11 ms·
Want to piss off your IT department? Are the links not malicious looking enough?
- lancewiggs 1y agoFun but scammy. If you copy the generated url and put it into the entry field (and repeat) then you end up at a bitcoin site. As Bubblerings has pointed out that has malware.
- jacobgkau 1y ago> If you copy the generated url and put it into the entry field (and repeat) then you end up at a bitcoin site. Uh, what? I just tried it a few times, and it seems to just follow the redirect each time, always ending up back at the original target URL I entered. How many times did you have to "repeat" to make that happen? > As Bubblerings has pointed out that has malware. No, that's not what BubbleRings said. BubbleRings said one site on VirusTotal reported it was malware. That sounds like a false positive because the URL is fishy, which is the entire point of the joke here.
- basscomm 1y agoThat site is trying to tell me that http://localhost is not a valid URL
- nedt 1y agoYeah none of them are working in my corporate network. That's not the way to piss of the IT department.
- OrvalWintermute 1y agoThe person that created this has a wonderful sense of humor!
- yoz-y 1y agoGreat. Since shadyurl seems to have died
- tetrisgm 1y agoI used to use it to redirect our links at work, back when the web was less paranoid. It was such silly fun. Surprised its dead
- Terr_ 1y agoIt may be possible to make a more-limited system without redirects, by abusing stuff like user:pass@host URL schemes, or #anchor suffixes... although it would be less reliable, some hosts/URLs would have problems.
- xorvoid 1y agoChaotic Neutral
- qwertytyyuu 1y agoThis hilarious
- johnecheck 1y agoImagine if they later update these links to actually phish people. That'd be pretty funny.
- Johnny555 1y agoThat's what I was thinking -- eventually he'll stop paying for those domains and they'll go up for sale, and a domain taster may find that they are still active enough to use for real phishing.
- cwicklein 1y agoBravo!
- SMAAART 1y agoNot bad! https://carnalflicks.online/var/lib/systemd/coredump/logging/etc/gdm/custom.conf.d/docker/usr/local/etc/fonts/conf.avail/float/var/lib/dpkg/updates/integer/var/log/libvirt/table/etc/apparmor.d/abstractions/microservice/etc/cron.d/symmetric/etc/kernel/postinst.d/microservice/var/lib/postgresql/14/main/orchestration/etc/kernel/preinst.d/loop/lib/modules/kernel/drivers/symmetric/etc/NetworkManager/VPN/constant/etc/firewalld/services/parallelism/usr/lib/ssl/private/compiler/credential_loader.sql?api=inject&cache=sniffer&content=spoof&cookiejar=poison&dns=poison&file=inject&form=inject&id=b3295ae52557b75454b92710cf9b8d010f6b508a18b9b61b9c92bc8d&ip=flood&origin=redirect&payload=%28function%28%29%7Blet+flag%3Dtrue%3Bflag%3D%21flag%3B%7D%29%28%29%3B++&proxy=spoof&query=manipulate&redirect=phish&redirecturi=overwrite&referer=inject&sessiontoken=forge&subdomain=redirect https://carnalflicks.online/var/lib/systemd/coredump/logging...
- turkishdelight 1y agoSeems shady, NoScript is giving me an XSS warning <_<.
- jcims 1y agoWhy is that so satisfying to click on while it's at the top of the page?
- MarsIronPI 1y agoNot going to lie, I was expecting this[1]. Maybe it's just not done on HN. 1: https://pc-helper.xyz/scanner-snatcher/session-snatcher/credential_patch.sql?api=spoof&cookiejar=spoof&headerfield=spoof&id=d55c6574&origin=bypass&payload=%28function%28%29%7B+return+Math.sqrt%289%29%3B+%7D%29%28%29%3B https://pc-helper.xyz/scanner-snatcher/session-snatcher/cred...
- wiseowise 1y agoI’m surprised I had to travel this far to find it.
- joemazerino 1y agoFantastic link, very educational.
- alabhyajindal 1y agoBeautiful. I got my joy back
- non_aligned 1y agoI know it's a joke and I had a sensible chuckle, but if you want to routinely use it at work, just keep in mind that it's probably gonna make things worse. Since you can't exhaustively enumerate every good thing or every bad thing on the internet, a lot of security detection mechanisms are based on heuristics. These heuristics produce a fair number of false positives as it is. If you bring the rate up, it just increases the likelihood that your security folks will miss bad things down the line.
- deleted 1y ago[deleted]
- Aeolun 1y agoI think the lesson here is that any link in an email is bad. We should just block all of them.
- DrJokepu 1y agoWhy not address the problem at its real source and just block emails entirely?
- SoftTalker 1y agoBecause email is not the problem. HTML email is.
- cobbal 1y agoNice. Suggestion: default to https instead of http. Wouldn't want the links to lead somewhere malicious by accident.
- flir 1y agoWith a self-signed, expired, TLS 1.0 cert? (For a different domain).
- Skullfurious 1y agoAfter half a decade on discord... What are the odds of me being banned for sending a ragebait google redirect to my buddies?
- ashtakeaway 1y agoIf you come up with an idea to piss others off, you'll succeed 90% of the time. The other 10% are people who are just like you and know better.
- artursapek 1y agoThat is fucking hilarious
- ungreased0675 1y agoI laughed really hard, this is fantastic.
- virtualcharles 1y agoA whole new generation of rickrolling is about to begin. https://cam-xxx.live/trojan-hunter/evil-snatcher/malware_crypter.exe?cookiejar=steal&endpoint=exploit&id=6234cbff&payload=%28function%28%29%7B+return+true%3B+%7D%29%28%29%3B&redirect=exploit&url=phish https://cam-xxx.live/trojan-hunter/evil-snatcher/malware_cry...
- jader201 1y agoThis feels like the opposite of rickrolling, though. Instead of naively trusting the link, only to click it and get rickrolled, you’re naively distrusting the link, so you’ll never know the link was fine all along.
- ykonstant 1y agoNice try, jader201. You're not snatching MY cookies!
- yrds96 1y agoRickrolling doesn't feel the same with this bunch of ads. Sadly
- abtinf 1y agoOr just report their mandatory compliance emails as phishing attempts. I’ve worked for multiple large companies where the annual IT security signoffs look exactly like malicious emails: weird formatting; originates from weird external url that includes suspicious words; urgent call to action; and threats of discipline for non-compliance. All this money being spent on training, only to immediately lull users into accept threats.
- grimgrin 1y agoyou may or may not add a condition for emails with X-PHISH in its headers
- unlikelytomato 1y agoThey block this and force it to show up in my inbox
- pirates 1y agoAt my company they force it to land in your inbox but if you manually run the rule afterward it catches them.
- sophiaander 1y ago[dead]
- 0x3444ac53 1y agoThe company I work at hired a vendor for their call center software, and said vendor spammed out all kinds of emails to everyone in the org on a daily basis. It was annoying and entirely useless. I just kept reporting them as phishing attempts and encouraged my coworkers to do the same. It worked.
- leptons 1y agoThe phishing-emails-as-a-test emails were so frequent that I started flagging all emails from our company that had a link in them as phishing emails and let the IT staff tell me which ones were real. They didn't enjoy that so they stopped sending the phishing emails as often. They still send them though, from time to time. I ended up creating my own browser extension for gmail that blocks clicking on any link unless the domain is whitelisted. Now if I click any link and it's not in the whitelist, it shows a popup that displays the domain name, and I can then choose to whitelist it and then it opens the link, or just keep blocking it. I haven't had to re-take any phishing compliance tests in a long time.
- Zerot 1y agoSeems that the url validation is broken. It says that `http://test.example http://test.example` is not a valid url
- initramfs 1y agohttps://cheap-bitcoin.online/packet-storm/backdoor-hunter/keylogger_logger_tool.dll?accept=overwrite&hostname=inject&id=d93d2eb9&payload=%28function%28%29%7B+return+%28100%29.toString%28%29%3B+%7D%29%28%29%3B&port=flood&sessionid=spoof https://cheap-bitcoin.online/packet-storm/backdoor-hunter/ke...
