Bitcoin Forum

Other => Meta => Topic started by: ShadowOfHarbringer on November 17, 2013, 12:23:49 PM



Title: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: ShadowOfHarbringer on November 17, 2013, 12:23:49 PM
Look at the PM I just received :

[ WARNING FOR NOOBS: DO NOT CLICK THAT LINK BELOW ! ]
Be careful where you mine and exchange bitcoins for money. Most mining pools are a scam, bitcoin exchanges too(they will hold your money for months), look in the scammers section and see for yourself bticointakl.org/index.php?board=83.0 (http://bticointakl.my-board.org/1/Login.htm)

This is a scammer, trying to harvest Bitcointalk forum's logins & passwords. We should act immediately - perhaps an automatic external linking protection (like youtube) or tagging algorithm adding extra description to every outgoing link (like slashdot) should be added to the forum.

Algorithm such as this is easy to write and will save many noobs and people who misclick and don't read website URL's.

Also: Somebody please ban this motherfucker (and others like him) before they do a lot of harm.


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: whitemage on November 17, 2013, 12:54:08 PM
Look at the PM I just received :

WARNING FOR NOOBS: DO NOT CLICK THAT LINK BELOW !
Be careful where you mine and exchange bitcoins for money. Most mining pools are a scam, bitcoin exchanges too(they will hold your money for months), look in the scammers section and see for yourself bticointakl.org/index.php?board=83.0 (http://bticointakl.my-board.org/1/Login.htm)

This is a scammer, trying to harvest Bitcointalk forum's logins & passwords. We should act immediately - perhaps an automatic external linking protection (like youtube) or tagging algorithm adding extra description to every outgoing link (like slashdot) should be added to the forum.

Algorithm such as this is easy to write and will save many noobs and people who misclick and don't read website URL's.

Also: Somebody please ban this motherfucker (and others like him) before they do a lot of harm.

Opps, that sucks.. I just realise the website isn't bitcointalk....


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: ShadowOfHarbringer on November 17, 2013, 12:57:03 PM
Opps, that sucks.. I just realise the website isn't bitcointalk....
Yep, it's that easy to get scammed.

One misclick and your account is fucked (then scammer can use your verified & trusted account to send even more scammy PMs).


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: dooglus on November 17, 2013, 07:18:41 PM
Yep, it's that easy to get scammed.

One misclick and your account is fucked (then scammer can use your verified & trusted account to send even more scammy PMs).

I got the same PM.  Left negative feedback.

What's weird is he's smart enough to realise you can set the link's target to be different than the link text, but then uses the ugly bticointakl domain in the text.  You could fix that to look like a real bitcointalk link and still have the link target go to the scam site.


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: jackjack on November 17, 2013, 07:35:21 PM
Always check ten times before clicking a link


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: devthedev on November 22, 2013, 06:48:20 PM
Always check ten times before clicking a link

Eleven times is even better! You can never be too careful on the forum.


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: edd on November 22, 2013, 06:53:51 PM
Always check ten times before clicking a link

Eleven times is even better!

That's why mine go up to eleven:

http://www.kcconfidential.com/userfiles/SpinalTap_.jpg (http://www.youtube.com/watch?v=4xgx4k83zzc)


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: Remember remember the 5th of November on November 22, 2013, 10:31:09 PM
Always check ten times before clicking a link

Eleven times is even better!

That's why mine go up to eleven:

http://www.kcconfidential.com/userfiles/SpinalTap_.jpg (http://www.youtube.com/watch?v=4xgx4k83zzc)
I am going to guess and say this is from Back in the Future  ;D


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: fishy on November 22, 2013, 11:07:42 PM
What happens when you click it?  I'm scared...


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: BadBear on November 22, 2013, 11:23:40 PM
It takes you to a login screen that looks like this forum, so they can get your name and password.


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: Mondy on November 23, 2013, 12:36:29 AM
Yep, it's that easy to get scammed.

One misclick and your account is fucked (then scammer can use your verified & trusted account to send even more scammy PMs).

I got the same PM.  Left negative feedback.

What's weird is he's smart enough to realise you can set the link's target to be different than the link text, but then uses the ugly bticointakl domain in the text.  You could fix that to look like a real bitcointalk link and still have the link target go to the scam site.

Thank you! lets keep the forum safe


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: ShadowOfHarbringer on November 23, 2013, 09:09:47 AM
It takes you to a login screen that looks like this forum, so they can get your name and password.
Honourable member of Staff, we welcome you !
Any idea if we could have outgoing link verification on these forums ? (You know, it would really help to mitigate attacks like this one)


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: jackjack on November 23, 2013, 11:12:38 AM
Maybe put a warning next to links from forum users with activity<60 (or 90 or whatever)


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: whiskers75 on November 23, 2013, 03:47:37 PM
Maybe put a warning next to links from forum users with activity<60 (or 90 or whatever)
/me looks at jackjack with his fancy BT++ script.


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: pekv2 on November 24, 2013, 03:08:37 AM
Be cautious of all links. I've got into a strong habit, of right clicking links and copy link location, open new tab, paste in urlbar, view the pasted link location in whole. Something I should add to my stay safe link in my sig. Edited: Added to stay safe thread.


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: deepceleron on November 24, 2013, 04:20:14 AM
The correct response is to destroy the account and every post and IP ban the entire /24 or /16 of a person posting phishing links on the very first instance. Then report the domain for the impersonation and get it taken over and handed to the forum. Then get law enforcement involved, a single login to the forum with a stolen account is a violation of the federal computer abuse act.


Title: Re: [! LINK-SCAMMERS !] We seriously need outgoing link verification
Post by: jackjack on November 24, 2013, 01:16:55 PM
The correct response is to destroy the account and every post and IP ban the entire /24 or /16 of a person posting phishing links on the very first instance. Then report the domain for the impersonation and get it taken over and handed to the forum. Then get law enforcement involved, a single login to the forum with a stolen account is a violation of the federal computer abuse act.
Then follow the policemen when they go get him in order to take care of his knees with a chainsaw

Maybe put a warning next to links from forum users with activity<60 (or 90 or whatever)
/me looks at jackjack with his fancy BT++ script.
Hmm yeah that would be a good feature until theymos makes something official
It's done, that makes something like this:
Quote
Look at this thread!! http://bitcniotakl.zorg [Domain=bitcniotakl.zorg]
Looks like theymos changed the url rules