Why use a URL shortener when you can use a phishy URL extender?

https://phishyurl.com/

Keep your security people alert and awake, generate phishing-looking redirecting links

#infosec

554 Boosts, 681 Favs 🎉 That does it. You just outliked my previous best toot with the "We do not test on animals, we test in production" sticker.

https://chaos.social/@FlohEinstein/111339907063126324

FlohEinstein (DECT: 3564) (@[email protected])

Attached: 1 image Working on another sticker for #37c3 - found this image a while ago, but only as a lowres jpg, so I re-did it as a vector graphic. #infosec #devops #sticker We do not test on animals, we test in production. EDIT: Here's the SVG for all of you who asked https://blog.kohler.is/sticker-we-do-not-test-on-animals-we-test-in-production/

chaos.social
@FlohEinstein This is how every URL shortener looks to me.
@FlohEinstein I one bought 'totallylegitlinks.biz' to use for this exact purpose. But I slacked too long and the domain expired.
@FlohEinstein Looks just like the URLs that are sent by legit services… oh no. (like http://t.eservices-laposte.fr/TrackActions/[over 200 base64 characters] is legit, and yes it transmits tokens over http://)
@lanodan @FlohEinstein yeah, now anybody can generate legit-looking links for their old-school static websites.
@FlohEinstein Good idea, but needs more ' OR 1=1 --.
@FlohEinstein beautiful, thanks for sharing!

@FlohEinstein This is either a clever sousveillance technique to obsure users from Big Tech or a glorious shitpost.

And I'm happy with either.

@FlohEinstein "backdoor loader, rat controller" sounds like a line from a metal song
@samerion 🤘 I can hear it in my head.
@samerion @FlohEinstein “that was the latest tune by backdoor loader. And now, the news.”

@twoowls73 @samerion @FlohEinstein I can see a bunch of hairy shock rock awful dudes in tight leather putting up generic edgy songs 😅

Oh and having 5 scandals on their asses in two years of existence

@FlohEinstein I like how NoScript addon catches it as an XSS attempt

@FlohEinstein missed an opportunity to include the EICAR standard test file.

(edit: autocorrect)

Rick Astley - Never Gonna Give You Up (Official Video) (4K Remaster)

Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

YouTube
@LinaBlue @FlohEinstein oh ? Tusky follows the redirect and show the preview YouTube header thingy. It's les efficient this way 😁
@FlohEinstein lmao great tool XD Please tell me it's open source?
@denoiksde so far it isn't. I have bought the author a coffee on https://buymeacoffee.com/andrei007 to ask them for the source
Andrew

I make silly sites

Buy Me a Coffee
@FlohEinstein I am so going to use this. I choose chaos..
Heaps legit links

@pj thnx, didn't know that one. Well, good ideas reoccur, I guess 🙂
@FlohEinstein it's hilarious, like it so much 😁
@FlohEinstein A long time ago, shadyURL did something like this, but it's also been gone a long time.
Lord Grompulus Kevin Ribbiton of Croaksworth :moldlinker: (@[email protected])

@FlohEinstein Previously done at verylegit.link by https://mango.pdf.zone and shadyurl.com (as noted in https://news.ycombinator.com/item?id=14628278)

@FlohEinstein @farcepest (small clarification, just to satisfy my anxiety: i didn't mean my response in negative way [and hope it wasn't taken that way], I like that this idea reoccurs even if not inspired by previous attempts, posting references to other projects so one can compare/learn/have fun/etc, very cool thing made by OP  )
@pj @farcepest no worries. And I didn't make it, I just found it and wanted to share it
@FlohEinstein Nice. Will Mastodon show those as verified when I use this for my profile links? 

@FlohEinstein yep, popular internet idea

One small problem - the more successful and known it becomes, the more scammers pick it up. Happened to shadyurl and forced it to close

> Sadly it became a frequent target for scammers, I guess who use it for reverse psychology? I’ve been booted from a number of hosts, so it’s offline for the moment.

https://www.mikelacher.com/work/shady-url/

ShadyURL - Mike Lacher

A tool to make any URL look suspicious and frightening.

Mike Lacher
@FlohEinstein missing an eicar Sig in the payload 😁
@FlohEinstein that is hilarious, I've gotta try that with some of my friends whenever I send a rick roll
@FlohEinstein Rat controller?
@farah probably related to https://en.m.wikipedia.org/wiki/Pied_Piper_of_Hamelin 😉 no, RAT remote access trojan
Pied Piper of Hamelin - Wikipedia

@FlohEinstein First chuckle for the morning (and wow do I need one). Gracias.
@FlohEinstein this is going to work great at my office. Sending mundane links to teammates is going to be filled with excitement now! Thanks!
@FlohEinstein 🖐️ URL Shortener
👉URL Longener
@FlohEinstein I’ve got a good one for you: https://phish.net 
Phish.net

Phish.net is a non-commercial project run by Phish fans and for Phish fans.

Phish.net
@FlohEinstein
Mmmh... die Frage ist: Kann ich darauf vertrauen, dass das sicher ist? Vielleicht speichert das auch meine Daten..? Man weiß es ja nicht!
@DerJoshDer Datensicherheit ist hier definitiv nicht die Frage 😃
@FlohEinstein just needs to be a share.google link to round it out
@FlohEinstein
Nice, the return of shadyurl.
@ftg you are number (looking it up) 6 to mention shadyurl in the replies. But thanks!