Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | https://eu.jotform.com #1091

Open
gorkemfilizoz opened this issue Feb 3, 2025 · 21 comments
Open

False Positive | https://eu.jotform.com #1091

gorkemfilizoz opened this issue Feb 3, 2025 · 21 comments
Assignees

Comments

@gorkemfilizoz
Copy link

What are the subjects of the false-positive (domains, URLs, or IPs)?

https://eu.jotform.com

Why do you believe this is a false-positive?

I believe this is a false-positive because Jotform is a product that allows users to easily create forms and collect data. We have both automated and manual processes to prevent and mitigate abuse on our service. Also, abuse reports sent to [email protected] e-mail address or the abuse reports sent via our Report Abuse form (https://www.jotform.com/report-abuse/) are actively monitored by our security and reviewers team.
Our customers are experiencing access issues due to this URL being blocked by your service.

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

I discovered this false-positive by VirusTotal

Have you requested a review from other sources?

No.

Do you have a screenshot?

Image

Additional Information or Context

At Jotform, we take the privacy and security of our users very seriously. We have taken all necessary measures to ensure that our platform adheres to the highest security standards and that our users' data is protected at all times.
We kindly request that you remove the block on Jotform URLs and allow our users to continue using our platform without any interruptions. If you require any further information or assistance from our team, please do not hesitate to reach out to me directly.

@phishing-database-bot
Copy link
Member

Verification Required

@gorkemfilizoz, thank you for submitting a false positive report! To help us verify your ownership of the affected domain(s), please complete the following steps:

  1. Set a DNS TXT record for the domain(s) listed in this issue with the following details:

    • Record Name: _phishingdb
    • Record Value: antiphish-7e9aeb8ebbc041e8cb59fe8530d93717e684927b

    Your Verification ID: antiphish-7e9aeb8ebbc041e8cb59fe8530d93717e684927b

  2. Wait for DNS propagation (this may take a few minutes to a few hours).

  3. Reply to this issue once the TXT record has been set.

Important Notes

  • Verification does not guarantee whitelisting. The Phishing.Database team will review your report after verifying ownership, but the decision to whitelist depends on further investigation and analysis.
  • If the record cannot be set or you need alternative methods of verification, please contact us at [email protected] - preferably from the domain's official email address.

How to Check the TXT Record ?

You can verify that the TXT record is properly set using:

Thank you for your cooperation! We will address your issue as soon as possible after verification.

The Phishing.Database Project Team.

@spirillen
Copy link
Contributor

So you admit the rest of these records are phishing??

http://form.jotform.com/202268964605057
http://form.jotform.com/202404180749048
http://form.jotform.com/202474722390049
http://form.jotform.com/210082211992145
http://form.jotform.com/210947733721053
http://form.jotform.com/211174960621350
http://form.jotform.com/211575852072052
http://form.jotform.com/212079090460047
http://form.jotform.com/212079102124139
http://form.jotform.com/213401731192041
http://form.jotform.com/220322482811345
http://form.jotform.com/221025420361540
http://form.jotform.com/221884142921152
http://form.jotform.com/222895744691066
http://form.jotform.com/223003446285450
http://form.jotform.com/230224062387046
http://form.jotform.com/231911417067554
http://form.jotform.com/240110592846554
http://form.jotform.com/paiement0leboncoin/leboncoin
http://form.jotform.com/paiement0leboncoin/leboncoin/*
http://form.jotform.com/paiement0leboncoin/Leboncoin
http://form.jotform.com/webserver/Dappwebs-server-synchronized
http://jotform.com/Willingcalvin/government-pandemic-stimulus-bonus-
https://app.jotform.com/250042702567148
https://app.jotform.com/250152435283552
https://app.jotform.com/250197208695566
https://eu.jotform.com/app/250234036167349
https://form.jotform.com/210490797485063
https://form.jotform.com/210947733721053
https://form.jotform.com/211235127258551
https://form.jotform.com/211396536322555
https://form.jotform.com/211504299991059
https://form.jotform.com/211561987009157
https://form.jotform.com/211578761292159
https://form.jotform.com/211785005078354
https://form.jotform.com/211813881475056
https://form.jotform.com/211814414967055
https://form.jotform.com/211867238033556
https://form.jotform.com/211875419653160
https://form.jotform.com/211906868761163
https://form.jotform.com/211916108708051
https://form.jotform.com/211954201484048
https://form.jotform.com/211989015136154
https://form.jotform.com/212122183127140
https://form.jotform.com/212155791348156
https://form.jotform.com/212179075791159
https://form.jotform.com/212243342979156
https://form.jotform.com/212244946894062
https://form.jotform.com/212653193944056
https://form.jotform.com/212725446492156
https://form.jotform.com/212745469593064
https://form.jotform.com/213265315962557
https://form.jotform.com/213282782615357
https://form.jotform.com/220331466982356
https://form.jotform.com/220443218089050
https://form.jotform.com/221027503251138
https://form.jotform.com/221981943697573
https://form.jotform.com/222157190481049
https://form.jotform.com/222165049167153
https://form.jotform.com/222387010725046
https://form.jotform.com/222592794928573
https://form.jotform.com/222624132806045
https://form.jotform.com/222872197983976
https://form.jotform.com/222891906933970
https://form.jotform.com/222903478345460
https://form.jotform.com/222904104515446
https://form.jotform.com/222941730670959
https://form.jotform.com/223004930939455
https://form.jotform.com/223005374438452
https://form.jotform.com/22309
https://form.jotform.com/223108207973051
https://form.jotform.com/230093869703865
https://form.jotform.com/230131216443037
https://form.jotform.com/230224062387046
https://form.jotform.com/230303724289050
https://form.jotform.com/230604401931040
https://form.jotform.com/231835869469374
https://form.jotform.com/231837838369068?email=3D
https://form.jotform.com/232066991736162
https://form.jotform.com/232142641113138
https://form.jotform.com/232198979156069
https://form.jotform.com/232246820949563
https://form.jotform.com/233101536364347
https://form.jotform.com/233241314270342
https://form.jotform.com/233343763930962
https://form.jotform.com/233382164920252
https://form.jotform.com/250173738751056
https://form.jotform.com/elenabrown266/government-pandemic-extra-stimulus-
https://form.jotform.com/emrbeogyphpaopjpvu/microsoftonline_docuscanactiveXhY3z
https://form.jotform.com/hesewms/usa-gov
https://form.jotform.com/Lromero74002/government-pandemic-stimulus-bonus-
https://www.jotform.com/232387829452163
https://www.jotform.com/app/243137631990156
https://www.jotform.com/build/221571716008552

@gorkemfilizoz
Copy link
Author

Hi,
Thanks for the URLs that you shared. Majority of these URLs have already been detected as phishing by our automated and manual mechanisms and the form owners have been suspended already. After carefully examining all of them, we have suspended the remaining suspicious form owners.
We’ll be waiting your feedback as soon as possible.

@spirillen
Copy link
Contributor

ptcheck jotform.com antiphish-7e9aeb8ebbc041e8cb59fe8530d93717e684927b
Failed to query DNS TXT record for _phishingdb.jotform.com

Thanks for using my tools.
Please consider a sponsor ship at https://www.mypdns.org/donate

You forgot to set up the TXT record to verify your association with this domain.

@gorkemfilizoz
Copy link
Author

Hi,
Can you check it again?

@spirillen
Copy link
Contributor

ptcheck jotform.com antiphish-7e9aeb8ebbc041e8cb59fe8530d93717e684927b
The test value matches the DNS TXT record.

Thanks for using my tools.
Please consider a sponsor ship at https://www.mypdns.org/donate

spirillen added a commit to mypdns/matrix that referenced this issue Feb 6, 2025
@spirillen
Copy link
Contributor

Not good enough....

