Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
OgNar
Oct 26, 2002

They tapdance not, neither do they fart

IShallRiseAgain posted:

Maybe somebody should just start a separate thread for all the goons who click on those extremely shady links, so the thread isn't constantly spammed with it. Presumably if they actually read this thread, they wouldn't fall for the scam because someone posts about it on every page of this thread. It feels like 10% of this thead is someone posting about who fell for this scam.

Why would anyone read that thread?
Post it here where someone who might know them can find out and let them know.
Yes its spam sort of, but best way to do it.

Adbot
ADBOT LOVES YOU

ts0hg
Apr 30, 2014
I only found this thread when I was searching for his username.

Leal
Oct 2, 2009
Alright I just went to the website myself. I had to wait for a DdoS guard to verify my browser, then do a bot check, and get greeted with this



The bad grammar isn't enough of a tip off? But then when I click sign in




Goons can't be this dense about online security

ultrafilter
Aug 23, 2007

It's okay if you have any questions.


Wanna bet?

Peewi
Nov 8, 2012

Leal posted:

What can steam possibly do to not "let" it happen? People are willfully entering their account info into this scam. Somehow in TYOOL 2021 people still can't get it through their heads to not enter their info on any website that isn't the website itself.


Unrelated, but I am a Nigerian prince, who is looking to leave his country and needs an American bank account to move my money over. Can you give me your bank's routing and account number?

Scam sites like this tend to look just like the real thing. If you click a "log in with Steam" button, it's easy to miss if it takes you to stearncommunity.com instead of steamcommunity.com or some other misspelled domain.

Cardiovorax
Jun 5, 2011

I mean, if you're a successful actress and you go out of the house in a skirt and without underwear, knowing that paparazzi are just waiting for opportunities like this and that it has happened many times before, then there's really nobody you can blame for it but yourself.
Yeah, that's basically the whole thing. That site looks exactly like the real Steam login site, even the "not associated with Steam or Valve" is not in and of itself a warning sign, it just means that neither Steam nor Valve own the site you're logging into. There are plenty which are legitimate and look no different.

If phishing wasn't so effective and easy to fall for, people wouldn't bother using phishing scams. Everyone thinks they're too smart to fall for a scam until the moment they do.

Volte
Oct 4, 2004

woosh woosh

Leal posted:

The bad grammar isn't enough of a tip off? But then when I click sign in




Goons can't be this dense about online security
That's what all Steam sign-in pages say to authorize third-party accounts say, even the legit ones. e.g., click the Sign In button on https://scrap.tf/ (just an example I found on Google). Identifying that the URL isn't actually coming from Steam or Valve is the only way to really tell that it's not legit.

Broken Cog
Dec 29, 2009

We're all friends here
Just got a message from Strongmouse as well, so the impersonator is still going.
Reported the profile as hijacked, though I have no idea how much of a difference it makes.

treat
Jul 24, 2008

by the sex ghost
hey dude
wassup?

may u help me?
can you vote for my sa:goon posting team on forums.sornthingawful.net?

only need 2 more :justpost:

Leal
Oct 2, 2009

treat posted:

hey dude
wassup?

may u help me?
can you vote for my sa:goon posting team on forums.sornthingawful.net?

only need 2 more :justpost:

hunter2

ts0hg
Apr 30, 2014
He ended up blocking me when I called him out. I know StrongMouse is a variety gamer and rarely plays CS:GO lol

Broken Cog posted:

Just got a message from Strongmouse as well, so the impersonator is still going.
Reported the profile as hijacked, though I have no idea how much of a difference it makes.

Zathril
Nov 12, 2011

treat posted:

hey dude
wassup?

may u help me?
can you vote for my sa:goon posting team on forums.sornthingawful.net?

only need 2 more :justpost:

help, the link isn't working.

Kibayasu
Mar 28, 2010

Did Project Zomboid turn into something decent at some point recently because I’ve noticed a few streamers uploading videos of it to YouTube.

Professor Beetus
Apr 12, 2007

They can fight us
But they'll never Beetus
Welp pour one out for Spacebeez, appears to be another goon lost to the great goon phishing project.

explosivo
May 23, 2004

Fueled by Satan

Kibayasu posted:

Did Project Zomboid turn into something decent at some point recently because I’ve noticed a few streamers uploading videos of it to YouTube.

