Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add piptrip.com #24

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Conversation

kornkaobat
Copy link

Requesting a site block on piptrip.com. The site mimics itself to be pantip.com and, redirects to ad sites ( possibly clickfraud too ).
This is my preliminary analysis on one of the URLs:

  • The site manipulates Google Algorithm to display their site which morphs pantip.com (typosquatting)
  • The site limits 2 entry per IP, this ensures that VPN/Proxies/Analysis won't be in their way. (3+ attempts return code 500)
  • The site rotates exit URL every time you enter ( 1st and 2nd time )
  • The site contains JS obfuscation which checks for location.ancestorOrigins == Array member of Piracy/Porn Sites before running its next payload
  • The site fakes HTTPS at its end stage, using trckfeed (dot) com certificate
  • The website to be analysed ( Be minded that you only get 2 tries per IP, I wasted both tries, so prepare Wireshark and Chrome DevTools beforehand. ) :
    https:(doubleslash)piptrip(dot)com/topic/38053356 -- Link is without spaces and () ->changed as needed

kowith337 added a commit to kowith337/PersonalFilterListCollection that referenced this pull request Oct 19, 2021
pDNSF
- `rest` TLD block
- More privacy instance hosts that use CrapFlare

BadBait
- Update Fake Pantip based on adblock-thai/thai-ads-filter#24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant