we are vulnerable to abuse by users. The security of all Pitch users is at the top of our minds, and we are aware of a recent effort to abuse Pitch for phishing. We resolved the issue and invested a lot in automation of content scanning and blocking. We believe we solved the recent issue. Among the measures taken are: - We integrated multiple tools and services that scan each Pitch public slide/URL for phishing and other abuse. In doubt, our tooling automatically blocks suspicious content. - We added multiple tools that allow users to report suspicious content. - We are manually scanning Pitch for suspicious content. We would appreciate a fast merge and removal from the list, as many innocent users are currently affected. Happy to provide any other details privately at [email protected].
I, as @spirillen, can't help until you allow traffic from tor |
Thanks @spirillen . can you provide more details about the issues you are having using pitch.com with Tor? (OS, browser, anything we can use to reproduce the issue) I am not aware of any measures we are taking to block Tor and I was able to use the Tor browser to browse |
Hi @spirillen, thanks for your response. I work as a Security Engineer @ Pitch (pitch.com), and I am able to visit pitch.com via Tor too (tested on macOS Sonoma and Android). How can we help you break the deadlock and move pitch.com into falsepositive.list? :) ![]() |
You tell me... Logger output
|
Your Security Level is set on "Safer". If you set it on "Safest" or "Standard" you should be able to load it. |
@spirillen are you able to visit pitch.com using the Standard Security Level? Because I was able to reproduce 404 in the Safer Security Level. |
I'm using standard, but that is not your issue. I can see your site for about 1 => 2 seconds, then I get some unwanted software from your server which gets blocked and you are then returning a 404, to have people lowering their privacy settings. By the way, I find it rather impressive that your site know a new visitor have 4 pending jobs without even logging in!! |
4 is the number of open positions on the career page (Jobs) that we have. |
Our engineers have fixed the website, so now you should be able to visit it in all three Tor levels: Standard, Safer, and Safest. @spirillen let me know if it works for you. |
Relates to Phishing-Database/phishing#291
Domains or links
pitch.com
More Information
How did you discover your web site or domain was listed here? Found it on virustotal.com
Have you requested removal from other sources? CRDF - removal was approved
Additional context
Pitch is a presentation platform that allows users to publish content on the web. As such, we are vulnerable to abuse by users.
The security of all Pitch users is at the top of our minds, and we are aware of a recent effort to abuse Pitch for phishing.
We resolved the issue and invested a lot in automation of content scanning and blocking. We believe we solved the recent issue.
Among the measures taken are:
We would appreciate a fast merge and removal from the list, as many innocent users are currently affected.
Happy to provide any other details privately at [email protected].