Bitcoin Forum
May 17, 2024, 12:38:44 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Bitcointalk.org clone website pops up on google (?) possibly phishing  (Read 986 times)
alani123 (OP)
Legendary
*
Offline Offline

Activity: 2408
Merit: 1436


Leading Crypto Sports Betting & Casino Platform


View Profile
May 12, 2015, 08:20:47 PM
Last edit: May 13, 2015, 01:15:50 AM by alani123
 #1

bitcointalk dotNo SEOxyz is probably trying to fool people into giving them the password to their bitcointalk account. The website looks exactly like bitcointalk.org and is accessible through google searches.

Entering a username and a password there will somehow redirect to bitcointalk.org and try to login with the credentials? Can someone from the staff confirm that it is not (or is) affiliated with bitcointalk.org? Because if it's not, we should consider reporting it to google as a phishing website.

Edit: Theymos posted here from his secondery account:

It's not mine. Leeching traffic for ads, phishing, malware, or maybe just bypassing China/Russia's ban of the forum. I strongly recommend not logging in there in any case.

If you end up visiting this website do not put in your login details. We can't be sure about the reason this website was created, but you shouldn't trust it with your login credentials as it's operated by a third party we know nothing about.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
tspacepilot
Legendary
*
Offline Offline

Activity: 1456
Merit: 1078


I may write code in exchange for bitcoins.


View Profile
May 12, 2015, 08:25:39 PM
 #2

Wow, I'm amazed at their ability to mirror so quickly if they're aren't actually a legit version of this forum (even your post in meta appears there!).  Really interested in what the official word is on this one.

Icann wiki says TLD xyz is supposed to be a "truly generic" tld (http://icannwiki.com/.xyz), I had never heard of it before seeing this thread.
alani123 (OP)
Legendary
*
Offline Offline

Activity: 2408
Merit: 1436


Leading Crypto Sports Betting & Casino Platform


View Profile
May 12, 2015, 08:31:15 PM
 #3

Wow, I'm amazed at their ability to mirror so quickly if they're aren't actually a legit version of this forum (even your post in meta appears there!).  Really interested in what the official word is on this one.

Icann wiki says TLD xyz is supposed to be a "truly generic" tld (http://icannwiki.com/.xyz), I had never heard of it before seeing this thread.

.xyz is one of the newly authorised TLDs. The website is indeed a very convincing and dynamic clone of bitcointalk.org but it's SEO is suspiciously good. Makes me think that it's not here to serve as a mirror of bitcointalk.org but instead an attempt to steal people's accounts.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
jbrnt
Hero Member
*****
Offline Offline

Activity: 672
Merit: 500



View Profile
May 12, 2015, 08:44:41 PM
 #4

The xyz forum looks exactly like bitcointalk. Is it a frame redirect and not actually phishing?
chmod755
Legendary
*
Offline Offline

Activity: 1414
Merit: 1020



View Profile WWW
May 12, 2015, 09:37:01 PM
 #5

I just reported it to Google and others for phishing.

RussianRaibow
Hero Member
*****
Offline Offline

Activity: 616
Merit: 500

I AM A SCAMMER


View Profile WWW
May 12, 2015, 09:58:52 PM
 #6

bitcointalk dotNo SEOxyz is probably trying to fool people into giving them the password to their bitcointalk account. The website looks exactly like bitcointalk.org and is accessible through google searches.

Entering a username and a password there will somehow redirect to bitcointalk.org and try to login with the credentials? Can someone from the staff confirm that it is not (or is) affiliated with bitcointalk.org? Because if it's not, we should consider reporting it to google as a phishing website.

It seems they are just domain cloaking. Not using any DB at their end like bitcointa.lk. That is why their threads are getting updated in real time.

I AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMERI AM A SCAMMER
alani123 (OP)
Legendary
*
Offline Offline

Activity: 2408
Merit: 1436


Leading Crypto Sports Betting & Casino Platform


View Profile
May 12, 2015, 10:34:25 PM
 #7

The xyz forum looks exactly like bitcointalk. Is it a frame redirect and not actually phishing?
It doesn't seem like a simple frame. You can check the source of the page and see that the code is similar to the original.

Click this image for a screenshot comparing the first lines of source pages from the two websites

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
tspacepilot
Legendary
*
Offline Offline

Activity: 1456
Merit: 1078


I may write code in exchange for bitcoins.


View Profile
May 12, 2015, 11:31:08 PM
 #8

The xyz forum looks exactly like bitcointalk. Is it a frame redirect and not actually phishing?
It doesn't seem like a simple frame. You can check the source of the page and see that the code is similar to the original.

Click this image for a screenshot comparing the first lines of source pages from the two websites


Most likely they are mirroring from the back-end. I e, you can run curl and print to stdout if you want to republish the source of another site.  I'm also curious if this might be a legit experiment that theymos is doing with changing the TLD or something.
alani123 (OP)
Legendary
*
Offline Offline

Activity: 2408
Merit: 1436


Leading Crypto Sports Betting & Casino Platform


View Profile
May 12, 2015, 11:39:26 PM
 #9

The xyz forum looks exactly like bitcointalk. Is it a frame redirect and not actually phishing?
It doesn't seem like a simple frame. You can check the source of the page and see that the code is similar to the original.

Click this image for a screenshot comparing the first lines of source pages from the two websites


Most likely they are mirroring from the back-end. I e, you can run curl and print to stdout if you want to republish the source of another site.  I'm also curious if this might be a legit experiment that theymos is doing with changing the TLD or something.

This is why I'm suggesting that we should wait for a staff member to give us a hint on what this is before taking action.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
theymos_away
Member
**
Offline Offline

Activity: 82
Merit: 26


View Profile
May 13, 2015, 12:14:09 AM
 #10

It's not mine. Leeching traffic for ads, phishing, malware, or maybe just bypassing China/Russia's ban of the forum. I strongly recommend not logging in there in any case.
ISIS Representative
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
May 13, 2015, 12:25:34 AM
 #11

Theymos can issue a takedown notice if he feels the need too. Glad you notified us about it.
No, there is no such thing as a takedown notice. Most nations do not care about US laws.
tspacepilot
Legendary
*
Offline Offline

Activity: 1456
Merit: 1078


I may write code in exchange for bitcoins.


View Profile
May 13, 2015, 12:27:56 AM
 #12

It's not mine. Leeching traffic for ads, phishing, malware, or maybe just bypassing China/Russia's ban of the forum. I strongly recommend not logging in there in any case.

Well, now we know that it's not something theymos is doing anyway.  Interesting suggestion that they might be somehow trying to provide something legit.  I certainly won't be logging in there.
guitarplinker
Legendary
*
Offline Offline

Activity: 1694
Merit: 1024



View Profile WWW
May 13, 2015, 01:03:25 AM
 #13

Theymos can issue a takedown notice if he feels the need too. Glad you notified us about it.
No, there is no such thing as a takedown notice. Most nations do not care about US laws.
Looks like the domain is registered through a Chinese provider (the whois says it's registered through Xiamen Nawang technology Co., Ltd) so I don't think they would take the site down even if theymos complained. However the fact that it's registered through a Chinese provider could also mean that it is indeed trying to pass Chinese restrictions on the normal Bitcointalk site, as theymos mentioned.
chmod755
Legendary
*
Offline Offline

Activity: 1414
Merit: 1020



View Profile WWW
May 13, 2015, 03:45:35 AM
 #14

Looks like the domain is registered through a Chinese provider (the whois says it's registered through Xiamen Nawang technology Co., Ltd) so I don't think they would take the site down even if theymos complained. However the fact that it's registered through a Chinese provider could also mean that it is indeed trying to pass Chinese restrictions on the normal Bitcointalk site, as theymos mentioned.

There are already several websites mirroring bitcointalk and calling it bitcointalk.xyz should make it quite easy to detect for those who are monitoring the traffic. I think I would use a foreign (non-chinese) company if I tried to bypass the "Great Firewall of China" to avoid getting arrested for doing that.

shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
May 13, 2015, 10:32:16 AM
 #15

Same as bitcoin-forums (DOT) net as it was reported in the german section[1].

[1] https://bitcointalk.org/index.php?topic=1058533.0

Im not really here, its just your imagination.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!