Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My favorite link of all time:

https://jpmorgan.c1ic.link/logger_zcGFC2_bank_xss.docm

Definitely not meta



I got one where the called script ended in ".pl" and I had a flashback to the 90s. My trousers grew into JNCOs, Limp Bizkit started playing out of nowhere and I got a massive urge to tell Slashdot that Alan Thicke had died.

With Firefox on Android it simply says

Deceptive site issue

This web page at [...] has been reported as a deceptive site and has been blocked based on your security preferences.

What's going on? I can't find any setting to disable this.


NextDNS is blocking it too (https://google.c1ic.link/lottery_qrdLCz_account_verification). The reason is that Google Safe Browsing considers that site as unsafe.

TBF it ought to trigger even the simplest heuristics so it wouldn't surprise me if it was automatically categorized that way.

I was able to get past that (Firefox on the Desktop) by clicking the "see details" button and then clicking the "ignore the risk" link. It took me a while to actually read the text too.

Imagine using this as your personal website lol

email too



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: