Bitcoin Forum
June 19, 2024, 04:04:56 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: [BEWARE!] Bitcointalk Credential Phishing Attack -- Targeting Collectibles  (Read 456 times)
blucepheus (OP)
Copper Member
Full Member
***
Offline Offline

Activity: 536
Merit: 214



View Profile
May 27, 2021, 03:43:44 AM
 #21

If I PM this (to my Mobile):
Code:
Test fake URL:
[url=thisurldoesntexistttt.com]https://bitcoin talk.org/index.php?topic=5339312[/url]
I receive this:
Quote
Theymos prevents fake Bitcointalk link descriptions.

PM to the user with a link that appears to be a valid page on the forum (hint, it's not -- see stage 2)
Can you forward me the PM? I'm curious why theymos' fix didn't work here. Was there a non-ascii character in the it?
If that's the case, maybe theymos can fix that too:
Done. I only did the ones that look really similar to Latin characters, and it only applies to English sections. It's done at display time, so it's retroactive.
Although it probably won't work for PMs that aren't in English.

Just forwarded to you. Thanks for investigating!
LoyceV
Legendary
*
Offline Offline

Activity: 3346
Merit: 16842


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
May 27, 2021, 08:05:45 AM
Merited by blucepheus (2)
 #22

Just forwarded to you. Thanks for investigating!
This is what the URL looks like in your PM: https://bitcointalk.oгg/index.php?topic=5338607.60. But if I post it, theymos converts it into normal characters again so you don't see anything special.** Click loyce.club/other/non-ascii.txt to see what it looks like after saving in a text file.
The word "bitcointalk" is normal, the "org" has a non-ascii character.

In Google's search field it looks almost normal:
__________________________________________________
Image loading...
In DuckDuckGo's search field the different "r" is easier to notice:
___________________________________________________________________
Image loading...
If you search the fake "oгg" on Google, you'll notice the difference.
It's a smart trick, and I don't think it can be prevented without making PMs in certain languages impossible.

** I was wrong, this character doesn't get replaced!

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!