Just discovered a new way to locate you via forum spam

For discussions about security.
Post Reply
Message
Author
gcmartin

Just discovered a new way to locate you via forum spam

#1 Post by gcmartin »

I've just observed a new method that YOU can be attacked, right here in the forum.

A member joins the forum and posts a bogus post with a link in it. When you or anyone clicks on the link that is provided, you are taken to a site where your IP address is harvested. Then, that site can and does whatever it likes to YOU with this information.

This was done and almost immediately DoS went to work.

Beware.

@Flash has been notified.

User avatar
Ted Dog
Posts: 3965
Joined: Wed 14 Sep 2005, 02:35
Location: Heart of Texas

#2 Post by Ted Dog »

dDoS against you?

User avatar
Burn_IT
Posts: 3650
Joined: Sat 12 Aug 2006, 19:25
Location: Tamworth UK

#3 Post by Burn_IT »

That is the same for Every forum/site.
Nothing new there!
"Just think of it as leaving early to avoid the rush" - T Pratchett

gcmartin

#4 Post by gcmartin »

ddos can be used to gain access to some weak IP end points. Yes, like our houses, if they have your address, they can try to gain entry.

User avatar
Burn_IT
Posts: 3650
Joined: Sat 12 Aug 2006, 19:25
Location: Tamworth UK

#5 Post by Burn_IT »

I meant getting your IP
"Just think of it as leaving early to avoid the rush" - T Pratchett

anikin
Posts: 994
Joined: Thu 10 May 2012, 06:16

#6 Post by anikin »

gcmartin,

I'm puzzled - not so long ago, you claimed that:
Everything can be Secured, "Centrally" in the home
http://murga-linux.com/puppy/viewtopic.php?t=94343
How come, you've ended up with "weak IP end points", through which the villains attacked you?
BTW, there's an unanswered question in the end of that thread.

User avatar
greengeek
Posts: 5789
Joined: Tue 20 Jul 2010, 09:34
Location: Republic of Novo Zelande

#7 Post by greengeek »

Which browser and version were you using please?

gcmartin

#8 Post by gcmartin »

Hello @Anikin.

Glad you asked about endpoint.

I use Cisco modem routers and detection features was able to provide necessary protections. The idea that this thread was concieved was that here in the forum, a poster (in this case someone poses as asking a legitimate question with a link for any of us to look at, could concievably not be interested in helping, as most members in the forum do) can mislead. In this case there were 2 things that occurred. One, it was to an advertisement and two, coincidental, it started an repeated attempt to gain access.

The problem which surfaces, is that anyone of us can be victim even in areas, like this forum, where one does NOT expect things like this to occur. In my case, I had assumed we had a new member to the forum trying to be helpful,not knowing that this was not the case.

Thus,the post is to raise some awareness to members to, as best we can, be sensitive to the ways that internet abusers can present themselves in the forum.

Reason for the missing answer you allude: I think post by @Rcrsn51, others and myself provided the answer(s) to your single request on that thread.

Anikin, Would you be interested in working on such a home project? If so, PM me.

Post Reply