logoalt Hacker News

shreyaspapitoday at 8:22 AM1 replyview on HN

This is very close to something that happened to a friend of mine. They were trying to follow a MoltBot installation guide, but clicked on a different link that looked legitimate. That page instructed them to paste a command into Terminal. After running it, macOS immediately started asking for multiple permissions, which in hindsight was the big warning sign. But for someone who is non technical might have ran with it.


Replies

renegat0x0today at 9:48 AM

This might sound stupid, but I have my own index, of trusted domains:

https://github.com/rumca-js/Internet-Places-Database

I start with it, to find stuff I know. If there is stuff I don't know and is important to me, I add it to my database.

Also it enforces me to verify each link I visit. So links I visit are mostly ok.

Though I sometimes use chatgpt for instructions, and if someone poinsed the well "well enough" it might spread malware.