Be careful, X.com (formerly Twitter) is used for fake URL scams


Vincent Mannessier

March 22, 2024 at 5:54 p.m.

1

A new scam is rampant on X.com © Diego Thomazini / Shutterstock

A new scam is rampant on X.com © Diego Thomazini / Shutterstock

X.com’s preview system is unique and different from what you can find on Google. And apparently it’s a lot easier to abuse too.

Don’t believe everything you see on Twitter. Of course, this statement has been true for a while, but now even previews of links posted there, and supposedly handled by the site, can be misleading and lead you to scams. A problem not only limited to obscure accounts, but which can also be found in advertising posts.

Don’t trust the previews on X.com

It was cybersecurity researcher Will Dormann who first noticed a post on the social network. This post was also highlighted, and the preview and domain name displayed indicated that the link led those who clicked on it to a trusted source if there ever was one, forbes.com. This post, published by a “certified” account, was nevertheless misleading: those who clicked on it did not arrive on the newspaper’s website, but on a Telegram channel, “Crypto with Harry”, which highlights even more dubious cryptocurrencies than the average.

The fault, according to Dormann, lies in a particular preview display system, the functioning of which differs from those that can be found on other social networks. While such a preview on Google, for example, displays the first domain to which a URL redirects, X.com uses a system that displays the destination and domain name of that page. Malicious actors use a system to determine whether a request is made by a bot or a genuine user and then redirects them to the content they wish to display for them respectively, thus allowing these crypto scams to slip through. the radars of Twitter’s detection systems.

X.com's internal decisions are unlikely to make this type of scam disappear © Angga Budhiyanto / Shutterstock

X.com’s internal decisions are unlikely to make this type of scam disappear © Angga Budhiyanto / Shutterstock

A problem that is not recent

For Elon Musk, who wants to make his platform the most trusted source of information in the world, this should be a problem. But not really a surprise, since the fewer moderators and other employees a social network has dedicated to verification, the more likely this type of incident is to occur.

And apparently the problem isn’t new, malicious actors have been exploiting it for at least a year, according to Reddit posts at least as old complaining about the phenomenon.

X.com (formerly Twitter)

Download

X.com (formerly Twitter)

  • Snapshot in information
  • Short messages
  • Hashtags, trends, tweet and retweet

Twitter (X.com today) is a social network that allows its users to find the latest international and local news in just a few seconds. It is one of the most popular platforms on the Internet for conversing, discovering, learning and exchanging. Generally speaking, when an important event takes place, it is mainly on Twitter that it is discussed first.

Twitter (X.com today) is a social network that allows its users to find the latest international and local news in just a few seconds. It is one of the most popular platforms on the Internet for conversing, discovering, learning and exchanging. Generally speaking, when an important event takes place, it is mainly on Twitter that it is discussed first.

Source : Bleeping Computer



Source link -99