Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PSA: FxTwitter is not compromised, fxdeviantart is an unrelated service #677

Open
dangeredwolf opened this issue Feb 18, 2024 · 22 comments
Open

Comments

@dangeredwolf
Copy link
Member

dangeredwolf commented Feb 18, 2024

A different embed fix service, fxdeviantart, had their domain expire, causing it to become parked and link to ads/potential malware. This has caused some confusion because of the similar name to FxTwitter, but fxtwitter.com both doesn't expire until 2026 and is on auto-renew. Hope this clears things up, stay safe out there!

Edit: Also fxfuraffinity.net, while unaffiliated with FxTwitter, does not appear to be compromised either as it still works.

TL:DR:

  • ✅ FxTwitter.com (and FixupX.com) are safe
    (domains currently expire July 2026, August 2025 respectively)

  • ✅ FxFuraffinity.net (and Fxraffinity.net) appear to be safe
    (domains currently expire July 2024)

  • ❌ FxDeviantArt.com has expired and no longer works.
    Do not click on old FxDeviantArt links as they now link to the parked page instead of forwarding you to DeviantArt.
    Replace old links with deviantart.com if possible, otherwise make sure to copy it and strip fx.

@dangeredwolf dangeredwolf pinned this issue Feb 18, 2024
@Atreidae
Copy link

It's good to have some context here; as usual, people assume, "Everything is broken!!!111"

@SoftwareGuy
Copy link

Thanks for the information about this, reassuring to know the developers keep eyes on such things.

@Atreidae
Copy link

Atreidae commented Feb 18, 2024

I don't want to pollute your issues with this, but I feel most people with a brain are going to come here for info.

Having a look, its just a generic parking domain. I've sent requests the match discords and I don't see anything that indicates "they are trying to steal your accounts" it's just a simple 302 redirect to a parking domain.

So Remember!
✅ FxTwitter.com is Safe
✅ FxFuraffinity.com appears to be Safe
❌ FxDeviantArt.com domain has just expired and at present doesn't appear to be anything nefarious
(but that doesn't stop someone buying it and doing something dodgy)

@out-of-phaze
Copy link

I don't want to pollute your issues with this, but I feel most people with a brain are going to come here for info.

Having a look, its just a generic parking domain. I've sent requests the match discords and I don't see anything that indicates "they are trying to steal your accounts" it's just a simple 302 redirect to a parking domain.

So Remember! ✅ FxTwitter.com is Safe ✅ FxFuraffinity.com appears to be Safe ❌ FxDeviantArt.com domain has just expired and at present doesn't appear to be anything nefarious (but that doesn't stop someone buying it and doing something dodgy)

Fxraffinity.net seems to be safe as well.

@sonicdude10
Copy link

I'm glad for this clarification as I run a few large servers that use the FX prefix a lot for content. I initially tried to search this up and got nowhere. A member shared this with me. Thanks for the clarification as that has helped with the fear factor my announcement caused. lol

@lloyddunamis
Copy link

lloyddunamis commented Feb 18, 2024

Please excuse, too. For those curious of FxDeviantArt's current state when visited atm, these "Related searches" pages displayed for expired domains (or even 404 pages at times) is what seems to be a common website hoster behavior to have these visits monetized for the hoster (not the original owner). Visitors are then under mercy of their ad providers, so they could be served redirections to anything from benign to malvertising.

What happens when fxdeviantart is still used as of writing? Nothing; the site doesn't provide anything to embed as the hoster doesn't know what to do with the rest of the URL. When the fx-ified URL is clicked though, it will land you to this same "Related searches" page, instead of redirect you to the original DeviantArt domain (assumed default behavior).
However, like what @Atreidae mentioned, it could be registered by anyone else atm that isn't the fxdeviantart author, and publish something that would take advantage of these URL queries.

Just don't visit, use nor click the fx'd deviantart links for the meantime, to avoid the potential landing to somewhere dangerous.
(And again, FxTwitter/fixupx is unaffected, just to put it on footnote)

@Clawthorn
Copy link

I'd like to mirror the sentiments above.

--

✅ FxTwitter.com is Safe
(embeds properly + redirects to here + owner said so + doesn't expire until 2026-07-07)

✅ FxFuraffinity.net is Safe
(embeds properly + redirects to informational landing page as it should + doesn't expire until 2024-07-26)

⛔ FxDeviantArt.com is Bad Mojo
(doesn't embed anymore + visiting link redirects to dangerous sites + listed as for sale/expired on 2024-02-15)

--

Right now, FxDeviantart is not a nuclear bomb. Posting it on Discord or Telegram won't immediately compromise everyone's account in the server/chat or fill their computer with viruses. Right now it's broken and does nothing unless you click the link.

