Bitcoin Forum

Other => Meta => Topic started by: alani123 on May 12, 2015, 08:20:47 PM



Title: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: alani123 on May 12, 2015, 08:20:47 PM
bitcointalk dotNo SEOxyz is probably trying to fool people into giving them the password to their bitcointalk account. The website looks exactly like bitcointalk.org and is accessible through google searches.

Entering a username and a password there will somehow redirect to bitcointalk.org and try to login with the credentials? Can someone from the staff confirm that it is not (or is) affiliated with bitcointalk.org? Because if it's not, we should consider reporting it to google as a phishing website.

Edit: Theymos posted here from his secondery account:

It's not mine. Leeching traffic for ads, phishing, malware, or maybe just bypassing China/Russia's ban of the forum. I strongly recommend not logging in there in any case.

If you end up visiting this website do not put in your login details. We can't be sure about the reason this website was created, but you shouldn't trust it with your login credentials as it's operated by a third party we know nothing about.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: tspacepilot on May 12, 2015, 08:25:39 PM
Wow, I'm amazed at their ability to mirror so quickly if they're aren't actually a legit version of this forum (even your post in meta appears there!).  Really interested in what the official word is on this one.

Icann wiki says TLD xyz is supposed to be a "truly generic" tld (http://icannwiki.com/.xyz), I had never heard of it before seeing this thread.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: alani123 on May 12, 2015, 08:31:15 PM
Wow, I'm amazed at their ability to mirror so quickly if they're aren't actually a legit version of this forum (even your post in meta appears there!).  Really interested in what the official word is on this one.

Icann wiki says TLD xyz is supposed to be a "truly generic" tld (http://icannwiki.com/.xyz), I had never heard of it before seeing this thread.

.xyz is one of the newly authorised TLDs. The website is indeed a very convincing and dynamic clone of bitcointalk.org but it's SEO is suspiciously good. Makes me think that it's not here to serve as a mirror of bitcointalk.org but instead an attempt to steal people's accounts.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: jbrnt on May 12, 2015, 08:44:41 PM
The xyz forum looks exactly like bitcointalk. Is it a frame redirect and not actually phishing?


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: chmod755 on May 12, 2015, 09:37:01 PM
I just reported it to Google and others for phishing.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: RussianRaibow on May 12, 2015, 09:58:52 PM
bitcointalk dotNo SEOxyz is probably trying to fool people into giving them the password to their bitcointalk account. The website looks exactly like bitcointalk.org and is accessible through google searches.

Entering a username and a password there will somehow redirect to bitcointalk.org and try to login with the credentials? Can someone from the staff confirm that it is not (or is) affiliated with bitcointalk.org? Because if it's not, we should consider reporting it to google as a phishing website.

It seems they are just domain cloaking. Not using any DB at their end like bitcointa.lk. That is why their threads are getting updated in real time.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: alani123 on May 12, 2015, 10:34:25 PM
The xyz forum looks exactly like bitcointalk. Is it a frame redirect and not actually phishing?
It doesn't seem like a simple frame. You can check the source of the page and see that the code is similar to the original.

Click this image for a screenshot comparing the first lines of source pages from the two websites
https://i.imgur.com/OK1QMxo.png?1 (https://i.imgur.com/OK1QMxo.png)


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: tspacepilot on May 12, 2015, 11:31:08 PM
The xyz forum looks exactly like bitcointalk. Is it a frame redirect and not actually phishing?
It doesn't seem like a simple frame. You can check the source of the page and see that the code is similar to the original.

Click this image for a screenshot comparing the first lines of source pages from the two websites
https://i.imgur.com/OK1QMxo.png?1 (https://i.imgur.com/OK1QMxo.png)

Most likely they are mirroring from the back-end. I e, you can run curl and print to stdout if you want to republish the source of another site.  I'm also curious if this might be a legit experiment that theymos is doing with changing the TLD or something.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: alani123 on May 12, 2015, 11:39:26 PM
The xyz forum looks exactly like bitcointalk. Is it a frame redirect and not actually phishing?
It doesn't seem like a simple frame. You can check the source of the page and see that the code is similar to the original.

Click this image for a screenshot comparing the first lines of source pages from the two websites
https://i.imgur.com/OK1QMxo.png?1 (https://i.imgur.com/OK1QMxo.png)

Most likely they are mirroring from the back-end. I e, you can run curl and print to stdout if you want to republish the source of another site.  I'm also curious if this might be a legit experiment that theymos is doing with changing the TLD or something.

This is why I'm suggesting that we should wait for a staff member to give us a hint on what this is before taking action.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: theymos_away on May 13, 2015, 12:14:09 AM
It's not mine. Leeching traffic for ads, phishing, malware, or maybe just bypassing China/Russia's ban of the forum. I strongly recommend not logging in there in any case.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: ISIS Representative on May 13, 2015, 12:25:34 AM
Theymos can issue a takedown notice if he feels the need too. Glad you notified us about it.
No, there is no such thing as a takedown notice. Most nations do not care about US laws.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: tspacepilot on May 13, 2015, 12:27:56 AM
It's not mine. Leeching traffic for ads, phishing, malware, or maybe just bypassing China/Russia's ban of the forum. I strongly recommend not logging in there in any case.

Well, now we know that it's not something theymos is doing anyway.  Interesting suggestion that they might be somehow trying to provide something legit.  I certainly won't be logging in there.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: guitarplinker on May 13, 2015, 01:03:25 AM
Theymos can issue a takedown notice if he feels the need too. Glad you notified us about it.
No, there is no such thing as a takedown notice. Most nations do not care about US laws.
Looks like the domain is registered through a Chinese provider (the whois says it's registered through Xiamen Nawang technology Co., Ltd) so I don't think they would take the site down even if theymos complained. However the fact that it's registered through a Chinese provider could also mean that it is indeed trying to pass Chinese restrictions on the normal Bitcointalk site, as theymos mentioned.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: chmod755 on May 13, 2015, 03:45:35 AM
Looks like the domain is registered through a Chinese provider (the whois says it's registered through Xiamen Nawang technology Co., Ltd) so I don't think they would take the site down even if theymos complained. However the fact that it's registered through a Chinese provider could also mean that it is indeed trying to pass Chinese restrictions on the normal Bitcointalk site, as theymos mentioned.

There are already several websites mirroring bitcointalk and calling it bitcointalk.xyz should make it quite easy to detect for those who are monitoring the traffic. I think I would use a foreign (non-chinese) company if I tried to bypass the "Great Firewall of China" to avoid getting arrested for doing that.


Title: Re: Bitcointalk.org clone website pops up on google (?) possibly phishing
Post by: shorena on May 13, 2015, 10:32:16 AM
Same as bitcoin-forums (DOT) net as it was reported in the german section[1].

[1] https://bitcointalk.org/index.php?topic=1058533.0