lux 2015 年 1 月 14 日 上午 6:13
Weird Steam url
I was searching something on google and then I found a weird url:
http://steamcommunity.mostneededsoftware.com/
Every url of steam is the same on that website, except that there is "mostneededsoftware" in between. There is also http://storesteampowered.mostneededsoftware.com/
Anyone has information regarding this website?
< >
正在显示第 1 - 15 条,共 17 条留言
FlamingDeath 2015 年 1 月 14 日 上午 6:54 
引用自 ���.Phisher
Anyone has information regarding this website?


flamingdeath@NAS:~$ whois mostneededsoftware.com Whois Server Version 2.0 Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to http://www.internic.net for detailed information. Domain Name: MOSTNEEDEDSOFTWARE.COM Registrar: GODADDY.COM, LLC Sponsoring Registrar IANA ID: 146 Whois Server: whois.godaddy.com Referral URL: http://registrar.godaddy.com Name Server: IRIS.NS.CLOUDFLARE.COM Name Server: TODD.NS.CLOUDFLARE.COM Status: ok Updated Date: 26-oct-2014 Creation Date: 23-oct-2012 Expiration Date: 23-oct-2015 >>> Last update of whois database: Wed, 14 Jan 2015 14:52:46 GMT <<< NOTICE: The expiration date displayed in this record is the date the registrar's sponsorship of the domain name registration in the registry is currently set to expire. This date does not necessarily reflect the expiration date of the domain name registrant's agreement with the sponsoring registrar. Users may consult the sponsoring registrar's Whois database to view the registrar's reported date of expiration for this registration. TERMS OF USE: You are not authorized to access or query our Whois database through the use of electronic processes that are high-volume and automated except as reasonably necessary to register domain names or modify existing registrations; the Data in VeriSign Global Registry Services' ("VeriSign") Whois database is provided by VeriSign for information purposes only, and to assist persons in obtaining information about or related to a domain name registration record. VeriSign does not guarantee its accuracy. By submitting a Whois query, you agree to abide by the following terms of use: You agree that you may use this Data only for lawful purposes and that under no circumstances will you use this Data to: (1) allow, enable, or otherwise support the transmission of mass unsolicited, commercial advertising or solicitations via e-mail, telephone, or facsimile; or (2) enable high volume, automated, electronic processes that apply to VeriSign (or its computer systems). The compilation, repackaging, dissemination or other use of this Data is expressly prohibited without the prior written consent of VeriSign. You agree not to use electronic processes that are automated and high-volume to access or query the Whois database except as reasonably necessary to register domain names or modify existing registrations. VeriSign reserves the right to restrict your access to the Whois database in its sole discretion to ensure operational stability. VeriSign may restrict or terminate your access to the Whois database for failure to abide by these terms of use. VeriSign reserves the right to modify these terms at any time. The Registry database contains ONLY .COM, .NET, .EDU domains and Registrars. For more information on Whois status codes, please visit https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en. Domain Name: MOSTNEEDEDSOFTWARE.COM Registry Domain ID: 1754229638_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.godaddy.com Registrar URL: http://www.godaddy.com Update Date: 2014-10-26T15:40:50Z Creation Date: 2012-10-23T16:16:44Z Registrar Registration Expiration Date: 2015-10-23T16:16:44Z Registrar: GoDaddy.com, LLC Registrar IANA ID: 146 Registrar Abuse Contact Email: abuse@godaddy.com Registrar Abuse Contact Phone: +1.480-624-2505 Domain Status: ok http://www.icann.org/epp#ok Registry Registrant ID: Registrant Name: WILLIAM JESUS Registrant Organization: Registrant Street: 1705 ENCARTA ST Registrant City: LAS VEGAS Registrant State/Province: Nevada Registrant Postal Code: 89117 Registrant Country: United States Registrant Phone: +1.7026047867 Registrant Phone Ext: Registrant Fax: Registrant Fax Ext: Registrant Email: cool@mostneededsoftware.com Registry Admin ID: Admin Name: WILLIAM JESUS Admin Organization: Admin Street: 1705 ENCARTA ST Admin City: LAS VEGAS Admin State/Province: Nevada Admin Postal Code: 89117 Admin Country: United States Admin Phone: +1.7026047867 Admin Phone Ext: Admin Fax: Admin Fax Ext: Admin Email: cool@mostneededsoftware.com Registry Tech ID: Tech Name: WILLIAM JESUS Tech Organization: Tech Street: 1705 ENCARTA ST Tech City: LAS VEGAS Tech State/Province: Nevada Tech Postal Code: 89117 Tech Country: United States Tech Phone: +1.7026047867 Tech Phone Ext: Tech Fax: Tech Fax Ext: Tech Email: cool@mostneededsoftware.com Name Server: IRIS.NS.CLOUDFLARE.COM Name Server: TODD.NS.CLOUDFLARE.COM DNSSEC: unsigned URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/ Last update of WHOIS database: 2015-01-14T14:00:00Z For more information on Whois status codes, please visit https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en The data contained in GoDaddy.com, LLC's WhoIs database, while believed by the company to be reliable, is provided "as is" with no guarantee or warranties regarding its accuracy. This information is provided for the sole purpose of assisting you in obtaining information about domain name registration records. Any use of this data for any other purpose is expressly forbidden without the prior written permission of GoDaddy.com, LLC. By submitting an inquiry, you agree to these terms of usage and limitations of warranty. In particular, you agree not to use this data to allow, enable, or otherwise make possible, dissemination or collection of this data, in part or in its entirety, for any purpose, such as the transmission of unsolicited advertising and and solicitations of any kind, including spam. You further agree not to use this data to enable high volume, automated or robotic electronic processes designed to collect or compile this data for any purpose, including mining this data for your own personal or commercial purposes. Please note: the registrant of the domain name is specified in the "registrant" section. In most cases, GoDaddy.com, LLC is not the registrant of domain names listed in this database.
lux 2015 年 1 月 14 日 上午 7:01 
MOSTNEEDEDSOFTWARE.COM isn't the same website I think
Kargor 2015 年 1 月 14 日 上午 7:08 
引用自 ���.Phisher
MOSTNEEDEDSOFTWARE.COM isn't the same website I think

As far as the domain name business goes, someone owns "mostneededsoftware.com" and is responsible for everything below that. Thus, the phishing site does relate to whoever owns "mostneededsoftware.com".

Of course, the owner of "mostneededsoftware.com" might just be selling domain names below that, so he might not actually RUN the phishing site. However, again, since the domain name business only deals with 2nd level domains, any complaints should probably be addressed to the "mostneededsoftware.com" owner.
最后由 Kargor 编辑于; 2015 年 1 月 14 日 上午 7:09
lux 2015 年 1 月 14 日 上午 7:12 
引用自 Kargor
引用自 ���.Phisher
MOSTNEEDEDSOFTWARE.COM isn't the same website I think

As far as the domain name business goes, someone owns "mostneededsoftware.com" and is responsible for everything below that. Thus, the phishing site does relate to whoever owns "mostneededsoftware.com".

Of course, the owner of "mostneededsoftware.com" might just be selling domain names below that, so he might not actually RUN the phishing site. However, again, since the domain name business only deals with 2nd level domains, any complaints should probably be addressed to the "mostneededsoftware.com" owner.

Makes sense, thank you! Only that it doesn't seem like a phishing site, it has 'a back-up' of nearly every steam site. And if I try to login (with fake credentials) nothing even happens. So I am actually wondering what the purpose of the website is.
Also mostneededsoftware.com redirects to http:// www.com/?redir=frame&uid=www54b68462bced19.37065502
最后由 lux 编辑于; 2015 年 1 月 14 日 上午 7:16
KillahInstinct 2015 年 1 月 14 日 上午 8:39 
I have added the remaining URL to the URL-filter. Please don't post any fake links in the future again.

And please report your malicious URL’s to either me in PM and/or here so they can be blocked throughout Steam and taken down.
lux 2015 年 1 月 14 日 上午 8:43 
I compared both sources, no major differences except:

</head> </script><iframe frameborder=”0″ vspace=”0″ hspace=”0″ width=”1″ height=”1″ marginwidth=”0″ marginheight=”0″ scrolling=”no” src=”http://track.newvirtuallife.com/redirect_bg.php?mn=123″></iframe>

<!– Histats.com START (hidden counter)–>
<script type=”text/javascript”>document.write(unescape(”%3Cscript src=%27http://s10.histats.com/js15.js%27 type=%27text/javascript%27%3E%3C/script%3E”));</script><a href=”http://www.histats.com” target=”_blank” title=”myspace tracker”><script type=”text/javascript”>
try {Histats.start(1,2296590,4,0,0,0,”");
Histats.track_hits();} catch(err){};
</script></a>
<noscript><a href=”http://www.histats.com” target=”_blank”><img src=”http://sstatic1.histats.com/0.gif?2296590&amp;101″ alt=”myspace tracker” border=”0″></a></noscript>
<!– Histats.com END –>


<iframe frameborder=”0″ vspace=”0″ hspace=”0″ width=”1″ height=”1″ marginwidth=”0″ marginheight=”0″ scrolling=”no” src=”http://track.newvirtuallife.com/redirect_ali.php?mn=123″></iframe>



