this post was submitted on 21 Mar 2024
544 points (96.7% liked)

Technology

59696 readers
2368 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

As noted by security researcher Will Dormann, some posts on X purport to lead to a legitimate website, but actually redirect somewhere else. In Dormann's example, an advertisement posted by a verified X user claims to lead to forbes.com. When Dormann clicks the link, however, it takes him to a different link to open a Telegram channel that is, "helping individuals earn maximum profit in the crypto market," he said. In short, the "Forbes" link leads to crypto spam

you are viewing a single comment's thread
view the rest of the comments
[–] wagoner@infosec.pub 9 points 8 months ago

I get the knee-jerk jaded cynicism but this is a little more nuanced than that.

"All they have to do is set up two different URL destinations in their post. In the case outlined above, clicking the forbes.com link actually takes you to joinchannelnow.net. Once on this site, the server checks to see whether the request is coming from a typical browser (that's you). If so, it'll take you to the spam site, which for this situation is a crypto scam Telegram channel. However, if the server detects the request is coming from something else—like a X link-verifying bot—it'll assume the request is not being made by a human; in these cases it returns a legitimate URL. So, even though the first link is to joinchannelnow, X checks it and is taken to forbes.com, and so it places that URL preview on the post. You're experience will be different."