8 ms·
Turn any link into a suspicious-looking one
- acbabis 9y agoThis is neat. I'll make sure to use it whenever I post something here or on Reddit. Great work
- BenjiWiebe 9y agoThe suffixes should be exe, com, js, hta, vbs, and so on, for extra evilness.
- troymc 9y agopdf and dmg are already pretty scary.
- josteink 9y agoConsidering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux. Exe-files has much bigger impact and can be run through emulation on non-Windows systems. I'd say exe is a much better choice.
- falcor84 9y agoMy mental pronunciation mechanism cannot stop reading "dmg" as "damage"
- dEnigma 9y agoSame for me. I guess that's what decades of playing with and reading about video games do to your brain ^^
- spiffworks 9y agoYou must be a Richard Herring fan.
- mikkohypponen 9y ago*Considering most people in the world use Android.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- wingerlang 9y agoAs an OSX user, it is fairly amusing when some sketchy ad auto-downloads some "setup.exe" file.
- skocznymroczny 9y agoAs a Windows user, it's amusing when shady websites try to emulate macOS system dialogs, or Android ones.
- mamon 9y agoBut what if you do the same on Linux, with Wine installed? are you vulnerable the same way Windows users are ? I mean: Wine lets you just double-click exe file to run it.
- wingerlang 9y agoNo idea, however I doubt any Linux user with Wine installed would double click some random setup.exe that was auto downloaded.
- fredsanford 9y agoYou are dangerously underestimating stupid...
- cel1ne 9y agoDmg isn't scary. It's just a disk-image that mounts upon download. You have to manually start any executable on it. And yes, there are users who click on executables carelessly, but those aren't scared by url-parts.
- robin_reala 9y agoSafari’s DMG behaviour has been problematic in the past: https://www.cnet.com/news/mac-os-xsafari-dmg-vulnerability-reported-turn-off-automatic-opening-of-safe-files-to-prevent/ https://www.cnet.com/news/mac-os-xsafari-dmg-vulnerability-r...
- evilDagmar 9y agoUhh... It mounts after downloading? Aside from that I doubt (or don't want to believe) that's what's happening... Doesn't that sound inherently dangerous to you? We've seen files that could infect Windows machines just from having the file browser look directly at them.
- dredmorbius 9y agoI've DNS blackholed the entire .link TLD, along with .science, .country, .click, and .rocks. So, there's that. (DNSMasq, router-based blocklist.)
- jessaustin 9y agoDo you care to share the reasons you've taken this decision?
- dredmorbius 9y agoDirect personal realisation, an increasingly take-no-prisoners approach to online abuse, and a considerable amount of evidence from elsewhere that such TLDs are almost entirely void of value. My router doesn't have sufficient resources to list individual hosts, particularly where widespread abuse is found. Plus it's just too much fucking work. BlueCoat Security (now part of Symantec) have been publishing a "Shady TLD series". https://www.symantec.com/connect/blogs/floating-down-stream-shady-tld-research-part-17 https://www.symantec.com/connect/blogs/floating-down-stream-... Basically: to 2-3 nines, these TLDs are nothing but trouble. If they can't clean up their own acts, fuck 'em. And let that be warning to other TLD registrars.
- cyphar 9y agoAs an aside, BlueCoat is not a very reputable company. They are responsible for the government-sponsored censorship of Burma's and Syria's internet[1]. Which means that Symantec is currently the (American) company responsible for the censorship blacklist of Syria and Burma. [1]: http://surveillance.rsf.org/en/blue-coat-2/ http://surveillance.rsf.org/en/blue-coat-2/
- dredmorbius 9y agoTaken into consideration. Though this doesn't speak to the specific analysis of TLDs referenced here.
- AlyssaRowan 9y ago
- nandhp 9y agoIs there any way to get SSL error messages in Firefox? https://irc.verylegit.link/0x8c*download()194mobiads(windows8!downloader.sh.exe https://irc.verylegit.link/0x8c*download()194mobiads(windows... is supposed to redirect to Facebook, and it does if you use HTTP. However, over HTTPS Firefox just gives me a very generic "Secure Connection Failed" message. (Chrome is rather more helpful, giving me "ERR_CONNECTION_CLOSED".)
- SimeVidas 9y agoClick the (i) icon to the left of the URL in the address bar, the the `>` button, then “More information” at the bottom. The technical details say the connection is not encrypted.
- nandhp 9y agoYes, I found that, but that's not even an inadequate error message -- it's just wrong. Firefox has no way to tell if the connection is encrypted or not because the connection is being dropped while the encryption is being established.
- srett 9y agoSo a connection that doesn't exist cam hardly be encrypted now can it? Scnr But yeah I noticed this trend too in browsers, it's getting harder to get to the technical bits every time they try to make these warnings more user friendly. I usually switch to openssl s_client in a terminal at this point.
- reitanqild 9y agoA general trend. I've been aware of it since Linus Torvalds pointed out that so called "ux-improvements" were actually ux problems back in gnome 2. UX-ers here (hopefully there must be a few ones from Google and Mozilla here): please help stop this long trend of dumbification. I'm not asking you to make it like bash and vim just to stop hiding menus, removing settings etc etc.
- SimeVidas 9y agoI get “Secure Connection Failed”in Firefox Nightly when clicking on the demo link.
- qume 9y agoWoz would love this, I hope he gets to see it
- rjbrock 9y agoA similar site has been around for a long time: http://www.shadyurl.com/ http://www.shadyurl.com/ example: google.com -> http://www.5z8.info/dogs-being-eaten_x2r3rq_5waystokillwithamelon http://www.5z8.info/dogs-being-eaten_x2r3rq_5waystokillwitha...
- auscompgeek 9y agoFunny you should mention that. The author actually attributes ShadyURL at the bottom of the project README: https://github.com/defaultnamehere/verylegit.link https://github.com/defaultnamehere/verylegit.link
- tcpdump 9y agothanks for sharing this utility. Which I see as even more unique than the OP utility, as it goes further to obfuscate the domain name to one which truly appears "shady".
- mlacher 9y agoI made shadyurl! The subdomain feature in this is great. Also cool it has an API. Though with the amount shadyurl was abused by phishers, I'd be interested to see how long an API stays viable.
- carbocation 9y agoIt's kind of wild that "SHADY URL" is something phishers want to use. But, in the end I guess it's all about finding a domain that isn't tied to them?
- eternauta3k 9y agoSimilar to 419 scams, shady links/propositions are a good way to select the people who are easy to trick.
- mlacher 9y agoYeah that's my best guess. I was shocked how much it was used for scams. Might also be possible the link is so suspicious looking it's actually more intriguing to click.
- Mayzie 9y agoDoesn't work for any HTTPS site.
- Markoff 9y agowhat is purpose? to confuse average user so he matter click on genuine shady links? seem dumb on same level as put bodies in blood next to road to check if people stop
- kinkrtyavimoodh 9y agoI think the purpose is just some good old harmless fun.
- tcpdump 9y agoI agree!
- m0atz 9y agoHow is this top of hacker news???
- LeoNatan25 9y agoPeople have a sense of humor, and this is a fantastic meta joke. Why so serious?
- superflyguy 9y agoThis site doesn't like jokey comments, so how are pointless jokey links tolerated? It's not like the linked to site is making a serious point in a light hearted way.
- matt_wulfeck 9y agoBecause the joke is actually a utility, and I for one plan to share links to others with it to continue the fun (can't be done with a witty/funny comment).
- CodeWriter23 9y agoNo, 10-20 humorless users on HN don't like jokey comments.
- gus_massa 9y ago> This site doesn't like jokey comments, Agree > so how are pointless jokey links tolerated? This is a small technical project. It requires some minimal level of technical abilities. A variation of this may be useful. (But I can't think any useful variation now.) So I think it's a good submission, perhaps to get 50-100 points, and a #20 in the front page. I think that 250 points and the #1 in the front page is too much, but whatever. [not a quote] So a page with a funny domain with a static text that says "YES" or "NO" is a good submission? Nah. This is has a very low level of technical content. But if the text is determined by the blockchain, or user votes, a sensor, or something it may be good enough. But it would be better to submit a blog post explaining the projects.
- 9y ago
- logicallee 9y agoThis: secure.verylegit.link/warez737speedupurpc.gif.pdf (example from site) doesn't look dodgy to me at all. I'd have no qualms clicking on it, because my browser and I can handle suspicious websites. (Especially ones ending pdf.) Something that would give pause would be: https://tinyurl.com/2ea2mu4?command=127.0.0.1/activate https://tinyurl.com/2ea2mu4?command=127.0.0.1/activate I would think...wait a minute... I probably wouldn't click this example.
- swampthinker 9y agoGood for you. But this is a scary looking link for the average internet browser.
- logicallee 9y agoI disagree, because it literally says "secure.verylegit.link". Those are not negative words. If this seemed suspicious to the people you're talking about, nobody would start a letter to them with the words, " Please permit me to make your acquaintance in so informal a manner. This is necessitated by my urgent need to reach a dependable and trust wordy foreign partner. This request may seem strange and unsolicited but I will crave your indulgence and pray that you view it seriously. " (I found this example online.) So, I simply disagree that the example produced looks suspicious. It looks fine. Further, I wouldn't even think twice before clicking it. The example I quoted simply doesn't look suspicious. (Because pdf is a 'safe' filetype.) I don't think it would give the average Internet user pause, either.
- TheSpiceIsLife 9y agoThe example I quoted simply doesn't look suspicious. (Because pdf is a 'safe' filetype.) Safe? https://www.cvedetails.com/vulnerability-list/vendor_id-53/product_id-497/Adobe-Acrobat-Reader.html https://www.cvedetails.com/vulnerability-list/vendor_id-53/p...
- logicallee 9y ago
- dingo_bat 9y agoUnable to open in Edge: http://imgur.com/a/nBAne http://imgur.com/a/nBAne
- pmiller2 9y agoMods, thanks for changing the title. It was screwing with the layout on mobile.
- swetabhsuman8 9y agoIMPORTANT THINGS TO KNOW ABOUT RANSOMWARE https://hackernucleus.com/important-things-to-know-about-ransomware/ https://hackernucleus.com/important-things-to-know-about-ran...
- OJFord 9y agoIf I were trying to send someone to my nefarious website, I'd definitely now wrap the link in this, so that the savvy viewer would think it's a harmless verylegit.link...
- sleepychu 9y agoYou already have that same deal with bit.ly and friends. http://bit.ly/2saifoB http://bit.ly/2saifoB http://bit.ly/2t5xNhB http://bit.ly/2t5xNhB Which is safe and wonderful and which is dangerous?
- Programmatic 9y agoRequestPolicy Continued in FireFox, and perhaps other plugins that control/restrict cross-site requests, asks for permission before redirecting to superdodgysite.com and safeandwonderfulsite.com. It's not a feasible solution for the masses, but I really like the control over browsing that it gives.
- eganist 9y agoFor the uninitiated: just add a + to the end of any bitly URL to expose metrics and preview the destination. http://bit.ly/2saifoB+ http://bit.ly/2saifoB+ http://bit.ly/2t5xNhB+ http://bit.ly/2t5xNhB+
- majewsky 9y agoProduces an empty page for me thanks to Noscript. I mean, I'm sort of used to this bullshit by now, but it's particularly egregious since this feature's audience is specifically the tinfoil crowd.
- eganist 9y agoIf your research suggests there's a market for a url shortener which uses no JS for analytics etc., you're quite empowered to start one.
- 9y ago
- alexdrans 9y agoHi, would you please consider paramaterising the input in the URL so that I can use it with Chrome's Omnibar?
- tcpdump 9y agovery nice!
- amelius 9y agoI'd like a way to get some statistics, e.g. how many people clicked the link, etc. That might even be useful when posting links to HN.
- pavlakoos 9y agoBut what for? So that people don't click it?
- Retr0spectrum 9y agoThis could potentially be useful to scammers, to pre-filter out the kind of people who click on shady links.
- zeep 9y agoredirect to about:config -> http://hey.look.a.verylegit.link/765ip-stealer_.json.zip http://hey.look.a.verylegit.link/765ip-stealer_.json.zip and get a Corrupted Content Error (edit: under Firefox)
- deleted 9y ago[deleted]
- btschaegg 9y agoHow does it work? Due to rapid advancement in dark ritual technology, the programming community has streamlined the Development and deployment of unspeakable eldritch horrors. Using robust open-source libraries like a sack of live geese, websites like this one can be developed with far more efficient sacrificial rituals than ever before. We're still stuck on the version with really inefficient sacrifical rituals though, due to comp͆aͭatib̊i̼͕l̈̿i̮̜t̚y̅ ͊i͋s̾s̢͈͠u̶e̛̊s̼̃. Not that I'm in need for an URL shortener, but I really like the style it's "advertised" in :-)
- deleted 9y ago[deleted]
- rkuykendall-com 9y agoI built this years ago when I made it up during an IM conversation with a friend and we realized it wasn't taken: http://shadydownloads.com/ http://shadydownloads.com/