<script src=”http://1moretoy.com/js/jquery-1.4.1.js” type=”text/javascript”></script><style type=”text/css”>
*{margin:0;padding:0;list-style-type:none;}
a,img{border:0;color:#5e5e5e;text-decoration:none;}
body{font:12px/180% Arial, Helvetica, sans-serif;}
*html,*html body{background-image:url(about:blank);background-attachment:fixed;}

/* fixediv */
.fixediv{position:fixed;top:140px;z-index:9999;height:216px;width:100px;}
*html .fixediv{position:absolute;top:expression(eval(document.documentElement.scrollTop));margin:140px 0 0 0;}
.fixediv-l{left:0px;}
.fixediv-r{right:0px;}

/* advbox */
*html .advbox{position:absolute;top:expression(eval(document.documentElement.scrollTop));}
.advbox{width:728px;position:fixed;z-index:9999;display:none;left:50%;top:0;margin:-215px 0 0 -325px;}
.advbox .advpic{position:relative;height:400px;overflow:hidden;}
.advbox .advpic .closebtn{display:block;width:60px;height:22px;line-height:26px;font-size:12px;color:#000;text-indent:12px;overflow:hidden;position:absolute;right:12px;top:5px;z-index:99;}

</style>
<script type=”text/javascript”>
function bar11901_show(){
document.getElementById(’Bar11901_big’).style.display=”;
document.getElementById(’Bar11901_small’).style.display=’none’;
}
function bar11901_hidden(){
document.getElementById(’Bar1190_big’).style.display=’none’;
document.getElementById(’Bar1190_small’).style.display=”;
document.getElementById(’Bar11901_big’).style.display=’none’;
document.getElementById(’Bar11901_small’).style.display=”;
}
var autohide11901 = setTimeout(”bar11901_hidden()”,18000);
</script><script type=”text/javascript”>
var _pop = _pop || [];
_pop.push(['siteId', 493414]);
_pop.push(['minBid', 0]);
_pop.push(['popundersPerIP', 0]);
_pop.push(['delayBetween', 0]);
_pop.push(['default', false]);
_pop.push(['defaultPerDay', 0]);
_pop.push(['topmostLayer', false]);
(function() {
var pa = document.createElement(’script’); pa.type = ‘text/javascript’; pa.async = true;
var s = document.getElementsByTagName(’script’)[0];
pa.src = ‘/c1.popads.net/pop.js’;
pa.onerror = function() {
var sa = document.createElement(’script’); sa.type = ‘text/javascript’; sa.async = true;
sa.src = ‘/c2.popads.net/pop.js’;
s.parentNode.insertBefore(sa, s);
};
s.parentNode.insertBefore(pa, s);
})();
</script>
</head>

Anyone know coding?
KillahInstinct 2015 年 1 月 14 日 上午 8:45 
What are you trying to accomplish? The site is FAKE.

The code will probably look the same too, because most code is ran serversided and you won't see in your browser (which does lay-out, mostly)
lux 2015 年 1 月 14 日 上午 8:48 
引用自 KillahInstinct
What are you trying to accomplish? The site is FAKE.

The code will probably look the same too, because most code is ran serversided and you won't see in your browser (which does lay-out, mostly)

If I'm curious I want to get to the bottom. Obviously this site is fake. It doesn't seem like a phishing site, so I am just trying to figure out what the real purpose is...
KillahInstinct 2015 年 1 月 14 日 上午 8:50 
It is a phishing site. It's exactly what they're trying to accomplish, make you think it's real.
lux 2015 年 1 月 14 日 上午 8:53 
What technique are they using then? It is weird that nothing happens
snh 2015 年 1 月 14 日 上午 8:57 
引用自 ���.Phisher
What technique are they using then? It is weird that nothing happens

What are you trying to achieve? There's no technique, it's just copy/paste the HTML and Javascript. There's nothing special here.
KillahInstinct 2015 年 1 月 14 日 上午 8:59 
引用自 ���.Phisher
What technique are they using then? It is weird that nothing happens
You try and login to a site, nothing happens. They have your login credentials.
lux 2015 年 1 月 14 日 上午 9:05 
引用自 snh
What are you trying to achieve? There's no technique, it's just copy/paste the HTML and Javascript. There's nothing special here.

That's what I'm saying I don't seem to get what the site does, if "there's no technique" why is everyone claiming that it is a phishing site? (By technique I mean like the fake screen cap or steam_guard download etc.)
KillahInstinct 2015 年 1 月 14 日 上午 9:06 
Perhaps read my comment above?
lux 2015 年 1 月 14 日 上午 9:09 
引用自 KillahInstinct
You try and login to a site, nothing happens. They have your login credentials.

Steam Guard is too save. You could argue that some people have the same password on their email, but then they don't have the email
< >
正在显示第 1 - 15 条,共 17 条留言
每页显示数: 1530 50

发帖日期: 2015 年 1 月 14 日 上午 6:13
回复数: 17