Not sure if it's on the normal branch yet but last time I played the experimental branch had a fairly sizeable update that changed the graphics to 3d models and generally made the game look/feel a lot better than it used to. It's been half a year or so since then so there might have been more changes to it.

StrixNebulosa
Feb 14, 2012

You cheated not only the game, but yourself.
But most of all, you cheated BABA

Kibayasu posted:

Did Project Zomboid turn into something decent at some point recently because I’ve noticed a few streamers uploading videos of it to YouTube.

Yeah, on the beta branch is feels and plays great. It's easily my favorite zombie game, tied with State of Decay 2 as they go in very different directions. I love the lonely, desperate struggle for survival in Zomboid. It perfectly captures too many slow zombies in a rural American town.

threelemmings
Dec 4, 2007
A jellyfish!

Leal posted:

*******

Hey that's cool, didn't know the forums automatically blank out your password!

Let me try:

************

Edit: looks like it works, cool. Gonna go vote for some teams now that my account is safe

FastestGunAlive
Apr 7, 2010

Dancing palm tree.

Leal posted:

Alright I just went to the website myself. I had to wait for a DdoS guard to verify my browser, then do a bot check, and get greeted with this



The bad grammar isn't enough of a tip off? But then when I click sign in




Goons can't be this dense about online security

The grammar would be a dead give away to me, even with friends that are ESL. However, I believe email scammers often use poor grammar intentionally to make it seem more believable to grandma and grandpa that an actual Nigerian prince is emailing them.

pseudorandom name
May 6, 2007

Leal posted:



Goons can't be this dense about online security

The funny thing about you posting this image is that it is visible proof that you fell for their phishing scam.

Like, you knew that it was a phishing scam and didn't log in, but everything about your wrong explanation demonstrates you don't actually understand the issue.

pseudorandom name
May 6, 2007

Here is a condescendingly marked up explanatory image, as is the style:

exquisite tea
Apr 21, 2007

Carly shook her glass, willing the ice to melt. "You still haven't told me what the mission is."

She leaned forward. "We are going to assassinate the bad men of Hollywood."


Hey it looks like neo-noir cyberpunk detective RPG Gamedec finally got a release date - September 16th. There's also a new demo build out that's free to try.

uber_stoat
Jan 21, 2001



Pillbug
turn on two factor!

spincube
Jan 31, 2006

I spent :10bux: so I could say that I finally figured out what this god damned cube is doing. Get well Lowtax.
Grimey Drawer

Leal posted:

What can steam possibly do to not "let" it happen? People are willfully entering their account info into this scam. Somehow in TYOOL 2021 people still can't get it through their heads to not enter their info on any website that isn't the website itself.

Change the Steam Guard app login method from 'input the code' to 'tap 'OK' on the app', and only have the 'tap OK' thing fire from pre-approved websites. That way you can't login to freecsgoskinsforstearn.cz, even if you give them your details.

Awesome!
Oct 17, 2008

Ready for adventure!


uber_stoat posted:

turn on two factor!

i wonder if this is part of it. people going "oh i have 2fa on i dont have to use my brain at all"

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


Awesome! posted:

i wonder if this is part of it. people going "oh i have 2fa on i dont have to use my brain at all"

it is at least 50% this

uber_stoat posted:

turn on two factor!

it asks you for a code and people are willingly putting one in, two factor won't save you if you're already fooled

Party Boat
Nov 1, 2007

where did that other dog come from

who is he


uber_stoat posted:

turn on two factor!

*looking at little old lady who unlocked her door to let in a nice young man with a fantastic investment opportunity and signed away her life savings*

"should have had an extra lock on this door"

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


pseudorandom name posted:

Here is a condescendingly marked up explanatory image, as is the style:



i'm not going to the site to find out, what does "not real" mean in this context? is the top bar an image instead of actual menus, or is the url spoofed? (afaict at first glance it looks valid and from Valve - but i'm also high as a kite atm)

K8.0
Feb 26, 2004

Her Majesty's 56th Regiment of Foot

uber_stoat posted:

turn on two factor!

It asks for your 2FA code, and will immediately use it to log into your account.

In general, the best thing you can do is the same thing you'd do with phone scams : don't login anywhere you followed a link, the same way you don't give important information to anyone who calls you. Find out what the real number/URL is, and YOU initiate the contact with it and verify that the original request was real. In the case of a steam or any other login, if you just go to steamcommunity.com and log in, then when another site wants authorization it will just ask you for authorization and not your password.

pseudorandom name
May 6, 2007

Ciaphas posted:

i'm not going to the site to find out, what does "not real" mean in this context? is the top bar an image instead of actual menus, or is the url spoofed? (afaict at first glance it looks valid and from Valve - but i'm also high as a kite atm)

It's like https://www.windows93.net/, a fake in-browser implementation of the Windows UI.

spiritual bypass
Feb 19, 2008

Grimey Drawer

exquisite tea posted:

Hey it looks like neo-noir cyberpunk detective RPG Gamedec finally got a release date - September 16th. There's also a new demo build out that's free to try.

This looks really cool; added to my constantly-growing wishlist

Owl Inspector
Sep 14, 2011

I never thought I'd see a worse name than Immortals: Fenyx Rising so soon but Record Of Lodoss War-Deedlit In Wonder Labyrinth- just went and did it

Ugly In The Morning
Jul 1, 2010
Pillbug

Gay Rat Wedding posted:

I never thought I'd see a worse name than Immortals: Fenyx Rising so soon but Record Of Lodoss War-Deedlit In Wonder Labyrinth- just went and did it

It’s Kingdom Hearts side-game level bad.

Xander77
Apr 6, 2009

Fuck it then. For another pit sandwich and some 'tater salad, I'll post a few more.



Peewi posted:

Scam sites like this tend to look just like the real thing. If you click a "log in with Steam" button, it's easy to miss if it takes you to stearncommunity.com instead of steamcommunity.com or some other misspelled domain.
I mean... if you're already logged into your steam account, you generally don't need to re-enter it.

Volte posted:

That's what all Steam sign-in pages say to authorize third-party accounts say, even the legit ones. e.g., click the Sign In button on https://scrap.tf/ (just an example I found on Google). Identifying that the URL isn't actually coming from Steam or Valve is the only way to really tell that it's not legit.
I get:

quote:

Sign into scrap.tf using your Steam account

Xander77
Not You?
If I have any doubts about a third party site, I just sign into steam proper in the same browser (not in the login window for the site), and... that works. If the site still asked for my login details, I'd have some serious questions.

Xander77 fucked around with this message at 21:12 on Mar 28, 2021

Chalks
Sep 30, 2009

pseudorandom name posted:

It's like https://www.windows93.net/, a fake in-browser implementation of the Windows UI.

It's actually quite clever, there's lots of training for people to check the url, check the lock icon and the certificate name, but checking whether the popup is actually a new window? i'm not sure i've ever explicitly checked for that before.

Volte
Oct 4, 2004

woosh woosh

Xander77 posted:

I mean... if you're already logged into your steam account, you generally don't need to re-enter it.

I get:
If I have any doubts about a third party site, I just sign into steam proper in the same browser (not in the login window for the site), and... that works. If the site still asked for my login details, I'd have some serious questions.
If you have doubts about a third party site then you've already passed the test. Also, I haven't logged into Steam in a browser since like 2010, so I got the password screen.

Kibayasu
Mar 28, 2010

Random thought but I’ve been playing Amnesia Rebirth and I feel there’s notably fewer monsters segments in it and I think that makes things worse (in the good way that is).

Phuzun
Jul 4, 2007

Just got a message from Mitchicon with the fetown link. How many goons gonna get hacked today?

Fuligin
Oct 27, 2010

wait what the fuck??

Gay Rat Wedding posted:

I never thought I'd see a worse name than Immortals: Fenyx Rising so soon but Record Of Lodoss War-Deedlit In Wonder Labyrinth- just went and did it

it's so bad it wraps around and becomes good again
unlike immortals, that's just an extremely bland 2000s gamecube platformer title

HarmB
Jun 19, 2006



Tamba posted:

What do they even do with the hijacked accounts (other than spreading it even more)?
It doesn't seem like the people who got hit have noticed anything.

e: someone should ask them, when they get the 'vote for my team'-message :v:



I tried but only got 'bro?' back. Even told them i knew the deal but seems to be fully automated now.

Adbot
ADBOT LOVES YOU

Zathril
Nov 12, 2011

Gay Rat Wedding posted:

I never thought I'd see a worse name than Immortals: Fenyx Rising so soon but Record Of Lodoss War-Deedlit In Wonder Labyrinth- just went and did it

I'd put The Sexy Brutale up there as well, would have never even looked at it if it wasn't recommended on here at some point.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply