Skip to content
View openbait's full-sized avatar

Block or report openbait

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
openbait/README.md

OpenBait

A phishing report desk a brand runs under its own name. It replaces the phishing@ mailbox with one link — openbait.com/report/<brand>. A customer pastes the site they do not trust, the answer comes back in seconds, and anything confirmed as phishing is filed with the browser blocklists, the hosting provider and the registrar, under one fixed reporter identity, on behalf of the brand. Nothing reaches a host or a registrar without the brand's confirmation.

→ openbait.com · run by Puson Limited, Hong Kong

Tools

rdap-abuse Who to send a phishing report to, from RDAP: registrar, IANA ID, abuse address, creation date, nameservers, status. One shell script, no API key.

Write-ups from the desk

Each of these is a case we ran, with dates, including what we got wrong.

  • Five clone shops, nine domains — an hour-by-hour UTC record of one takedown case. We reported a site as offline while it was still taking card numbers from US visitors, because every probe we had ran from one country and the site answered some networks and played dead for others.
  • How to report a phishing domain to its registrar — a report you can copy, what we measured in two cases, and what to do when the first one is ignored.
  • Typosquat detection: five methods and their trade-offs — including the audit of our own pipeline: of 100 candidates it had rated high or critical, none was a live impersonation and 87 no longer existed.
  • A .cn phishing site — reported the same day to Google Safe Browsing and, through Phish.Report, to Tencent. Gone in about a day by one route; no visible reaction from the other in three.

Reporting

Reports go out from one fixed address, contact@openbait.com, marked as made on behalf of the brand. Evidence is archived with a third party while the site is still live. Security researchers: same address for vulnerability reports, acknowledged within 48 hours — security page.

Pinned Loading

  1. rdap-abuse rdap-abuse Public

    Who to send a phishing report to, from RDAP: registrar, IANA ID, abuse address, creation date, nameservers, status. One shell script, no API key.

    Shell 1