Silk Road forums

Support => Customer support => Topic started by: bbbaac on May 21, 2013, 06:02 pm

Title: got a weird message...
Post by: bbbaac on May 21, 2013, 06:02 pm
Simonclark81    Hi, I'm not sure if you are the right person or not, but I live near to you and have noticed you making quite a few deliveries to the mailbox, some of which I managed to get on video... search for 'silk road local delivery' on www.videoupload.us and click on the the first video and you will be able to see.

This is not a threat, I am just trying to pre warning you to be more careful when mailing things (and maybe send someone else to the mailbox instead of yourself)

P.S If it is not you in the video, then you can ignore this

Simon


that was the message i received. i dont believe that is even a real website as nothing comes up on google when i search it.
Title: Re: got a weird message...
Post by: dirtybiscuitzz718 on May 21, 2013, 06:10 pm
Did you watch this alleged video of you?
Title: Re: got a weird message...
Post by: scout on May 21, 2013, 06:15 pm
Did you watch this alleged video of you?

He says he tried searching for the site on google and couldn't find it, so I'm assuming it was just intended to scare him?
Title: Re: got a weird message...
Post by: dirtybiscuitzz718 on May 21, 2013, 06:17 pm
No, cause i found it.. it just has some kind of Java add on that i didnt care to wait for.
Title: Re: got a weird message...
Post by: dirtybiscuitzz718 on May 21, 2013, 06:18 pm
I just copied and pasted the url.
Title: Re: got a weird message...
Post by: scout on May 21, 2013, 06:23 pm
I just copied and pasted the url.

I just saw a thread in the vendor forum about this - apparently it was sent to a lot of vendors on SR.  I would recommend that NO ONE visit the site or provide any information to it ...
Title: Re: got a weird message...
Post by: Talk to Frank on May 21, 2013, 06:34 pm
Got the same message and my trusty anti-virus was all over the URL it like the hair on my back.

Steer clear!
Title: Re: got a weird message...
Post by: dirtybiscuitzz718 on May 21, 2013, 06:36 pm
Awesome, i went to it..not where do i stand? lo

I have no virus protection at the moment. Figures, what i get for trying to help
Title: Re: got a weird message...
Post by: Talk to Frank on May 21, 2013, 06:40 pm
Awesome, i went to it..not where do i stand? lo

I have no virus protection at the moment. Figures, what i get for trying to help

I'm not that clued up on computer stuff, but I would imagine the point of these messages is to get control of our accounts. My worst fear would be keylogging, so might be a good idea to avoid typing any passwords/pins until you know you're clear! My antivirus didn't define what it was, but it considered it a threat enough to quarantine it.
Title: Re: got a weird message...
Post by: scout on May 21, 2013, 06:43 pm
Since you're on Tor, I would assume you're okay -- I'd be more worried about the site trying to record your IP ... but again, you're using Tor, so that shouldn't be an issue.

Hopefully someone more knowledgeable about this will chime in, and if not, you might get more reassurance by starting a new thread about it. 

But, yes, this is usually the kind of thing that happens when you try to help people.  lol.  Shit happens like this all the time to me (paying for trying to help).  Welcome to the club.  ;)
Title: Re: got a weird message...
Post by: dirtybiscuitzz718 on May 21, 2013, 06:45 pm
Thanks for the fast reply, i am the same, dont know much about computers, but i manage to figure out what i have to do when i get trojans or w.e

Im running a full scan on malwarebytes now, im such a cuntt.. i thought that may have been a virus of sorts. DOH!
Title: Re: got a weird message...
Post by: dirtybiscuitzz718 on May 21, 2013, 06:47 pm
Yeaaaa, about thatt. lmao.. i checked it out on clearnet also =X

hopefully malware finds something and scraps it. cunt cunt cunt  i am.
Title: Re: got a weird message...
Post by: bbbaac on May 21, 2013, 06:49 pm
lol damn
Title: Re: got a weird message...
Post by: BruceCampbell on May 21, 2013, 06:50 pm
I guess Simon has us pinned man. Game over man... game over.
Title: Re: got a weird message...
Post by: dirtybiscuitzz718 on May 21, 2013, 06:52 pm
I just checked my task manager, for running processes, there so  much shit in there that idk wtf it iss. arrrg
Title: Re: got a weird message...
Post by: bbbaac on May 21, 2013, 07:00 pm
let us know if any thing happens to your computer, or SR account please and thank you
Title: Re: got a weird message...
Post by: dirtybiscuitzz718 on May 21, 2013, 07:09 pm
absolutely will do, i would hope my SR account will not be compromised some how because of this, if it is some kind of key logger.

Ultimately it would be a waste for the hacker, cause my shit is always at zero coin, and the worst they can do is finalize a few orders, never the less i would like to not have the head ache of all this.

Did i mention that im a C U N T, lol. I always go against my gut and better judgment.
Title: Re: got a weird message...
Post by: Talk to Frank on May 21, 2013, 07:11 pm
absolutely will do, i would hope my SR account will not be compromised some how because of this, if it is some kind of key logger.

Ultimately it would be a waste for the hacker, cause my shit is always at zero coin, and the worst they can do is finalize a few orders, never the less i would like to not have the head ache of all this.

Did i mention that im a C U N T, lol. I always go against my gut and better judgment.
I just checked my task manager, for running processes, there so  much shit in there that idk wtf it iss. arrrg


I would suggest testing the water by logging out of your SR account and creating a new one with an unrelated username and password. Stay logged on for a bit, then log out and see if you can get back in? Then you can at least feel secure that you're not infected with logging shit.

If it recorded your IP address then there's not much that can be done about that I guess? Beware the clearnet :/ and user fuckery!
Title: Re: got a weird message...
Post by: dirtybiscuitzz718 on May 21, 2013, 07:14 pm
Good idea, im waiting for the malware scanners to finish up.. nothing thus far has been detected. Though my aswMBR program thing has been stuck on scanning my jpeg scrubber program for a minute now, but ive had that for a while now.
Title: Re: got a weird message...
Post by: WhiteShark on May 21, 2013, 07:26 pm
I actually created a thread before I saw this one...


I'll just copy and paste my thread here


Basically this is the message:
"    Hi, I'm not sure if you are the right person or not, but I live near to you and have noticed you making quite a few deliveries to the mailbox, some of which I managed to get on video... search for 'silk road local delivery' on www.videoupload.us and click on the the first video and you will be able to see.

This is not a threat, I am just trying to pre warning you to be more careful when mailing things (and maybe send someone else to the mailbox instead of yourself)

P.S If it is not you in the video, then you can ignore this

Simon"



My reaction " HAHA". Why?
1. My drop offs do not involve mail boxes at all. In fact I never come near a mail box, and no not telling you how. But first off I knew this was not me
2. How the hell would he know this is me, and who would go through that much work to message every single vendor in the country (assuming he did this --> unless he specifically targeted me


Now, my curiosity got the better of me, I opened it in Tor. Soon as I saw a java script appalet I CLOSED IT RIGHT AWAY!
The reason is because extensions like Java and other addons can be used to track you, EVEN IN TOR!

For those of you who are unaware:

Tor does not protect all of your computer's Internet traffic when you run it. Tor only protects your applications that are properly configured to send their Internet traffic through Tor. To avoid problems with Tor configuration, we strongly recommend you use the Tor Browser Bundle. It is pre-configured to protect your privacy and anonymity on the web as long as you're browsing with the Tor Browser itself. Almost any other web browser configuration is likely to be unsafe to use with Tor.
Don't enable or install browser plugins

The Tor Browser will block browser plugins such as Flash, RealPlayer, Quicktime, and others: they can be manipulated into revealing your IP address. Similarly, we do not recommend installing additional addons or plugins into the Tor Browser, as these may bypass Tor or otherwise harm your anonymity and privacy. The lack of plugins means that Youtube videos are blocked by default, but Youtube does provide an experimental opt-in feature (enable it here) that works for some videos.


Tor will encrypt your traffic to and within the Tor network, but the encryption of your traffic to the final destination website depends upon on that website. To help ensure private encryption to websites, the Tor Browser Bundle includes HTTPS Everywhere to force the use of HTTPS encryption with major websites that support it. However, you should still watch the browser URL bar to ensure that websites you provide sensitive information to display a blue or green URL bar button, include https:// in the URL, and display the proper expected name for the website.

Don't open documents downloaded through Tor while online
The Tor Browser will warn you before automatically opening documents that are handled by external applications. DO NOT IGNORE THIS WARNING. You should be very careful when downloading documents via Tor (especially DOC and PDF files) as these documents can contain Internet resources that will be downloaded outside of Tor by the application that opens them. This will reveal your non-Tor IP address. If you must work with DOC and/or PDF files, we strongly recommend either using a disconnected computer, downloading the free VirtualBox and using it with a virtual machine image with networking disabled, or using Tails. Under no circumstances is it safe to use BitTorrent and Tor together, however.
Use bridges and/or find company

Tor tries to prevent attackers from learning what destination websites you connect to. However, by default, it does not prevent somebody watching your Internet traffic from learning that you're using Tor. If this matters to you, you can reduce this risk by configuring Tor to use a Tor bridge relay rather than connecting directly to the public Tor network. Ultimately the best protection is a social approach: the more Tor users there are near you and the more diverse their interests, the less dangerous it will be that you are one of them. Convince other people to use Tor, too!



So I still want to see this video, so I head over to an internet cafe across the street. Try and load it, and it is just a continuous java running in the background with nothing occurring. My conclusion?
THIS IS LAW ENFORCEMENT ATTEMPTING TO TRACK VENDORS THROUGH TOR! DO NOT OPEN THIS LINK! DO NOT ENABLE JAVA!

If mods can sticky this or get support to send a warning out, would suck to see a bunch of vendors go down like this. I mean I hate competition, but I ain't gonna wish death on nobody. There ain't no coming back from that ;)



My advice for anyone who clicked the link and had java on --> clean your house for a while, just to be safe. Hate to see you go down like this.


Title: Re: got a weird message...
Post by: scout on May 21, 2013, 07:40 pm
I've just sent off a message to the other mods and admins to see if we can maybe post a thread and sticky it to help warn people NOT to visit that site ...
Title: Re: got a weird message...
Post by: Talk to Frank on May 21, 2013, 07:51 pm
My anti-virus kicked in and stopped the page from even trying to load, so no java applet ever started running. After I got the warning from anti-virus it just stayed on the 'new tab' page as if I'd never tried to load anything. I assume that means I'm safe from it, but I'm going to take some extra safety precautions to be sure I think!

Looking at vendors who seem to have been sent this message, they sell from Canada, the US and the UK at least, so I'm dubious as to whether or not it IS law enforcement behind it? My guess would be that it is a malicious individual who might try and blackmail vendors who compromise their IPs?
Title: Re: got a weird message...
Post by: Deutsche Bank on May 21, 2013, 08:46 pm
I've also got a message from Simonclark81.

My advice: If someone you don't know sends you a message, don't even bother reading it or clicking on some links, just delete and report it immediately.
Title: Re: got a weird message...
Post by: Darktime on May 21, 2013, 09:27 pm
Perhaps they only sent to USA,UK and Canada because all three use English and the message is in English?A simple hypothesis I know but hey...! :-\
Title: Re: got a weird message...
Post by: colorblack on May 21, 2013, 10:14 pm
I've just sent off a message to the other mods and admins to see if we can maybe post a thread and sticky it to help warn people NOT to visit that site ...

Good idea Scout. This is obviously nefarious.. and my spidey senses say that it's not even a scam actually. Methink this reeks of LE. Please, NO vendor click that link.
Title: Re: got a weird message...
Post by: Libertas on May 21, 2013, 11:06 pm
A sticky has now been posted here:
http://dkn255hz262ypmii.onion/index.php?topic=161834.0

Major props to scout for getting the ball rolling - they couldn't post it themselves as they are currently offline, but would certainly have done so immediately upon receipt of DPR's approval.

Locking this thread - please move all discussion to the sticky, or to the thread link contained within it.

Libertas