What happened:: The website 0day.today falsely presents itself as an owner of 0days exploits.
This is how the scam works:
1. The site has a legitimate free section with 1-day exploits (posted by real researchers)
2. The site has a restricted area with allegedly 0days exploit.
3. User need to pay USD1000 in order to view the premium section with the 0days.
4. User can select an exploit from the available list (see screenshot below) and should be able to download the 0day exploit.
5. Once user pays for the exploit, inj3ct0r disappears and account is blocked
This is a very sophisticated scam. There were some technical details that make me seriously suspect him, but I never believed such a scam could actually exist.
I saw the scam report at
https://bitcointalk.org/index.php?topic=343501.0 – but is seems like the reporter has doubtful reputation himself (
https://bitcointalk.org/index.php?topic=343501.msg3824461#msg3824461)
There is also a video at
https://www.youtube.com/watch?v=rHv0MFsHCTM , but I didn’t understand why the presented picture is a scam.
The only thing I’d like to achieve in this post is the first reliable scam report of 0day.today .
I feel terrible seeing legitimate researchers using this platform to post their work without knowing they are passively donating to crime.
I am willing the share any detail and every evidence so the last person who got scammed would be me.
Reference Link: https://bitcointalk.org/index.php?topic=343501.0https://www.youtube.com/watch?v=rHv0MFsHCTMAmount Scammed: 4.76 BTC/$3000 + 1.76 BTC/$1000 = total 6.5 BTC/$4000 Payment Method:Bitcoins Proof of Payment: https://blockchain.info/tx/bceb5cce2a00d31290b3b9cef9e536fe785284252875533020638ac3f18ca0d0https://blockchain.info/tx/8c90f72c5e14d53d9d7992614468cff43ae933b16f07373654eb301f9a8064fePM/Chat Logs: Screenshots of the final email exchange were my account was blocked:
https://s22.postimg.io/jvmif33pt/Screenshot_from_2016_09_08_21_32_42.pnghttps://s4.postimg.io/vsyvpl2fx/Screenshot_from_2016_09_08_21_34_03.pngThe entire email exchange is listed at
http://pastebin.com/yNM5eMb6 Here is what listed on the premium page (the so called “exploits”)
https://s10.postimg.org/om57egjax/Screenshot_from_2016_09_08_10_43_25.png Additional Notes: Stay away! The scam is very sophisticated, as the free section seems reliable – making this scam allegedly legitimate Thank you
Anthony