Last night I found an XSS stored vulnerability on hiveblockexplorer.com and some Hive users were giving me "crap" because I disclosed it before the maintainer fixed it.
I know that maybe I should have waited longer, but at the same time:
To compensate, I then decided to add a feature that @guiltyparties asked me if I could add a while back..
Starting from today @keys-defender will keep a list of known phishing links and compromised domains. As part of the scanning of new blocks added to the Hive blockchain, besides as usual protecting leaked keys, it will now automatically reply to any post or comment containing a known phishing link or compromised domain.
Until @penguinpablo fixes the XSS that I reported last night, a subpath of his site will be in the blacklist, in order to warn users of the potential threat.
@keys-defender/antiphish-keys-defender-bot-1598120388219
If you want to timely notify me of phishing campaigns happening on Hive, tag me or the other users in my discord: https://discord.gg/SXuwsH7. In alternative, join the HiveWatchers (@hivewatchers) discord and they'll add it themselves when the improvements above are ready.