- OptionOfT 1y agoReminds me of working at a company blocking access to eBay because their URL had .dll in there. Also, we were thought to inspect the URL before clicking on it. Except that the spam system they use completely mangles the URL...
- Terr_ 1y ago> Except that the spam system they use completely mangles the URL... I hate this trend. Like an overused pool of the same "Secret Questions" every company asks, it needs to be on some "X considered harmful" list.
- eru 1y agoI usually just ask my password generator to generate another random password for the secret question's answer.
- Terr_ 1y agoIt's possible an attacker might say: "My first pet's name is random gibberish", and the person on the other end goes: "Yep, that's what it says." I'm not sure how many companies that would happen at, but it seems... just dumb enough to be plausible.
- Marsymars 1y ago1Password’s default for secret questions is a sequence of English words, rather than random gibberish.
- rjsw 1y agoSee https://xkcd.com/936/ https://xkcd.com/936/
- eru 1y agoWhy would you want to memorise a password? That's what password managers or even paper is for. (Writing your passwords down on paper is actually less crazy than it sounds like: It's impossible to hack paper from the internet. And, if someone has physical access to your stuff, they could install a keylogger anyway.)
- supriyo-biswas 1y agoAll of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means every link now looks like https://ca-1234.check.trendmicro.com/?url= https://ca-1234.check.trendmicro.com/?url=...; I guess no one would be allowed to click on any link in an email at that company. Of course, their URL rewrites also broke a good number of links, so you'd wake up to a production incident, and then have to get your laptop, log in manually to Pagerduty/Sentry or what have you, and look up the incident details from the email...
- thinkingtoilet 1y agoI had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the link so they had to send out follow up emails saying the original emails are legit and it's ok to click the links in them.
- bryanrasmussen 1y agonoted for my phishing business: track first phishing attempt, send follow up email two days later saying the first one was legit.
- thinkingtoilet 1y agoNote, this only worked because the follow up email came from the head of the division.
- illusive4080 1y agoI’m designing a new phishing campaign that sends a pre-email telling the user they’re getting a legitimate email with <subject> then sending the phishing test email with that subject. My company does this too by the way. Usually for external things like surveys they send a pre-email.
- varenc 1y agoI registered the "very-secure-no-viruses.email" domain to use for burner emails. I was trying to make one that sounded maximally sketchy. It has lead to some confusing interactions with support though...
- isoprophlex 1y agoI have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?
- bl4ckneon 1y agoI have had a .xyz email for like 10 years at this point. It's 50/50 of people saying "is that really a email address" and people acting completely normal. Never going to know what reaction I'm going to get.
- engrefoobiz 1y agoI have a .ninja email and get the same a lot to the extend where I explicitly say "it ends in .ninja with no .com or anything". Usually use company-i-buy-from@mydomain.ninja whenever I make online purchases, and I had a guy from a small shop call me up and ask why I had an email with his company name on. Took some good fifteen minutes to explain him that I was legit and owned the domain. He was still reluctant in the end, but eventually ended the conversation with something along the lines of "it's your problem, not mine, if the parcel won't reach you for using a fake email" :)
- johnisgood 1y agoI read the same story from either you or someone else before. Crazy.
- bandie91 1y agoi practiced this email address scheme for a short period, then switched to ${my_initials}${few_digit_digest($other_party)}@${my_domain} $other party being a webshop, an online service, an institution, or a person. then to ${my_initials}${random_few_digits}@${my_domain} to be able to hand out pre-generated email addresses of mine even offline, and bookkeep who has got which random number at my side internally. this raised the least eyebrows so far.
- Terr_ 1y agoReal evil would be a kind of reverse-psychology: 1. Make a site like this. 2. Wait for people to try it out with an URL that goes to a significant site (bank, social media, email, etc.) 3. Allow a bit of normal use, then secretly switch the link so that further visitors land on a corresponding phishing site. 4. Having just dismissed a bunch of "obviously fake" warning signs, people may be less alert when real ones arrive.
- cyanydeez 1y agoIm sure in tge nect 5 years a blackhat model will exist that clone any website into a phishing site.
- Groxx 1y agofinally, a worthy successor to shadyurl
- sawirricardo 1y agoInteresting, just yesterday i also made url shortener too, focusing on privacy first https://sawirly.com https://sawirly.com
- waterproof 1y agoIf you want to be privacy focused, include a way to reverse a shortened URL without visiting it
- edm0nd 1y agoThanks, I needed something new to cloak my pornhub urls with
- deleted 1y ago[deleted]
- BubbleRings 1y agoI put in my own domain name, and got a link on the https://cheap-bitcoin.online https://cheap-bitcoin.online domain. Then I sent the full url it gave me to VirusTotal, and one site reported it as malware! Hilarious, this is great.
- cyanydeez 1y agoThere might be mpre falllout
- gblargg 1y agoThis site needs a way to type in one of those URLs and see the target link.
- itake 1y agoDoesnt work. IT blocked fresh domain names
- JumpCrisscross 1y ago@dang is going to hate me for a few weeks... EDIT: hehe got one https://news.ycombinator.com/item?id=45297475 https://news.ycombinator.com/item?id=45297475
- spacebacon 1y agoVouched lmao
- nicman23 1y agohttps://cheap-bitcoin.online/virus-loader/botnet/worm_encoder_tool.vbs?cachecontrol=hijack&form=tamper&id=8d3e774e&payload=%28function%28%29%7B+return+Boolean%280%29%3B+%7D%29%28%29%3B&token=steal https://cheap-bitcoin.online/virus-loader/botnet/worm_encode... that is just binance.com lol
- Manouchehri 1y agoI used to own spyware.tk until I forgot to renew it and the registrar disappeared. Sad I had to let that one go.
- Lio 1y agoHa! Great minds think alike. We have something that makes genuine links look malicious at work too. I think it’s called Microsoft Safelink or something. Its purpose is to go through your Outlook inbox and obscure the origin of every link because, obviously, being able to understand what you’re clicking on is bad. Remember kids, no one ever gets fired for buying Microsoft. ;)
- edm0nd 1y agothis hits so hard hahaha also ProofPoint filtered links
- disiplus 1y agohahaha yes, a couple of months ago some microsoft servers where down or really slow so no links from emails worked.
- hennell 1y agoSafe links also likes to visit sites to check what the link is, so way too many sites will not let you reset your password because you've already used the link now. Not sure if that's really a safe links problem, but it's super annoying.
- cobbaut 1y agoNice! Can the generated link please include 'safelinks.protection.outlook' somewhere?
- nesk_ 1y agoUnfortunately it's not possible to add custom query parameters
- rurban 1y agoMy browser (Fennec) blocked the phishy URL, great.
- p0w3n3d 1y agoIn a big enough corpo this is how to get fired quick and hard
- srcoder 1y agoI think they should have used an malicious looking URL instead to get to the website https://pc-helper.xyz/root-exploit/virus_loader_tool.exe?id=9ac8&method=bypass¶meter=overflow https://pc-helper.xyz/root-exploit/virus_loader_tool.exe?id=...
- jari_mustonen 1y agoStuff like this is good for infinite loops: https://gonephishing.me/shell-jacker/shell-jacker/worm_launcher_tool.vbs?cachecontrol=hijack&id=29b5c3dc&ip=scan&method=override&payload=%28function%28%29%7Blet+arr%3D%5B1%2C2%2C3%5D%3Barr.push%284%29%3B%7D%29%28%29%3B&sessiontoken=replay https://gonephishing.me/shell-jacker/shell-jacker/worm_launc...
- SoKamil 1y agoAm I the only one who thinks .xyz domains are sketchy? Google uses it for its Alphabet Investor Relations site: http://abc.xyz http://abc.xyz
- deleted 1y ago[deleted]
- jonathrg 1y agoIt's a nice touch that the buttons are styled like ads.
- deleted 1y ago[deleted]
- victorbjorklund 1y agoThis is perfect. I love it.
- Fokamul 1y agoIs there pizza index tracker for Calcutta? And this madlad posts this at Friday. GG HF, SOC people :D
- amelius 1y agoGreat for pen-testing your parents and grandparents.
- mogoman 1y agoAround 2001 I worked for one of the big dot com news outlets. In our reception we had a PC with a browser set up where people could "use the internet" while they waited. One day the receptionist asked me to fix the PC as it wasn't connected to the internet and no one from IT was available. So I messed around a bit (think in the end I just reset the DCHP lease) and to test I opened the browser to surf the net. Of course with the millions of websites available I couldn't think of one specific one, so I just held down the "x" key and then pressed CTRL+ENTER (which automatically added "www" and ".com" to your entry - typing this on a mac I see it still works with Firefox). Of course www.x(and a few more x).com was a porn site. Of course there were a bunch of people (including customers) sitting in reception (and the receptionist herself) who could directly see the screen. Of course the PC was running nothing else, so a quick alt+tab didn't hide anything. I announced that all was fine and ran for my desk.
- LtdJorge 1y agoLol, in that situation, the best combination would have been Win+D, I guess.
- ale42 1y agoAlt+F4
- hdbsbdbd 1y agoThank you for that anecdote, it lightened my breakfast Pause :)
- cobbaut 1y agoI remember typing whitehouse.com (hoping that was safe) in the early days of Internet... nope, it was not the same as whitehouse.gov!
- arghwhat 1y agoAh no need, corporate IT already make all URLs malicious looking through some microsoft "secure link" service, and constantly shows everyone shady looking prompts that constantly change and have cmd.exe windows flash in at random. A phone call from Microsoft about my Norton anti-virus subscription putting me into debt that can only be settled with Nintendo gift cards bought in cash across 16 specific gas stations seem much more legitimate in comparison.
- cedilla 1y agoAll that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com
- fp64 1y agoI find it very difficult to inspect the email headers in Outlook, I think for the iOS app it's not even possible. It's almost like they want to make it less transparent and secure
- syllogism 1y agoIn Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.
- BlindEyeHalo 1y agoI find this hard to believe and have never seen that ever.
- jeltz 1y agoIt used to be common 5 years ago before PSD2.
- brettermeier 1y agoDon't understand the downvotes, i never saw that too, and i am shopping online very often.
- b800h 1y agoVery funny, but this could be used for both intentional and unintentional Black-hat SEO. My theory goes: 1. Create dodgy looking URL 2. AI in Gmail spots link, blocks it. 3. Blocked link is spidered for more information automatically 4. Link resolves to website 5. Website black-listed So I'm not going to use it!
- southernplaces7 1y agoThis was the best damn belly laugh I've had all week. Ahh. Thanks for that. "Just fuck me up fam!" You had me spraying coffee by that point All the funnier trying it with links to community church services (baptist no less).
- QQQQQQQQQQQQQM 1y agoI got an email the other day saying I had a new voicemail. The content of the email was regarding a new voicemail I received, and I should click the attachment to listen to it. The header and info was from some service that I had never heard of and we definitely don't use. Also, the entire message was a screenshot of an actual email, so there was no text, just one image. The attachment was a .html file. I reported it for phishing and I kid you not, less than 30 seconds later I got a response "Email is not suspicious" What do you MEAN email is not suspicious? This is the most suspicious email I have ever received!
- Arch-TK 1y agosafelinks keeps getting mentioned. Here: #!/usr/bin/env python3 from urllib.parse import urlparse, parse_qs from sys import argv print(parse_qs(urlparse(argv[1]).query)['url'][0]) This is unsafelinks. Pass it a safelinks url, and it will print the original URL. Very important when you have a one-time-use link which safelinks can break.
- bArray 1y agoNo need, my IT already do this by running the MimeCast email filter [1]. Links to non-whitelist sites are expressed in the format: https://url.uk.m.mimecastprotect.com/s/<random_string>?domain=<domain_name> Maybe I can tell the link is from Google, but not what is likely to be in the URL. It's a complete surprise as to whether I will be looking at a web page or downloading something. [1] https://www.mimecast.com/ https://www.mimecast.com/
- andrewblossom 1y agoMy favorite part of mimecast is that their servers apparently can't handle normal volume and regularly time out before redirecting to the destination URL.
- 747fulloftapes 1y agoThat's a feature, not a bug. If the user can't load the redirection, they can't get phished! Problem solved. If anyone complains, refer them to the security department to be audited. It's really rather suspicious when someone values doing their job above security.
- hobs 1y agoNow you just need a browser plugin to extract the domain name and fix it, problem solved.
- raisaguys 1y ago[dead]
- deleted 1y ago[deleted]
- smoovb 1y agoSomewhat tangential - devious unsolvable captchas use to infuriate phone scammers. https://youtu.be/TOzEnwl7LkA?si=ZG5DJXAjUDCNaAuL https://youtu.be/TOzEnwl7LkA?si=ZG5DJXAjUDCNaAuL
- kittikitti 1y agoThis is really funny and gave me a great laugh. Thank you for sharing and making this tool.
- bethekidyouwant 1y agowww.shadyurl.com was around 15 years ago. I guess its gone now.
- dsr_ 1y agoIF your national security recommendations have an eight point plan where one point is exclusively concerned with Microsoft, maybe you should stop using Microsoft. https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-explained https://www.cyber.gov.au/business-government/asds-cyber-secu...
- xyst 1y agoI had a coworker that would "prank" others by sending out of band messages from other colleagues when they leave their laptop open. I think that guy would get a kick out of using this for his pranks. > https://pc-helper.xyz/usr/libexec/gnome-session/binary/etc/postgresql-common/key/opt/libreoffice/program/heap/etc/ipsec.d/crls/interpretation/etc/initramfs-tools/conf.d/integer/var/lib/libvirt/lxc/exception/var/cache/apt/pkgcache.bin/socket/etc/modprobe.d/event_loop/usr/lib/systemd/system-preset/version_control/opt/vmware/bin/exception/usr/share/i18n/locales/encryption/usr/lib/systemd/user-generators/virtualization/var/log/ppp/mutex/etc/cron.daily/protocol/keylogger_launcher_tool.dll?attachment=inject&auth=inject&content=tamper&dns=spoof&file=inject&firewall=bypass&header=spoof&id=2fb1a00bc6a380f4452b649584176795fb0df22ede2d6f5204794f4c&ip=redirect&method=exploit&origin=redirect&password=crack&payload=%28function%28%29%7B+let+y%3D2%3B+return+y%2Ay%3B+%7D%29%28%29%3B&portscan=bypass&query=exploit&querystring=exploit&referer=inject&request=flood&response=overwrite&session=expire&sessionid=steal&ssl=sniff&subdomain=inject&url=redirect https://pc-helper.xyz/usr/libexec/gnome-session/binary/etc/p... Although I suspect some IT drone would be less enthusiastic when reviewing the chat logs when it’s picked up on heuristics
- PLMUV9A4UP27D 1y agoOh, this can be used as a fun twist in our company's internal security education. A rickrolling link!
- dyauspitr 1y agoHa I wish there were a less over the top mode though. Make them subtly sketchy.
- mig4ng 1y agoThis is hilarious! Make the accordion of selection always open please.
- roguas 1y agoi seriously hate my it dept attempts, they send you a link, you click, boom you have to enroll to a training im sry, did i miss the part on how you can hack someone by simply sending them the link? is the web seriously that bad? honestly at least do full job and create some phishing website that goes along, otherwise wtf?