Captain obvious says... Don't click on links before checking them...steemCreated with Sketch.

in infosec •  6 years ago  (edited)

image.png
SRC

So you're all seasoned and experienced Internet users, right?

I'm sure that it won't come as a surprise that behind links that you might receive via messaging or email could lurk something malicious!

Nevertheless here a little reminder to never just click on any links that you receive without checking them first!

A pretty hands on approach I use if I want to investigate where a link sends me is to use URL checkers.


I'll show you one example that I've received via Twitter DM. I'll anonymize the Twitter user because it actually could have been an honest mistake.

So I received this... a twitter user just sent me a shortened URL link without any further comment.

image.png


I copied the link and checked it against some URL checkers. I use Virustotal on a regular basis if I investigate links.

image.png

Paste the URL you want to test into the regarding field and click on the magnifying glass...

Shortly after you'll be presented with the test results.

image.png


BTW... you are aware that you can see the actual link on the lower left side of your browser if you hover the mouse over it, right? This just as a quick tip for "readable" links but you might also receive shortened links where you cannot see what's going on so clearly.

image.png


Here a pretty neat and straight forward article on this!

https://www.raymond.cc/blog/urlvoid-scans-websites-for-viruses-with-multiple-scanning-engines/


Please be careful out there especially if you're in crypto!

If you can avoid to click on unknown links this would be the best option of all. When you want to use an URL link do yourself a favor and double check where it'll lead you!


Your questions and suggestions are very welcome!

Please drop a comment if you like!



Gif from my friend @smilinglllama!

Cheers!

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

man i got this link too from someone that he works in steem blockchain but i don't wanna say who, when i asked him he said he did not send this link to me

Does his handle look something like this @m*****n?

if you talking about twitter nickname (not username) yes that's him

Thought so... when I confronted him in twitter DM he apologized and wrote he made a mistake. So I didn't block him so far but I told him he try's shit like that again I'll block him and I'll call him out whit his handle as well. Could've been an honest mistake... however I'm in this infosec game for a long time... I very seldom came across "honest mistakes" by people spreading "long", script riddled links... Hahaha!

when I clicked it's directed me to I website called twitter followers to increase followers

Maybe an other link then? However... this is unacceptable behavior IMO. You should consider to up your internet usage protection and privacy protection by using an VPN, uBlock Origin, decentraleyes and HTTPS Everywhere in FF.

ya I use tor network on VPN mode as my favorite VPN