Live data from Hacker News

Turn any link into a suspicious-looking one

verylegit.link

41–50 of 103 posts

Re: Turn any link into a suspicious-looking one

#41
post #25

Earlier quoted context omitted.

pdf and dmg are already pretty scary.

Considering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux. Exe-files has much bigger impact and can be run through emulation on non-Windows systems. I'd say exe is a much better choice.

[deleted]

Re: Turn any link into a suspicious-looking one

#42

Earlier quoted context omitted.

Considering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux. Exe-files has much bigger impact and can be run through emulation on non-Windows systems. I'd say exe is a much better choice.

*Considering most people in the world use Android.

Good point. Doesn't invalidate mine though :)

Re: Turn any link into a suspicious-looking one

#43
post #36
post #25

Earlier quoted context omitted.

pdf and dmg are already pretty scary.

Dmg isn't scary. It's just a disk-image that mounts upon download. You have to manually start any executable on it. And yes, there are users who click on executables carelessly, but those aren't scared by url-parts.

Safari’s DMG behaviour has been problematic in the past: https://www.cnet.com/news/mac-os-xsafari-dmg-vulnerability-r...

Re: Turn any link into a suspicious-looking one

#44
post #5

Is there any way to get SSL error messages in Firefox? https://irc.verylegit.link/0x8c*download()194mobiads(windows... is supposed to redirect to Facebook, and it does if you use HTTP. However, over HTTPS Firefox just gives me a very generic "Secure Connection Failed" message. (Chrome is rather more helpful, giving me "ERR_CONNECTION_CLOSED".)

I get this in Firefox 55:

http://megg.ml/i/771715c9c2445b972e07fa529c6fdb4a.PNG

Note the second line, "The connection to irc.verylegit.link was interrupted while the page was loading." Does that show up for you?

Re: Turn any link into a suspicious-looking one

#48

Earlier quoted context omitted.

Given the risk/reward of, oh, say, finding my systems hosed or users scammed and/or bank accounts drained, vs. missing out on someone's link shortener, I think I'll err on the side of caution. This being an assessment based on local awareness of circumstances.

In what way are you more secure then when someone uses a .com domain? In both cases it is easy to register a url and turn into a malicious site. It really seems you are blackholing parts of the web for no good reason except to exempt yourself from actually performing a security check on the sites on the assumption all other tld's are safe.

Wrong question.

Risk. Reward. Administrative cost.

The first of these I blocked when I looked at the domain and realised that the TLD were registering any old line noise. I'm not going to bother sorting that. Search for other experience turned up Blue Coat.

I subscribe to blocklists, and they update periodically. There are other levels of protection.

When a TLD is 99.9% malware or scams, it's far easier to block it outright. Registrars should take responsibility for what they're registering. Not my problem.

Re: Turn any link into a suspicious-looking one

#49
post #19

Earlier quoted context omitted.

Direct personal realisation, an increasingly take-no-prisoners approach to online abuse, and a considerable amount of evidence from elsewhere that such TLDs are almost entirely void of value. My router doesn't have sufficient resources to list individual hosts, particularly where widespread abuse is found. Plus it's just too much fucking work. BlueCoat Security (now part of Symantec) have been publishing a "Shady TLD…

As an aside, BlueCoat is not a very reputable company. They are responsible for the government-sponsored censorship of Burma's and Syria's internet[1]. Which means that Symantec is currently the (American) company responsible for the censorship blacklist of Syria and Burma. [1]: http://surveillance.rsf.org/en/blue-coat-2/

Two points here, about both the advice and the people giving it.

Regarding the advice, personally I think the advice is bogus. A lot of Mastodon instances have started legitimately using unconventional newTLDs. And I seem to see more URI shorteners, .com and .ru in spam than all the newTLDs put together (zero, from a hacked site, costs less than free). Country K-lining, while attractive to the lazy network operator, only works as an extreme temporary measure in a crisis - spammers adapt, but blocklists tend to only grow. And perhaps Symantec, given their business dealings with Verisign, might not be a 100% neutral party in making recommendations seemingly targeted primarily at severely disrupting the present and future business of cheaply-available TLDs?

Regarding Blue Coat, research shows Blue Coat devices are also used in the censorship/mass surveillance programmes of: Russia, UAE, Bahrain, Iran, and even China. Please also remember Blue Coat devices intercept, log and parse near-everything that goes through them. That puts them at a significantly elevated security risk above a network which didn't have them at all. I know I would find it unethical to report any vulnerabilities to that vendor, and I know I am not the only one who thinks so. And middleboxes like that are incredibly frustrating to the interoperability of the internet and present probably the single biggest hurdle to progress in internet protocols - ask someone in the IETF TLS Working Group currently working on TLS 1.3 just exactly what they think of them!

Re: Turn any link into a suspicious-looking one

#50

This: secure.verylegit.link/warez737speedupurpc.gif.pdf (example from site) doesn't look dodgy to me at all. I'd have no qualms clicking on it, because my browser and I can handle suspicious websites. (Especially ones ending pdf.) Something that would give pause would be: https://tinyurl.com/2ea2mu4?command=127.0.0.1/activate I would think...wait a minute... I probably wouldn't click this example.

Good for you. But this is a scary looking link for the average internet browser.
Post reply on HN