Author Topic: soo...im guessin this is a scam  (Read 1424 times)

offmyr0ck3r

  • Full Member
  • ***
  • Posts: 167
  • Karma: +9/-5
    • View Profile
    • Personal Message (Offline)
soo...im guessin this is a scam
« on: January 08, 2014, 11:40:51 pm »
Can someone verify if this is a scam. I just got a message from a newbie named ADMIN subject IMPORTANT SECURITY UPDATE and it said this:

This me[REDACTED - THIS MESSAGE CONTAINS MALICIOUS CONTENT PLEASE REPORT] remote execution attack through a flaw in Javascript's
[REDACTED - THIS MESSAGE CONTAINS MALICIOUS CONTENT PLEASE REPORT] information transmitted over the tor network.

As of Janurary 2nd 2014 the following vulnerability was found

[REDACTED - THIS MESSAGE CONTAINS MALICIOUS CONTENT PLEASE REPORT]
Impact: Critical

An attack that exploits a Firefox vulnerability in JavaScript has been observed in the wild. Specifically, Windows users
using the Tor Browser Bundle (which includes Firefox plus privacy patches) appear to have been targeted.


Please note: If you are using Linux or Tails (bootable) this vulnerability does not apply to you, please disregard this message.

We are advising all of our community members to upgrade to the patched version Tor Bundle (3.5)

http://REDACTED

Mirror: http://REDACTED

Note: You do not need to remove your current Tor Bundle before installing. This will overwrite the previous installation and upgrade you to the latest 3.5 version.

If you are unsure of which version you have it is best to upgrade anyways, it will preserve your bookmarks and preferences during the upgrade.


Any questions? Please feel free to message any mod and we will do our best to reply Asap

Happy New Year & Stay safe in 2014!

-SRStaff

« Last Edit: January 08, 2014, 11:55:21 pm by Stealth »
If you want to msg me please learn PGP and msg me using my key. THANKS

HonoluluExpress

  • Hero Member
  • *****
  • Posts: 2097
  • Karma: +277/-144
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #1 on: January 08, 2014, 11:41:54 pm »
This is a scam.
Free Bitcoins: https://qoinpro.com/56dac0555612b52edb776964aa5f8fd2

Censor

  • Jr. Member
  • **
  • Posts: 58
  • Karma: +3/-1
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #2 on: January 08, 2014, 11:43:40 pm »
Could be a scam but it's a good idea to keep Tor updated using the official site. It has been wellknown that Javascript can be exploited to expose peoples identities through Tor.... everyone should have it disabled, through windows usually. Anyone who is serious about security shouldn't be using windows anyways. Windows is the least secure and most exploitable operating system that exists.

offmyr0ck3r

  • Full Member
  • ***
  • Posts: 167
  • Karma: +9/-5
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #3 on: January 08, 2014, 11:45:02 pm »
ok i figured it was. thought everyone else should know about this
If you want to msg me please learn PGP and msg me using my key. THANKS

Pharma Jack

  • Vendor
  • Full Member
  • *****
  • Posts: 100
  • Karma: +5/-2
  • Aussie Pharma's
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #4 on: January 08, 2014, 11:47:59 pm »
dont click on them links!!!
Pharma Jack Official Review Thread:
http://silkroad5v7dywlc.onion/index.php?topic=35123.0

Australian Vendor Database:
http://silkroad5v7dywlc.onion/index.php?topic=22777.0

offmyr0ck3r

  • Full Member
  • ***
  • Posts: 167
  • Karma: +9/-5
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #5 on: January 08, 2014, 11:50:33 pm »
hmmmm. i cant find where to turn java off in this. i used to go to options and then content and there was a thing there to uncheck it. now its not there
If you want to msg me please learn PGP and msg me using my key. THANKS

CaptainWhiteBeard

  • Certified Thief
  • Hero Member
  • *****
  • Posts: 3810
  • Karma: +260/-290
  • The Notorious Dark Net Pirate
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #6 on: January 08, 2014, 11:53:42 pm »
Scam. Do not click on any links from unknown people
Prepare to be robbed.

Stealth

  • Hero Member
  • *****
  • Posts: 787
  • Karma: +215/-75
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #7 on: January 08, 2014, 11:54:01 pm »
Yes, this is another scam attempt. The user has been banned. I have redacted the links from the OP because those files will contain backdoors.

Thanks for bringing this to our attention. As a general rule, never, ever, ever consider any message you receive from someone claiming to be staff unless you see the appropriately colored blue/orange squares AND title
“Government exists to protect us from each other. Where government has gone beyond its limits is in deciding to protect us from ourselves.”

– Ronald Reagan

*Please include your public key in ALL encrypted communication*

WickedWords

  • Vendor
  • Sr. Member
  • *****
  • Posts: 486
  • Karma: +121/-16
  • My pen is my sword. It's not much good in a fight.
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #8 on: January 09, 2014, 12:01:01 am »
This vulnerability may disclose a users actual identity and other sensitive information transmitted over the tor network.

