Hacker News new | ask | show | jobs
by aaron695 1771 days ago
They are a phishing site

https://webcache.googleusercontent.com/search?q=cache:HWH6z4...

Perhaps they have fixed it in the past 3 weeks, maybe they haven't.

From yesterday, so not fixed -

https://webcache.googleusercontent.com/search?q=cache:rMUgla...

Also love the way it's signed, the persons online profile is "I'm Black Hat SEO Expert" if anyone wants to write any Green policy I guess contact them?

3 comments

This is just streaming spam and any site that accepts user-generated content is susceptible to it.

Having been on their side it can sometimes be very difficult to mitigate without manual approval. This is not automated - it's done by humans and they adjust their patterns against any automatic mitigation attempts.

> This is just streaming spam and any site that accepts user-generated content is susceptible to it.

Not if the site polices user-generated content.

> This is just streaming spam

It's fraud not spam, you never got to watch the fight after paying - https://ici.radio-canada.ca/recit-numerique/2140/adcenter-hy...

And 6 weeks ago it might have been ISIS spam or a link to a exe or phishing.

> and any site that accepts user-generated content is susceptible to it

This site doesn't have user-generated content/events/calendar, it's employee generated.

> This site doesn't have user-generated content/events/calendar, it's employee generated.

That's incorrect. There's a call to action to register to submit an event here:

https://www.gp.org/earth_day_to_may_day_events_calendar

That's how the spam got in.

Edit: here, I made one for you: https://www.gp.org/janon/aaron695_hello

Edit2: it's deleted, looks like someone is finally doing cleanup

Apologises. You are correct. Good find

They did the same with a 'job ad' on the hosts web site -

https://webcache.googleusercontent.com/search?q=cache:2Uw0_n...

Hmm, that doesn't look like content the GP would put up intentionally.
No, it looks like they have glaring security issues of their website and the site regularly gets used for phishing, spam, etc.

So maybe that only has been an issue for 3 weeks (which is bad enough), but all things considered, it’s possible it’s been like this for years.

It looks like they allow user generated posts on a calendar, and every site that allows user generated content regularly gets used for phishing, spam, etc.
I read an interesting article on the Big Lie over the weekend and it mentioned an example from 2016 where private non-profit conservative groups were involved in promoting Green and Independent candidates with the intention of diluting vote for Dem candidates.

Probably not related, but worth mentioning the coincidence just because it was such a good article https://www.newyorker.com/magazine/2021/08/09/the-big-money-...

This should be the top answer -- it is a phishing/spam site, whether due to being hacked or poor moderation policies.

No outrage to see here, please move along

By that logic, any site that allows to display third party content is a phishing/spam site and should be blocked - including twitter, facebook, HN and of course gmail.