Subject                                                                                              Status      Source     Expiration Date   HTTP Code  Checker       Tested At          
---------------------------------------------------------------------------------------------------- ----------- ---------- ----------------- ---------- ------------- -------------------
http://form.jotform.com/210947733721053                                                              ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  06. Feb 2025 17:26:56
http://form.jotform.com/202404180749048                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:56
http://form.jotform.com/210082211992145                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:56
http://form.jotform.com/211174960621350                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:56
http://form.jotform.com/202474722390049                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:56
http://form.jotform.com/202268964605057                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:56
http://form.jotform.com/212079090460047                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:57
http://form.jotform.com/211575852072052                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:57
http://form.jotform.com/213401731192041                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:57
http://form.jotform.com/220322482811345                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:57
http://form.jotform.com/221025420361540                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:57
http://form.jotform.com/212079102124139                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:57
http://form.jotform.com/221884142921152                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:57
http://form.jotform.com/230224062387046                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:58
http://form.jotform.com/222895744691066                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:58
http://form.jotform.com/223003446285450                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:58
http://form.jotform.com/231911417067554                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:58
http://form.jotform.com/240110592846554                                                              INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:58
http://form.jotform.com/paiement0leboncoin/leboncoin                                                 INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:58
https://app.jotform.com/250042702567148                                                              ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  06. Feb 2025 17:26:58
http://form.jotform.com/webserver/Dappwebs-server-synchronized                                       INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:58
http://form.jotform.com/paiement0leboncoin/Leboncoin                                                 INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:58
http://jotform.com/Willingcalvin/government-pandemic-stimulus-bonus-                                 ACTIVE      HTTP CODE  Unknown           301        AVAILABILITY  06. Feb 2025 17:26:58
http://form.jotform.com/paiement0leboncoin/leboncoin/*                                               ACTIVE      HTTP CODE  Unknown           302        AVAILABILITY  06. Feb 2025 17:26:59
https://app.jotform.com/250152435283552                                                              ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  06. Feb 2025 17:26:59
https://form.jotform.com/210947733721053                                                             ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  06. Feb 2025 17:26:59
https://form.jotform.com/210490797485063                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:26:59
https://app.jotform.com/250197208695566                                                              ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  06. Feb 2025 17:26:59
https://form.jotform.com/211235127258551                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:00
https://form.jotform.com/211396536322555                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:00
https://eu.jotform.com/app/250234036167349                                                           ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  06. Feb 2025 17:27:00
https://form.jotform.com/211504299991059                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:00
https://form.jotform.com/211561987009157                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:00
https://form.jotform.com/211578761292159                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:00
https://form.jotform.com/211785005078354                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:00
https://form.jotform.com/211813881475056                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:00
https://form.jotform.com/211814414967055                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:01
https://form.jotform.com/211867238033556                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:01
https://form.jotform.com/211875419653160                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:01
https://form.jotform.com/211906868761163                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:01
https://form.jotform.com/211916108708051                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:01
https://form.jotform.com/211954201484048                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:01
https://form.jotform.com/211989015136154                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:01
https://form.jotform.com/212122183127140                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:02
https://form.jotform.com/212155791348156                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:02
https://form.jotform.com/212179075791159                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:02
https://form.jotform.com/212243342979156                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:02
https://form.jotform.com/212653193944056                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:02
https://form.jotform.com/212244946894062                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:02
https://form.jotform.com/212725446492156                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:03
https://form.jotform.com/213265315962557                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:03
https://form.jotform.com/212745469593064                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:03
https://form.jotform.com/213282782615357                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:03
https://form.jotform.com/220443218089050                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:03
https://form.jotform.com/220331466982356                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:03
https://form.jotform.com/221027503251138                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:04
https://form.jotform.com/221981943697573                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:04
https://form.jotform.com/222157190481049                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:04
https://form.jotform.com/222165049167153                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:04
https://form.jotform.com/222387010725046                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:04
https://form.jotform.com/222592794928573                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:04
https://form.jotform.com/222624132806045                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:04
https://form.jotform.com/222872197983976                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:04
https://form.jotform.com/222891906933970                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:05
https://form.jotform.com/222903478345460                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:05
https://form.jotform.com/222904104515446                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:05
https://form.jotform.com/222941730670959                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:05
https://form.jotform.com/223004930939455                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:05
https://form.jotform.com/223005374438452                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:05
https://form.jotform.com/22309                                                                       ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  06. Feb 2025 17:27:05
https://form.jotform.com/223108207973051                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:05
https://form.jotform.com/230093869703865                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:06
https://form.jotform.com/230131216443037                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:06
https://form.jotform.com/230224062387046                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:06
https://form.jotform.com/230303724289050                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:06
https://form.jotform.com/230604401931040                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:06
https://form.jotform.com/231835869469374                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:06
https://form.jotform.com/231837838369068?email=3D                                                    INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:07
https://form.jotform.com/232066991736162                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:07
https://form.jotform.com/232142641113138                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:07
https://form.jotform.com/232198979156069                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:07
https://form.jotform.com/232246820949563                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:07
https://form.jotform.com/233101536364347                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:07
https://form.jotform.com/233241314270342                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:07
https://form.jotform.com/233343763930962                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:08
https://form.jotform.com/233382164920252                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:08
https://form.jotform.com/250173738751056                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:08
https://form.jotform.com/elenabrown266/government-pandemic-extra-stimulus-                           INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:08
https://form.jotform.com/emrbeogyphpaopjpvu/microsoftonline_docuscanactiveXhY3z                      INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:08
https://form.jotform.com/hesewms/usa-gov                                                             INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:08
https://form.jotform.com/Lromero74002/government-pandemic-stimulus-bonus-                            INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:08
https://www.jotform.com/app/243137631990156                                                          ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  06. Feb 2025 17:27:09
https://www.jotform.com/232387829452163                                                              ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  06. Feb 2025 17:27:10
https://www.jotform.com/build/221571716008552                                                        INACTIVE    STDLOOKUP  Unknown           404        AVAILABILITY  06. Feb 2025 17:27:10

Execution Time: 00:00:00:16.36036



Status      Percentage   Amount      
----------- ------------ ------------
ACTIVE      12%          11          
INACTIVE    88%          83          
INVALID     0%           0           

spirillen added a commit to mypdns/matrix that referenced this issue Feb 6, 2025
@gorkemfilizoz
Copy link
Author

Hi,
Can you check it again?

