Mander
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
CarlsIII@kbin.social to /kbin meta@kbin.social ·
edit-2
2 years ago

Getting a suspicious download prompt while browsing all

media.kbin.social

message-square
17
link
fedilink
14

Getting a suspicious download prompt while browsing all

media.kbin.social

CarlsIII@kbin.social to /kbin meta@kbin.social ·
edit-2
2 years ago
message-square
17
link
fedilink
  • SalamanderA
    link
    fedilink
    arrow-up
    3
    ·
    edit-2
    2 years ago

    I’m glad you could figure it out!

    I followed the link and I see that network request too. I downloaded the file and it is the video.

    • Teppic@kbin.social
      link
      fedilink
      arrow-up
      2
      ·
      2 years ago

      I concur. I also navigated to the site and can see the .mp4 file with that name.
      However the video file is 13.5Mb, not 30b. It also has a valid .mp4 extension.
      I still can’t reproduce the pop-up.

      My best theory this point is OP’s browser is cropping the URL for some reason, which means the “.mp4” part isn’t seen. The browser is then trying to save the 404 response to the request for a file which didn’t exist, and had no extension.

      Sorry OP, but at this point it looks like something your end.
      Out of curiousity, it is an unusual browser, or any scripts/ extensions running which might have corrupted the videos’s URL?

      • CarlsIII@kbin.socialOP
        link
        fedilink
        arrow-up
        1
        ·
        2 years ago

        Just Firefox for iOS, no scripts

      • Pamasich@kbin.social
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        2 years ago

        My best theory this point is OP’s browser is cropping the URL for some reason, which means the “.mp4” part isn’t seen. The browser is then trying to save the 404 response to the request for a file which didn’t exist, and had no extension.

        I looked at the actual web request url it’s doing for me.

        https://downloader.disk.yandex.ru/disk/dfc79ab0f88295834385d89e14b27d1f687e201bf8074f21e0d0d9972096319a/64dc8782/MuDSbA9z5TnczT15nZM5t_fipdB2eZIesleov6SiJ-7hJ1g7sSwJpQ0_lNHok396G53tTWxxKw4e4Gu_L_UmFQ%3D%3D?uid=465360380&filename=7fed06c9.mp4&disposition=attachment&hash=&limit=0&content_type=video%2Fmp4&owner_uid=465360380&fsize=14161986&hid=9d62d8b95cb1158833293fffdf4deada&media_type=video&tknv=v2&etag=a5f932a629c3d365ed6d74bd3ac546e6&expires=1692173809

        I don’t know why they’re getting a download offered in the first place for such a scam looking url, but the display on OP’s image is clearly separating the url into its components and only displaying some of them (the domain and file name). The file extension isn’t part of the url itself here but rather the parameters which aren’t displayed here because there’s usually no need to and they would take up way too much screen space on mobile.

        I think hiding the parameters is a good idea. While comments suggest this is a real video file, this could have easily been a virus disguised as a video. By hiding the parameters, you’re preventing unsuspecting users from putting too much trust into those parameters.

        Edit: reworded the comment

/kbin meta@kbin.social

kbinMeta@kbin.social

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !kbinMeta@kbin.social

Magazine dedicated to discussions about the kbin itself. Provide feedback, ask questions, suggest improvements, and engage in conversations related to the platform organization, policies, features, and community dynamics. ---- * Roadmap 2023 * m/kbinDevlog * m/kbinDesign

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 1 user / month
  • 1 user / 6 months
  • 15 local subscribers
  • 15 subscribers
  • 1.2K Posts
  • 11.8K Comments
  • Modlog
  • mods:
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org