The @gtg.witnesses scam is still going around, meaning:
1. there are still SBDs sent to various accounts, with the same fake message
the screenshot above is an actual screenshot of my wallet. I also saw a few other prominent witnesses targeted.
2. the site https://steemit-rewards.com is still up and it does nasty stuff
So, I poked a bit in the source and here's how it actually works:
- If you click in the link you get in the memo, your username is already added to the session, it's in the $QUERY_STRING va '$u'.
- if you click on "Claim Rewards" you get a page copied almost bit by bit form the official steemconnect.com site, with the exception of a small JavaScript snippet. That snipped does the following:
-- if you add any of your keys in the form, will use the Steemjs library to generate the WIF password
-- it will then redirect to the same domain, targeting a file called done.php, to which it will send the account, the wif and then a 'status' var with the value 'done'. I presume the key is stolen in this file, which probably sends it away. No verification is done and nothing comes to frontend, which fools the user into believing everything was ok. That's what you get if you actually mingle with the vars in the $QUERY_STRING:
I got to the screenshot above, using this username / key combination:
So no backend verification is done, and data is just sent to another server, probably anonimized in some way, then keys are used.
It's not very sophisticated, but it's effective.
So, please take care of your keys, folks.
Steem on!
I'm a serial entrepreneur, blogger and ultrarunner. You can find me mainly on my blog at Dragos Roua where I write about productivity, business, relationships and running. Here on Steemit you may stay updated by following me @dragosroua.
Wanna know when you're getting paid?
|
|
I know the feeling. That's why I created steem.supply, an easy to use and accurate tool for calculating your Steemit rewards |