@spirillen
Copy link
Contributor

I cannot proceed with any testing without access to your network. If you want me to continue addressing this issue, you need to make your network publicly available. Otherwise, I will have to step back and let someone else take over.

Image

@gorkemfilizoz
Copy link
Author

Hi,
We do not have a form with the form ID you mentioned. We cannot access that form as well. But when you check the other forms with valid form ID, you can see that all of them are closed and the users are suspended.

@spirillen
Copy link
Contributor

Hi, We do not have a form with the form ID you mentioned. We cannot access that form as well. But when you check the other forms with valid form ID, you can see that all of them are closed and the users are suspended.

Thank you for your response. However, I would like to clarify that I have been receiving multiple HTTP status codes of 200. In accordance with the specifications outlined in RFC 7231, I would expect to see status codes in the following order of preference: 410 (Gone), 404 (Not Found), and ideally not 403 (Forbidden), as this indicates that the URI is still active. Your attention to this matter would be greatly appreciated.

# Generated by PyFunceble (v4.3.0a15.dev) / https://pyfunceble.github.io
# Date of generation: 2025-02-07T12:31:44.618689+00:00

Subject                                                                                              Status      Source     Expiration Date   Registrar                      HTTP Code  Checker       Tested At          
---------------------------------------------------------------------------------------------------- ----------- ---------- ----------------- ------------------------------ ---------- ------------- -------------------
http://form.jotform.com/210947733721053                                                              ACTIVE      HTTP CODE  Unknown           Unknown                        200        AVAILABILITY  07. Feb 2025 12:31:43
https://app.jotform.com/250042702567148                                                              ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  07. Feb 2025 12:31:46
http://form.jotform.com/paiement0leboncoin/leboncoin/*                                               ACTIVE      HTTP CODE  Unknown           302        AVAILABILITY  07. Feb 2025 12:31:47
http://jotform.com/Willingcalvin/government-pandemic-stimulus-bonus-                                 ACTIVE      HTTP CODE  Unknown           301        AVAILABILITY  07. Feb 2025 12:31:47
https://app.jotform.com/250152435283552                                                              ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  07. Feb 2025 12:31:47
https://app.jotform.com/250197208695566                                                              ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  07. Feb 2025 12:31:48
https://form.jotform.com/210947733721053                                                             ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  07. Feb 2025 12:31:48
https://eu.jotform.com/app/250234036167349                                                           ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  07. Feb 2025 12:31:48
https://form.jotform.com/22309                                                                       ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  07. Feb 2025 12:31:55
https://www.jotform.com/app/243137631990156                                                          ACTIVE      HTTP CODE  Unknown           200        AVAILABILITY  07. Feb 2025 12:32:00

@cigdemtosun
Copy link

Hi @spirillen,

I am Cigdem and I work for Jotform.

Can we kindly stay in the "phishing" context and not dive into RFC specifications? If a URI returns 200, it does not mean that the "unwanted" content is still available and in this case the content was the problem, not the status code.

Since we care about our platform we are constantly monitoring it and hence why we wanted to create an issue here to see what more we can do. I believe we have done our part here so let's not complicate things with bureaucracy.

We appreciate your help to improve our platform reputation and I thank you in advance. We would also much appreciate if you can contact us at abuse[@]jotform[.]com in the future.

@spirillen
Copy link
Contributor

Can we kindly stay within the "phishing" context and avoid diving into RFC specifications?

Yes, we can stay on topic, but it's important to note that the RFC serves as the standard for the internet and is integral to our testing process (https://github.com/Phishing-Database/Phishing.Database?tab=readme-ov-file#automated-testing).

We adhere to the guidelines outlined in RFC 7231.

Active Status Codes

100, 101, 200, 201, 202, 203, 204, 205, 206

If a URI returns 200, it does not mean...

Actually, you're mistaken; a 200 status code indicates that the page is indeed active.

