Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NextDNS blocking legitimate Israeli rockets alert app #1349

Open
whatuserever opened this issue Jul 14, 2024 · 0 comments
Open

NextDNS blocking legitimate Israeli rockets alert app #1349

whatuserever opened this issue Jul 14, 2024 · 0 comments

Comments

@whatuserever
Copy link

I noticed that redalert.me is being blocked by Threat Intelligence Feeds:

image

However, this is a legit domain used by @eladnava's open source RedAlert app.

According to Cloudflare, there is a malicious domain at redalertS[.]me (notice the s), but redalert.me is legitimate:

In the last two days, a new malicious website (hxxps://redalerts[.]me) has advertised the download of well-known open source application RedAlert by Elad Nava (https://github.com/eladnava/redalert-android). Domain impersonation continues to be a popular vector for attackers, as the legitimate website for the application (hxxps://redalert[.]me ) differs from the malicious website by only one letter. Further, threat actors continue to exploit open source code and deploy modified, malicious versions to unsuspecting users.

It seems to me like the legitimate domain was accidently blocked. Please remove it from the blocklist.


NOTE: I already reported this in the official bug reports forum, but got no response. This seems like the next best place.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant