Author Topic: Website Asking For Key Going Around  (Read 10222 times)

I sent him a fake BL key, which was IDI0T-SPENC-ERALT-DUMBASS

Also, I reported the form for phishing.

Gold? Blockland has got gold?

Gold? Blockland has got gold?
Even if you're joking, I'll still warn you about it. It's a complete scam, this user Spencer2015 has been doing it for ages now. A real problem user. I suggest you don't enter your key in anywhere except blockland.

seriously spencer if you're going to steal keys use something better than a google doc

http://pastebin.com/anNNZfT3

I made a little flooder userscript that generates a convincing key. Just save the userscript, open the page, and enjoy. Adjust the interval as you wish.


http://pastebin.com/anNNZfT3

I made a little flooder userscript that generates a convincing key. Just save the userscript, open the page, and enjoy. Adjust the interval as you wish.


Little late the the party. My flooder already did that

Personally I'd just make a console application that just sends POST requests, instead of bothering to render the web page and everything

why are we still spamming it lol
not like he'll check it and actually snoop all of the posts out to find a working key

Personally I'd just make a console application that just sends POST requests, instead of bothering to render the web page and everything
You can turn the webpage off too

Personally I'd just make a console application that just sends POST requests, instead of bothering to render the web page and everything
pretty sure someone already made a batch script that does this with cURL

pretty sure someone already made a batch script that does this with cURL
Look a little further back rofl.

Also you cannot filter the real keys out. It sends to a google docs and then lists them down in order.
I just want to ask you guys, if you see anymore of this phishing send us the google docs link so we can protect people who fall for it and enter their key by us flooding it with fake keys. We can stop Spencer by doing this.

Look a little further back rofl.

Also you cannot filter the real keys out. It sends to a google docs and then lists them down in order.
I just want to ask you guys, if you see anymore of this phishing send us the google docs link so we can protect people who fall for it and enter their key by us flooding it with fake keys. We can stop Spencer by doing this.

^^

Little late the the party. My flooder already did that
Not to mention that his keys miss a segment.

I just want to ask you guys, if you see anymore of this phishing send us the google docs link so we can protect people who fall for it and enter their key by us flooding it with fake keys. We can stop Spencer by doing this.
Only if those keys pass the basic check. Generating random letters is not enough.

Not to mention that his keys miss a segment.
Only if those keys pass the basic check. Generating random letters is not enough.

So he's going to enter all the thousands of keys we've flooded in just to find one that works.
uh k.
The point of flooding in realistic looking ones is to hide the real ones. Thus saving people who fall for this.

So he's going to enter all the thousands of keys we've flooded in just to find one that works.
uh k.
The point of flooding in realistic looking ones is to hide the real ones. Thus saving people who fall for this.
No.
Valid keys follow a certain numbering scheme. For example, in a valid credit card number, all the digits add up to a certain number. This makes it very easy to check if a number is valid without having to authenticate it with a server
I don't know the numbering scheme with keys, but if you do, you can just write a script that will go through all the keys and throw away any that don't conform to this scheme, making spamming the form with completely random keys pointless
Conversely, if you do know the scheme, you can generate random keys according to this scheme that couldn't be thrown out by an automated script