Live data from Hacker News

Turn any link into a suspicious-looking one

verylegit.link

71–80 of 103 posts

Re: Turn any link into a suspicious-looking one

#72
post #10

A similar site has been around for a long time: http://www.shadyurl.com/ example: google.com -> http://www.5z8.info/dogs-being-eaten_x2r3rq_5waystokillwitha...

thanks for sharing this utility. Which I see as even more unique than the OP utility, as it goes further to obfuscate the domain name to one which truly appears "shady".

Re: Turn any link into a suspicious-looking one

#73

Earlier quoted context omitted.

Considering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux. Exe-files has much bigger impact and can be run through emulation on non-Windows systems. I'd say exe is a much better choice.

As an OSX user, it is fairly amusing when some sketchy ad auto-downloads some "setup.exe" file.

But what if you do the same on Linux, with Wine installed? are you vulnerable the same way Windows users are ? I mean: Wine lets you just double-click exe file to run it.

Re: Turn any link into a suspicious-looking one

#74
post #15

Earlier quoted context omitted.

Should also consider .top. It's along with .science as the biggest offenders for me.

That's on Bluecoat's list. My set (dnsmasq format): # Shady TLDs (see BlueCoat) address=/.accountant/0.0.0.0 address=/.christmas/0.0.0.0 address=/.click/0.0.0.0 address=/.country/0.0.0.0 address=/.cricket/0.0.0.0 address=/.date/0.0.0.0 address=/.download/0.0.0.0 address=/.faith/0.0.0.0 address=/.gdn/0.0.0.0 address=/.gq/0.0.0.0 address=/.kim/0.0.0.0 address=/.link/0.0.0.0 address=/.loan/0.0.0.0 address=/.mom/0.0.0.0…

.XYZ is used by Google's parent company Alphabet inc. I thought that gave .XYZ a bit more street cred, I guess not.

https://abc.xyz

Re: Turn any link into a suspicious-looking one

#75

Earlier quoted context omitted.

Good for you. But this is a scary looking link for the average internet browser.

I disagree, because it literally says "secure.verylegit.link". Those are not negative words. If this seemed suspicious to the people you're talking about, nobody would start a letter to them with the words, " Please permit me to make your acquaintance in so informal a manner. This is necessitated by my urgent need to reach a dependable and trust wordy foreign partner. This request may seem strange and unsolicited but…

The example I quoted simply doesn't look suspicious. (Because pdf is a 'safe' filetype.)

Safe?

https://www.cvedetails.com/vulnerability-list/vendor_id-53/p...

Re: Turn any link into a suspicious-looking one

#76
post #55
post #5

Is there any way to get SSL error messages in Firefox? https://irc.verylegit.link/0x8c*download()194mobiads(windows... is supposed to redirect to Facebook, and it does if you use HTTP. However, over HTTPS Firefox just gives me a very generic "Secure Connection Failed" message. (Chrome is rather more helpful, giving me "ERR_CONNECTION_CLOSED".)

Where did you get that link? Was it one of the sample links? I don't think those are real links. But if you type in https://facebook.com and click "Make it look dodgy" it will give you a real link. http://hey.look.a.verylegit.link/malware-425iphone)ip-steale... (.docx.html.rar Edit: Although it appears Hacker News decided to mangle this link that I posted. Apparently it's not happy about mismatched parenthesis in lin…

Markdown uses parenthesis? HN software parses markdown in comments to format them?

Re: Turn any link into a suspicious-looking one

#77

Earlier quoted context omitted.

I disagree, because it literally says "secure.verylegit.link". Those are not negative words. If this seemed suspicious to the people you're talking about, nobody would start a letter to them with the words, " Please permit me to make your acquaintance in so informal a manner. This is necessitated by my urgent need to reach a dependable and trust wordy foreign partner. This request may seem strange and unsolicited but…

The example I quoted simply doesn't look suspicious. (Because pdf is a 'safe' filetype.) Safe? https://www.cvedetails.com/vulnerability-list/vendor_id-53/p...

Yes, safe. I open it safely in Chrome (I just click, Chrome opens it natively in the same view) and the chance someone is going to burn a PDF zero-day for chrome on a random link I come across is vanishingly small.

You can open PDF files in Chrome. Even malicious ones. It's okay.

Re: Turn any link into a suspicious-looking one

#78

Earlier quoted context omitted.

People have a sense of humor, and this is a fantastic meta joke. Why so serious?

This site doesn't like jokey comments, so how are pointless jokey links tolerated? It's not like the linked to site is making a serious point in a light hearted way.

> This site doesn't like jokey comments,

Agree

> so how are pointless jokey links tolerated?

This is a small technical project. It requires some minimal level of technical abilities. A variation of this may be useful. (But I can't think any useful variation now.)

So I think it's a good submission, perhaps to get 50-100 points, and a #20 in the front page. I think that 250 points and the #1 in the front page is too much, but whatever.

[not a quote] So a page with a funny domain with a static text that says "YES" or "NO" is a good submission?

Nah. This is has a very low level of technical content. But if the text is determined by the blockchain, or user votes, a sensor, or something it may be good enough. But it would be better to submit a blog post explaining the projects.

Re: Turn any link into a suspicious-looking one

#79
post #55

Earlier quoted context omitted.

Where did you get that link? Was it one of the sample links? I don't think those are real links. But if you type in https://facebook.com and click "Make it look dodgy" it will give you a real link. http://hey.look.a.verylegit.link/malware-425iphone)ip-steale... (.docx.html.rar Edit: Although it appears Hacker News decided to mangle this link that I posted. Apparently it's not happy about mismatched parenthesis in lin…

Markdown uses parenthesis? HN software parses markdown in comments to format them?

HN doesn't use Markdown, it has its own eccentric and much more limited markup system.
Post reply on HN