Poor punctuation

Note: You do not need to remove your current Tor Bundle before installing. This will overwrite the previous installation and upgrade you to the latest 3.5 version.

This instruction conflicts with common best practice advice (which is to NOT overwrite old versions with new versions)

it is best to upgrade anyways

Colloquial language a little out of place, considering this person attempted to write formally.
W̲̲̿ɪ̲̲̿ᴄ̲̲̿ᴋ̲̲̿ᴇ̲̲̿ᴅ̲̲̿ ̲̲̿W̲̲̿ᴏ̲̲̿ʀ̲̲̿ᴅ̲̲̿s̲̲̿ - Writing | Marketing | Strategy

✎ Powerful Listings & Profiles
✎ Forum Announcements & Promotions
✎ Custom Copywriting & Consultation

Shop: http://silkroad6ownowfk.onion/users/wickedwords
Reviews: http://silkroad5v7dywlc.onion/index.php?topic=4428.

vince

  • Hero Member
  • *****
  • Posts: 552
  • Karma: +59/-94
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #9 on: January 09, 2014, 12:19:34 am »
LOL, this is so blatantly a scam it's funny. What was it? a 500kb exe file with no icon that said "tor 3.5 insatll"?

tehjollyroger

  • Jr. Member
  • **
  • Posts: 73
  • Karma: +5/-6
  • Hermes - The true god
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #10 on: January 09, 2014, 07:15:31 am »
All this talk about back doors is getting me hot furreal.
Did you see what god just did to us man?
That wasn't god you're a god damn narcotics agent I knew it.

---Agora Invite-
a g o r a b a s a k x m e w w w .onion/p/PUgvbRVjBE

WickedWords

  • Vendor
  • Sr. Member
  • *****
  • Posts: 486
  • Karma: +121/-16
  • My pen is my sword. It's not much good in a fight.
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #11 on: January 09, 2014, 09:51:51 am »
All this talk about back doors is getting me hot furreal.

Just wait until they start talking dirty about how they're going to exploit your software and make it hardware or something
W̲̲̿ɪ̲̲̿ᴄ̲̲̿ᴋ̲̲̿ᴇ̲̲̿ᴅ̲̲̿ ̲̲̿W̲̲̿ᴏ̲̲̿ʀ̲̲̿ᴅ̲̲̿s̲̲̿ - Writing | Marketing | Strategy

✎ Powerful Listings & Profiles
✎ Forum Announcements & Promotions
✎ Custom Copywriting & Consultation

Shop: http://silkroad6ownowfk.onion/users/wickedwords
Reviews: http://silkroad5v7dywlc.onion/index.php?topic=4428.

TheDr

  • Full Member
  • ***
  • Posts: 120
  • Karma: +11/-0
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #12 on: January 09, 2014, 09:53:39 am »
Quick question people.

When I start up Tor it takes you to the TorPage. There it says there is an update for the security for tor bundle.

Can i assume that is safe to download and run?

StringerBell

  • Hero Member
  • *****
  • Posts: 556
  • Karma: +132/-39
  • We don't need to dream no more
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #13 on: January 09, 2014, 10:16:11 am »
It is just like back in the days

The days with Back Orifice and Cult of the Dead Cow.

 

Desperado

  • Full Member
  • ***
  • Posts: 183
  • Karma: +17/-20
  • DeSp
    • View Profile
    • Personal Message (Offline)
Re: soo...im guessin this is a scam
« Reply #14 on: January 09, 2014, 10:40:09 am »
Doesn't take a genius to work this out mate.

be careful!
Fake friends are like shadows, they follow you in the sun, but leave your side when it gets dark.

Been here from the start.

Nightcrawler

  • Guest
Re: soo...im guessin this is a scam
« Reply #15 on: January 09, 2014, 02:04:40 pm »
Yes, this is another scam attempt. The user has been banned. I have redacted the links from the OP because those files will contain backdoors.

Thanks for bringing this to our attention. As a general rule, never, ever, ever consider any message you receive from someone claiming to be staff unless you see the appropriately colored blue/orange squares AND title

He may have been referring to the main site, as opposed to the Forum. It's pretty easy to determine who is staff on the Forum, but not so much on the main site proper.

Nightcrawler
4096R/BBF7433B 2012-09-22 Nightcrawler <Nightcrawler@SR>
PGP Key Fingerprint = D870 C6AC CC6E 46B0 E0C7  3955 B8F1 D88E BBF7 433B

Security is a bit like religion... some things have to be taken on faith.
Where security differs from religion is that security is NOT retroactive.
Unlike Christianity, where you can come to Jesus, be 'saved' and have all
your sins washed away, with security you can adopt Tails or PGP, and be
secure from that point forward, but rest assured that your previous sins
(security failings) WILL come back to haunt you and bite you in the ass.
The original DPR is the poster child for that, right now.

Folly, thou conquerest, and I must yield!
Against stupidity the very gods Themselves
contend in vain.      --Friedrich Schiller