Hi,
I am a cybersecurity engineer in the area of phishing. I see hundreds of phishing domains every month from the plesk.page domain and have a few questions.
Some of the attacks are from domains with the standard "adjective-scientist.xxx.xxx.xxx.xxx.plesk.page" format and host a multitude of phishing sites. If a site has malicious content regarding a brand a takedown can be initiated, it often consists of contacting the hosting provider, domain owner, perhaps registrar etc.
Plesk does not respond to takedown requests on the [email protected] contact email, I am not sure if you see these requests then act on them and don't respond but not acknowledging the emails even via an automated manner makes it difficult to determine if Plesk is in fact performing any takedown or is taking action.
What is Plesks policy on this issue ? although you are not the hosting provider you are still providing a free hostname service that is being abused and well known by cybercriminals. Does Plesk take measures to avoid malicious content on dev pages ?
There is also domains with custom subdomains such as "custom.custom.custom.xxx-xxx-xxx-xx.plesk.page/..." This allows attackers to make even more plausible attacks using plausible subdomains to make their attack look more legitimate. Could you explain how users can add subdomains in the panel I have not been able to do it myself ?
I am aware this is the community forum but I thought discussing this in the open with staff is preferred.
Thanks,
I am a cybersecurity engineer in the area of phishing. I see hundreds of phishing domains every month from the plesk.page domain and have a few questions.
Some of the attacks are from domains with the standard "adjective-scientist.xxx.xxx.xxx.xxx.plesk.page" format and host a multitude of phishing sites. If a site has malicious content regarding a brand a takedown can be initiated, it often consists of contacting the hosting provider, domain owner, perhaps registrar etc.
Plesk does not respond to takedown requests on the [email protected] contact email, I am not sure if you see these requests then act on them and don't respond but not acknowledging the emails even via an automated manner makes it difficult to determine if Plesk is in fact performing any takedown or is taking action.
What is Plesks policy on this issue ? although you are not the hosting provider you are still providing a free hostname service that is being abused and well known by cybercriminals. Does Plesk take measures to avoid malicious content on dev pages ?
There is also domains with custom subdomains such as "custom.custom.custom.xxx-xxx-xxx-xx.plesk.page/..." This allows attackers to make even more plausible attacks using plausible subdomains to make their attack look more legitimate. Could you explain how users can add subdomains in the panel I have not been able to do it myself ?
I am aware this is the community forum but I thought discussing this in the open with staff is preferred.
Thanks,