🔑🦸‍♂️ [weekly report #49] 🚑 - 1 leak, 2 (harmless) code injections, 12 flags

in HiveDevs3 years ago (edited)









Stats of the past 7 days on Hive


 




K E Y S   P R O T E C T I O N:


PRIVATE KEYS LEAKS protected:


1. @ sweecee

  • Chain: Hive (Hive + steem account) [intentional leak 🤦]
  • Type: Posting key
  • Operation in which the account was leaked: post
Leaked account stats:
- Estimated Account Value: $ 21.30 (on Hive)
- Reputation: 57
- Followers: 560
- Account age: Joined September 2017







NOTE: @keys-defender still scans the STEEM blockchain because your private keys are shared across the two chains unless you reset your password at https://wallet.hive.blog/@your-username-here/password!

TOTAL KEYS FOUND since launch:


posting keys: // todo
active keys: // todo
memo keys: // todo
owner keys: // todo



 



PHISHING LINKS detected (and auto-replied to):   0

Auto-replies in wallet memos currently being developed..


   

CODE INJECTIONS detected:   1 ❗



UNSAFE LINKS detected:

NOTE: links that do not use a secure protocol (https) and shortened links (eg. bit.ly) are NOT a threat per se but can lead to theft of credentials if misused or used in a malicious attack.








O T H E R   A C T I V I T I E S:


Confirmed re-posting authors:   0 ✔️

critical bug fixes required


 

Downvotes of @keys-defender (and its trail) against hive-abusers:  
12
  ❗

Accounts:
kingscrown, cryptopie, juanmiriethoriel, maikuraki, daio




What does this bot do?

- Keys protection[live scan of transfers / posts / comments / other_ops. Auto-transfers to savings, auto-reset of keys, ..] {see automatic posts on leak and weekly reports}
- Phishing protection [live scan of blocks to warn against known phishing campaigns and compromised domains]
- Re-posting detection [mitigates the issue of re-posters]
- Code injections detection [live scan of blocks for malicious code targeting dapps of the Hive ecosystem]
- Anti spam efforts [counteracts spam from hive haters]


To support this bot..
   
- Delegation links:
10, 20, 30, 40 HP
50,100, 200 HP,
500 HP, 1000 HP
- Curation trail
Follow my curation trail on hive.vote to upvote all my posts with a fixed weight.

Sort:  

Seems none of the blockchain platforms likes daily motion's video embed code for some reason. I tried having autoplay on and off and either the video wouldn't show up or I got flagged for code injection.

Ahah, don't worry @sketch.and.jam it's nothing personal. I now removed the downvote =]

The flag is automated and it's just to scare potential malicious users trying to find XSS vulnerabilities in the Hive ecosystem. It's like 0.01 as well.

And as I wrote in my weekly report:

"False positive, not a code injection attempt: @sketch.and.jam testing d.tube
https://scribe.hivekings.com/?url=https%3A%2F%2Fhive.blog%2F%40sketch.and.jam%2Fnjs53m4j6j1

I already whitelisted you and I will whitelist that attribute for d.tube!

Take care!   =]

!discovery 25


This post was shared and voted inside the discord by the curators team of discovery-it
Join our community! hive-193212
Discovery-it is also a Witness, vote for us here
Delegate to us for passive income. Check our 80% fee-back Program