Parcimony Apr 22, 2015 @ 4:58pm
Another phishing method (may not be new)
Received a chat message from someone without a profile set up who wanted to friend.

He provided the link:

[ LINK REMOVED BY AUTHOR]

What is important here is that the link spells "steam" as "stearn".

S T E A M =/= S T E A R N

Might be old news but I'd never seen it before. Went ahead and reported it.

Last edited by Parcimony; Apr 22, 2015 @ 5:05pm
< >
Showing 1-15 of 25 comments
Kesac Apr 22, 2015 @ 5:02pm 
Please don't post the link -- otherwise you'll get curious people who go to the link and get their accounts stolen.
Parcimony Apr 22, 2015 @ 5:03pm 
Should i edit it? I think the important part is showing that stearn = steam which is crafty.
supertrooper225 Apr 22, 2015 @ 5:03pm 
Yup...you should remove it if you can.
Parcimony Apr 22, 2015 @ 5:06pm 
How's that? Better?
supertrooper225 Apr 22, 2015 @ 5:06pm 
Yup, thanks. You would think people wouldn't click the link you are warning them about....but you would be surprised.
Laptop Apr 22, 2015 @ 5:07pm 
Never understood how people try to prevent phishing by linking the actual phishing link.
Parcimony Apr 22, 2015 @ 5:10pm 
To be fair, I edited the link to not include the numbers at the end and then the filter actually blocked it anyway, so I just put quotes around the first "/". It wasn't ever the actual link.
Uplinked Apr 22, 2015 @ 5:17pm 
Still, you shouldn't add the phishing links anyways.
Parcimony Apr 22, 2015 @ 5:44pm 
Just a question then: how do you educate people on what to look out for?
Uplinked Apr 22, 2015 @ 5:47pm 
Like this: (Taken from the guide I wrote.)

NEVER accept friend requests from people you do not know.
Beware of level 0 accounts, and private profile account.
Be very careful of links to sites you do not know. Better yet, don't click links at all, unless absolutely necessary.
When clicking links, read it first. Links that include steamcommunity can be manipulated to look similar, like steam comnunity. Notice there is a different letter. steamcomnunity.
If something seems too good to be true, it most likely is. Avoid "Free Game sites," random "My friend can't find you, click this link (Malicious link) to go to his profile," and "I want to trade with you. This is my offer (Malicious link.)

Originally posted by Parcimony:
Just a question then: how do you educate people on what to look out for?
HLCinSC Apr 22, 2015 @ 5:57pm 
They're slowly running out of fake links. The best one was steamcomrnunity instead of steamcommunity the r+n made it look like a m (rn) at first glance
Last edited by HLCinSC; Apr 22, 2015 @ 5:58pm
Laptop Apr 22, 2015 @ 5:59pm 
Originally posted by #Let Girls Learn #Sunshine Week:
They're slowly running out of fake links. The bet one was steamcomrnunity instead of steamcommunity the r+n made it look like a m (rn) at first glance
Valve should just contact all the Domain Registrars that have similar links to Steamcommunity and either kindly ask they turn them all over to Valve or put them on some sort of restricted blacklist so that no one is able to buy them or even use them. Any domain registrar that refuses is just being a complete a-hole because they know that they are being used to phish and steal people's accounts + money.
Last edited by Laptop; Apr 22, 2015 @ 6:07pm
Teknohead Apr 22, 2015 @ 6:04pm 
People should just wake up.. steam is not your mum.
Last edited by Teknohead; Apr 22, 2015 @ 6:05pm
Uplinked Apr 22, 2015 @ 6:08pm 
Originally posted by Teknohead:
People should just wake up.. steam is not your mum.

You're right. It's better.
HLCinSC Apr 22, 2015 @ 6:11pm 
Originally posted by Laptop65:
Originally posted by #Let Girls Learn #Sunshine Week:
They're slowly running out of fake links. The bet one was steamcomrnunity instead of steamcommunity the r+n made it look like a m (rn) at first glance
Valve should just contact all the Domain Registrars that have similar links to Steamcommunity and either kindly ask they turn them all over to Valve or put them on some sort of restricted blacklist so that no one is able to buy them or even use them. Any domain registrar that refuses is just being a complete a-hole because they know that they are being used to phish and steal people's accounts + money.
domain squatting is big business and there are less than reputable domain hosts more than happy to facilitate. Politicians face it all the time

TedCruz.com: It's owned by an Arizona lawyer, according to Mother Jones magazine, and now lists a pro-Obama message promoting immigration reform.

JebBushForPresident.com: Gay couple CJ Phillips and Charlie Rainwater bought this domain in 2008 that now promotes conversation about LGBT topics.

HillaryForPresident.com: This redirects to a website at TheAmerican.net by Larry Kawa, a Florida orthodontist and Republican activist.

< >
Showing 1-15 of 25 comments
Per page: 1530 50

Date Posted: Apr 22, 2015 @ 4:58pm
Posts: 25