6 ms·
A large collection of fraudulent web stores
- napsterbr 4y agoOff-topic, but something seems dangerously off with urlscan.io (a service I had never heard of before). If I go to urlscan.io and look at the recently scanned sites (which are live-updated), every now and then I can find links with potentially sensitive information. I found OneDrive and SharePoint links. I was unable to actually access the documents in them (it asked me to login), but I could see their content (or metadata) with UrlScan's "live screenshot" feature. At one point, it scanned a "reset password" link with the authentication token in the query string (!). I was able to access that link and I would likely be able to reset the password for that specific user. I won't share the underlying website so others don't go ahead looking for it, but it was for a non-US government service. The impression I have is that some email provider (or perhaps some antivirus software?) is automatically scanning user emails and the links are being shared publicly, alongside a "live screenshot". I might be missing something, but this is weird.
- chair6 4y agoNope, not missing something.. it has been a problem for GitHub (https://news.ycombinator.com/item?id=30348980 https://news.ycombinator.com/item?id=30348980) and others (https://portswigger.net/daily-swig/urlscan-io-api-unwittingly-leaks-sensitive-urls-data https://portswigger.net/daily-swig/urlscan-io-api-unwittingl...).
- freitasm 4y agoYou are not the only one. This was posted/discussed earlier today: https://news.ycombinator.com/item?id=33435002 https://news.ycombinator.com/item?id=33435002
- quickthrower2 4y agoMakes me question if URL-as-all-factors is a secure way to authenticate someone/thing. Even with SSL encrypting the path , there is the risk of someone sharing that URL since it is a familiar thing to do to share links.
- NavinF 4y agoWith third party cookies going away, URL parameters are the only way to do SSO across domains. Not much you can do about it.
- quickthrower2 4y agoWith SAML IIRC the IdP request is GET (but hey that one is fairly public - no credentials have been supplied yet) and the response is POST back to the origin site.
- zinckiwi 4y agoAn Amazon?
- BLKNSLVR 4y ago"The Internet"?
- bashcoder 4y agoA burgle.
- quickthrower2 4y agoA phish
- deleted 4y ago[deleted]
- dane-pgp 4y agoIf homophones are the pattern to follow, then (since a large collection of legitimate stores can be thought of as a "mall") perhaps the new word should be "a maul" or "a mawl" (suggestive of being something that swallows your money, and doesn't give you anything of value in return).
- quickthrower2 4y agoMaybe I should have said a phishbowl then!
- deleted 4y ago[deleted]
- GauntletWizard 4y agoA Trey of phishing sites.
- deafpolygon 4y agoYo!
- 10g1k 4y agoAlibaba.
- mamborambo 4y agoThe consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.
- Krisjohn 4y agoThat’s kind of what antivirus web plugins do
- NavinF 4y agoIn practice consumers just go straight to Amazon because they're afraid of the wider internet and depend on the return policy to save them when they get scammed. Doubt any "opt-in validation, ring of trust, p2p feedback and rating" will change that in the next decade.
- leveraction 4y agoThis and the fact that they have your cc and shipping already on file, which makes things a lot easier. More than once I have found a product on some site and then purchased it from Amazon just because it is so much easier.
- jesterson 4y agoAs weird as it sounds, it is still the best. If we have centralised "licensing" solution it is abused by large capital to wash off smaller - there is plenty of examples. If we have decentralised solution (which is basically what review is) - it is immediately abused by "marketers". There is no simple and easy solution to the problem.
- BobbyJo 4y agoIMO, the best solution to the problem is friction. Criminals are criminals because it's easy. If opening a fraudulent store is 90% as difficult as opening a legit one, no one is going to bother.
- steve_taylor 4y agoIsn't this something that Extended Validation certificates were designed to address?
- sofixa 4y agoYes, but they were expensive and didn't really work - https://arstechnica.com/information-technology/2017/12/nope-this-isnt-the-https-validated-stripe-website-you-think-it-is/ https://arstechnica.com/information-technology/2017/12/nope-...
- dspillett 4y agoIsh. But there are two significant flaws for ecommerce: 1. Knowing that the company using the certificate is who they say they are, doesn't necessarily mean you can trust them not to be fraudulent traders. 2. Control of the domain names and associated certificates can change hands after the fact, officially through buyouts/merges or via more nefarious means, just like any other certificate. and of course the other key question to address which is: 3. How do you trust those validating the certificate. The average user is not going to know/care that a rogue CA exists and it might take some time for their actions to be noticed and for appropriate revocations to happen. However they were intended to be used, HTTPS and certificates for it are used to protect data in transit and not really for identity assurance. ---- There is also the more cynical view that the main thing EV certs addressed was the desire for CAs to bring in some revenue, especially as standard certs became more and more a commodity item (now effectively free) with low or zero margins.
- ccbccccbbcccbb 4y ago[dead]
- langsoul-com 4y agoI wonder if the best bet would be to hash the main site and its images. Then retroactively scan sites with similar HTML hash and flag them? Fairly sure you could do a HTML search with Google, 7 stores having extremely similar HTML and images seems rather unlikely. Effectively, it's virus total but for copycat sites.
- justusthane 4y agoBut there's no such thing as a "similar" hash - change one character in the HTML, and the hash would be completely different.
- asdadsdad 4y agoDoes anyone care? I've seen this reported many times, and it never gets the same attention as phish
- aww_dang 4y agoWere they billing the cards or just reselling the data? The second option seems more probable.
- lovingCranberry 4y agoCurious question: Why are all these sites behind Cloudflare and why is Cloudflare not acting? These sites are literally made to steal my grandma's money when she's buying presents for Christmas and what not.
- mfonda 4y agoThanks for investigating this and ultimately getting the fraudulent store taken down. I saw the same social media post regarding the fraudulent store and was surprised that a small local store was targeted with this kind of attack. A good mix of small stores and major corporations in the list. I wonder if they target the small stores because SEO is easier? It's inspiring to see you follow up like this and help out a wonderful mountain shop. A great reminder and inspiration to be more involved in my community.