If you're not familiar with the basics of HTTP status codes, please feel free to ask. It's not advisable to instruct someone who has been working with the HTTP protocol for over 25 years on how it should function. If you have a different perspective, you might consider submitting your comments to the RFC.

We appreciate your help in improving our platform's reputation.

Unfortunately, I can't provide better support than this unless you manage to get the RFC revised. HTTP status codes have been established for decades and are fundamental to how the HTTP protocol processes and interprets requests.

We would also much appreciate if you can contact us at abuse[@]jotform[.]com in the future.

Not gonna happen, this is a open source project, we keep thing in the open, mostly to later be phasing false accusations.

@spirillen
Copy link
Contributor

I'm sorry, but can we please move on from this?

Hey @cigdemtosun, I've been reflecting on our conversation from yesterday, and I think I may have misunderstood your message. It seems there might have been some miscommunication regarding my response about the list of HTTP 200 codes.

To clarify, I intended to return the registered URIs in the PD project with that list, and I was hoping you could provide some insights on whether those links should be there or not.

Could you please take a moment to double-check the lists? As we've learned, it's always good to verify things, and I would appreciate your feedback on this. Thank you!

@cigdemtosun
Copy link

cigdemtosun commented Feb 12, 2025

Hi @spirillen,

Thank you for your reply!

I have checked the latest list you have shared with us and I can say that apart from "https://form.jotform.com/22309" all URIs are valid. For the remaining, the potential scam content in the URIs are removed as the owners of the resources have been suspended. And now they look like this:

Image (Related URI: https://www.jotform.com/app/243137631990156)

Or like this:

Image (Related URI: http://form.jotform.com/210947733721053)

Since the content that put the URIs in your list has been removed, I am hoping you can remove the URIs from PD.

Kind regards.

spirillen added a commit to Phishing-Database/phishing that referenced this issue Feb 12, 2025
This issue will whitelist `.jotform.com`

Closes Phishing-Database/Phishing.Database#1091

Signed-off-by: spirillen <[email protected]>
@spirillen
Copy link
Contributor

spirillen commented Feb 12, 2025

Dear @cigdemtosun

Thanks for your reply. I wanted to take a moment to discuss the HTTP status codes used on your website, particularly in relation to the RFC standards.

As we have some time to address this matter, I would like to understand the reasoning behind the decision not to adhere to the RFC guidelines regarding HTTP responses. Specifically, the links you provided should ideally return a 410 status code, as this aligns with the intended use of HTTP codes. Implementing this change would not only enhance the accuracy of your responses but also streamline the process of identifying and removing false positives, both manually and through automated testing.

While I have cleared your records for now, I believe that updating your HTTP code responses in accordance with the RFC would greatly benefit your website. This adjustment would not only improve functionality but also enhance user experience.

Thank you for considering this suggestion. I look forward to your thoughts on the matter.

Best regards,

PS: I am transferring this discussion regarding the server response code to the merge request. Phishing-Database/phishing#751

@cigdemtosun
Copy link

You are definitely right about the status codes but unfortunately my department is not a stakeholder of this issue. However, I know that there are some internal discussions regarding the status codes so I believe we will see some improvements in the future.

Thank you for your efforts on this issue.

@spirillen
Copy link
Contributor

Please feel free to direct them here if it can assist in your development efforts to align with the RFC and reduce false positives in the future. I will keep this issue open until there is no further hope for resolution. Otherwise, you may face challenges with blacklists due to incorrect HTTP codes.

Let me know if/when the "battle is lost"

@emidaniel
Copy link

After carefully examining all of them, we have suspended the remaining suspicious form owners.

You did not remove these:
https://eu.jotform.com/app/250283108000339 https://www.phishtank.com/phish_detail.php?phish_id=8956395
https://eu.jotform.com/app/250281817001345 https://www.phishtank.com/phish_detail.php?phish_id=8955999
https://eu.jotform.com/app/232774111857358 https://www.phishtank.com/phish_detail.php?phish_id=8478171
They should be removed even if the destination has been already taken down.

This one is an active redirector:
https://form.jotform.com/250417713409050 ->
https://eu-submit.jotform.com/submit/250417713409050 ->
https://maracreditor.weebly.com/ ->

active phish

Image

The rest is now marked as offline on Phishtank.

@spirillen
Copy link
Contributor

@emidaniel Please read the thread, I do know it have grown, but in the comments above ⏫ you will find a reference to Phishing-Database/phishing#749 and some letters, you know those funny things jumping around the screen making words... actually tries to spell to some words letting you all know, that the whitelisting process is broken... 🤷🏻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: 🆕 New
Development

No branches or pull requests

8 participants