portapack-mayhem / mayhem-firmware

Custom firmware for the HackRF+PortaPack H1/H2

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

[Wiki Issue] Wiki is using grabify link to track users

Programicus opened this issue · comments

commented

Describe the bug.

Currently, the H2 mayhem edition on the portapack versions page uses a grabify link to redirect to alibaba. This was introduced in commit ddb6ab2e16c331ca744fab018087849c671be958 to the wiki.

For context, grabify is a url shortener (similar to bit.ly), however it also comes with a page that logs all uses of the redirection. Here is an example such a tracking and logs page for a redirect I made to github.com, as well as a hit it via archive.ph to give an example hit without doxing myself. As you can see from this example, I get quite a bit of information about people who the link: ip address, timezone, browser info, isp, os version, etc.

Reproduction

Go to: H2 mayhem edition on the portapack versions page. Hover over the link and see that it https://grabify.link/5CL1IP.

Expected behavior

Have either a normal alibaba link, or one from a reputable url shortner like bit.ly or t.ly

Environment/versions

No response

Anything else?

Sorry if this isn't the best way to post this. I couldn't find a way to create an issue about the wiki page

Hi! Grabify is made by one of our contributors, I actually prefer this redirection than other option knowing we can discuss directly about it.

What is your concern? this redirection does not get more info that any script can get from your browser, there is no "magic" spyware or something evil behind. We ofc get click stats about what users are interested on.

I added a note on the wiki. It needs more work, but it is open for edits

commented

Fair enough that you are just using it for click stats, and makes sense knowing that grabify was made by one of the contributers.

I'm used to it seeing grabify used to with respect to scamming and scam baiting, so and had associate it with a lack of trust in the clicker. You're right in that it doesn't give you anything extra than if you were hosting your the link shortener on a server you controlled.