Lately, I have been seeing a lot of posts getting comments from bots or some random dude who can't even write proper English, I can hear you saying "But Deathwing, this always happens, it is not something new" but there is one caveat in those comments.
All of them have a link, a link that seems similar to steemit.com or any other big sites such as busy but in fact, it is not.
[IMAGE: https://res.cloudinary.com/hpiynhbhq/image/upload/v1521329747/ruajztjkxxezusihv3be.png]
In this picture, you can see the user posted a link with a normal spam message you say? But in fact, it's not a link to his "usual" profile, well... It is. But not on Steemit. More on that later.
What is Phishing
>Phishing is the attempt to obtain sensitive information such as usernames, passwords, and credit card details (and money), often for malicious reasons, by disguising as a trustworthy entity in an electronic communication.
Wikipedia
Phishing is pretty much a way of scamming, stealing your private information. Most importantly, your private keys or passwords here on steemit (never, ever use your password to login, always use a posting key on a daily basis. ONLY use active key when you are verifying stuff (well, transactions in this case).
Alright, back to the "link" thingy.
[IMAGE: https://res.cloudinary.com/hpiynhbhq/image/upload/v1521329982/jgdnbx5psquclpcuxni0.png]
As you can see when I hover over the link, you see "sleemit.com" so, what is the difference?
[IMAGE: https://res.cloudinary.com/hpiynhbhq/image/upload/v1521330662/peo0oipuwqemjvag6fks.png]
This image is taken on Steemit.com, as you can see; I am completely logged in with Steem Plus active.
[IMAGE: https://res.cloudinary.com/hpiynhbhq/image/upload/v1521330736/urldgoz1y2ss7fls95eh.png]
And this is Sleemit.com, I am no longer logged in and Steem Plus is not active anymore. I am not on Steemit anymore, but the site looks EXACTLY like Steemit and works like it. So this is the phishing right here. As an innocent user, you would think you just "got logged out" and would instinctively log back in once again.
[IMAGE: https://res.cloudinary.com/hpiynhbhq/image/upload/v1521330897/axgztwccpcnj1jugeqav.png]
You see the normal login page of Steemit, and only a few scripts are running
[IMAGE: https://res.cloudinary.com/hpiynhbhq/image/upload/v1521330972/x28qhwyjkwblpjlpjnbr.png]
And there you go, this is Sleemit's login page. A few extra scripts right there and the most notably, app.js which is the javascript file they use to steal your passwords as soon as you log in.
Ways to prevent this:
Always check the link you are clicking to
Install the Steem Plus extension made by @stoodkev as it will warn you whenever you are clicking a link that directs you out of steemit.com
Don't click the links at all if they are posted by low rep users, or have no meaning.
TLDR: Never click a link before checking where it redirects you to. Especially on Steemit. Otherwise you will have your password stolen, your account and your money gone. Always have Steem Plus installed.
P.S.: The site and the user I shared here were completely out of coincidence, during my observations for the past few weeks I know that there are more than 15 maybe 20 phishing sites available on the internet just to steal your passwords.
Very interesting find. Very sneaky form of attack. Scary thing is it is so easy to register a domain name and even SSL certificate these days. Also scary because anyone can pretty much run a frontend for condenser, but it is hard to know if the site is trustworthy or not. Thanks for the article, I find this kind of thing super interesting. Will be following you.
Some of the guys that do phising like do make use of url shorteners to hide the actual link. Or from what I could tell in your post they used steem markup to disguise the actual link. In the case where the use a url shortnerer for example tinyurl then you can actually check what the link redirects to by making use of curl. You can do it like this:
$ curl -I https://tinyurl.com/2fcpre6
See the output. The actual url it redirects to is in the "Location" section in the response.
This link for example was a tinyurl link for the video:"Rick Astley - Never Gonna Give You Up". Haha I got you!
Anyways tinyurl has a feature where you can take any link shortened by tinyurl and preview it by prefixing tinyurl with "preview" like this: https://preview.tinyurl.com/2fcpre6.
Just take in mind that tinyurl is one of many sites that people could use to shorten a url. Twitter even have their own site that they use to shorten any links posted on twitter. My curl trick should work on almost any url shortener, but if you aren't that technical I would suggest that you try:
http://www.checkshorturl.com/ which you can use to check shortened urls. For example I did a check for this url that was shortened by twitter's url shortening service: https://t.co/LGaAniJH32
Something you can also do if you aren't sure if a frontend/site other than steemit.com is legit or not is to use security related reputation checking site to check what other people have to say about the site. Here is a list of sites you can use to check if the site is flagged as malicious by other users or not:
https://www.threatcrowd.org
https://www.virustotal.com/ (It has a feature to check a url and there is a very handy comments section)
https://www.phishtank.com/
(Btw I check sleemit.com and its not mentioned on any of these sites yet , unfortunately).
PLEASE MAKE A SEPARATE PAGE FOR COMPLAINERS, PROGRAMMERS AND MEETUPS. THESE DONOT COME UNDER GOOD CONTENT. STEEMIT IS ABOUT GOOD CONTENT CREATING GOOD POSTS/BLOGS, STEEMIT IS NOT ABOUT STEEMIT.
HAVE YOU SEEN QUORA MAKING BLOGS ABOUT QUORA AND TRENDING?
STOP THIS NONSENCE
WE NEED TO FIX THESE THINGS FIRST:
a) We need good content on trending page, and no 2 liners or only specific content related or of specific members only or just a dinner shot.
b) Bots should review the posts before upvoting.
c) Need genuine Meritocracy, not fake (Give Fair chance to everyone, not just the rich)
d) Meetups/Programmer related should be funded privately, and not by trending, This is not called good content. Need a speprate page for it like an UPDATE or ANNOUNCEMENT page.
e) Or You can remove Trending and Hot page, so people will only look for content they are intrested in, using search bar or tags, & not upvote only for rewards.
f) We also need Reward limits and Posts limit. I guess if we keep max 200$ per post and max 5 posts, that comes to 1000$ per day means 30000$ per month. Which is morethan enough for any one to live life in any part of the world. and obviously you can invest in steem/SBD or other cryptos. This will also limit greed.
g) Also a minimum reward like 50 cents to 1$ (more or less i leave to experts) for every post with a minimum content (bots can handle this im sure) will give a boost to minnows, and will also lead to genuine wealth distribution.
All the above points will eliminate the "Central Banking System for the Rich only" type scenario that going on on steemit.
Reposting here as it gets ignored all the time..