However... Everyone needs to stop using FxDeviantart right now. And clear out old links just to be safe.

Just because the current owner doesn't care to do anything bad, it doesn't mean the next owner won't start injecting ads/propaganda/fake news/gore/bad-bad-things into every embed. Or start showing things like "To view the hidden link please scan this QR code" to try and hijack accounts.

So please stop using FxDeviantart until it has been established and publicly verified whether it's been recovered by someone benevolent, or whether it's been taken over by someone intending on doing very bad things.
(Or if it's going to be forever stuck in parking limbo behind a $10,000 paywall).

Stay safe everyone.

@seacat17
Copy link

At this point someone should hijack this domain from the malicious actors just to bring it back to the rightful owners.

@lustfulglance
Copy link

oh alr cool, thanks for the info!

1197666742483296356.png

@schuhgri
Copy link

Good to see we actually have sensible information amidst all this panicked misinformation.

@ohareza
Copy link

ohareza commented Feb 21, 2024

At this point someone should hijack this domain from the malicious actors just to bring it back to the rightful owners.

It's at least 100 grand
image

@Clawthorn
Copy link

It's at least 100 grand

I wonder how they calculate that sum, because that seems absolutely bonkers insane...
Unless of course they are actually taking into account how much someone could """earn""" by buying the domain and using it to infect people and cleaning out their bank accounts, and other such terrible, terrible things.

@Meaxis
Copy link

Meaxis commented Feb 21, 2024

I think they calculate it based on the amount of visits it gets? A previous comment here says 10k and now it's up to 100k so maybe the amount of influx traffic from this whole fiasco made them raise the price?

MeAxis.com is also price at $7395 since several years for some reason. Nobody ever bought it, still priced at $7395

@Tschrock
Copy link

That is NOT the price to buy the domain.
That is GoDaddy's minimum offer to start a sale negotiation with the owner. GoDaddy considers the domain to be a Premium Domain, so they've bloated the minimum offer needed for them to negotiate a sale with the owner.
Word of advice, do not use GoDaddy for stuff - For ex, Namecheap's minimum offer to start a negotiation with the owner is only $199.

The domain is registered at Namecheap and is not for sale yet.

According to Namecheap's documentation, the domain is currently in a 30 day grace period in which only the original owner can renew it. After that will be another 30 day redemption period in which the owner can recover it for a fee, or the registrar can auction it - it looks like most namecheap auctions start at $15 but no one really knows what will happen at that point. After that if it has not been recovered or bought, it will enter a 5 day "pending delete" period where no one can touch it, and after that it will be available to the public for registration.
https://www.namecheap.com/support/knowledgebase/article.aspx/9916/2207/tlds-grace-periods/

@Atreidae
Copy link

I'm glad for this clarification as I run a few large servers that use the FX prefix a lot for content. I initially tried to search this up and got nowhere. A member shared this with me. Thanks for the clarification as that has helped with the fear factor my announcement caused. lol

For anyone running Discords, I highly recommend a bot like Nano to convert all your links into posts.

It will reduce the load on services like FxTwitter as it will cache and embed the content into the channel.
It also forces all embeds from supported services to use the same look and feel regardless if they use FX/VX/whatever

Support: https://nano.buxy.xyz/discord
Website: https://nano.buxy.xyz/

@SoftwareGuy
Copy link

I'm glad for this clarification as I run a few large servers that use the FX prefix a lot for content. I initially tried to search this up and got nowhere. A member shared this with me. Thanks for the clarification as that has helped with the fear factor my announcement caused. lol

For anyone running Discords, I highly recommend a bot like Nano to convert all your links into posts.

It will reduce the load on services like FxTwitter as it will cache and embed the content into the channel. It also forces all embeds from supported services to use the same look and feel regardless if they use FX/VX/whatever

Support: https://nano.buxy.xyz/discord Website: https://nano.buxy.xyz/

I've seen this bot in a few different discords, but the website is pretty much "this website is unfinished still sorry xoxo" which is a little... underwhelming...? 😅

I think SaucyBot also was using the fxtwitter prefix too. Not sure if that's been changed.

@Atreidae
Copy link

That is NOT the price to buy the domain. That is GoDaddy's minimum offer to start a sale negotiation with the owner. GoDaddy considers the domain to be a Premium Domain, so they've bloated the minimum offer needed for them to negotiate a sale with the owner. Word of advice, do not use GoDaddy for stuff - For ex, Namecheap's minimum offer to start a negotiation with the owner is only $199.

The domain is registered at Namecheap and is not for sale yet.

According to Namecheap's documentation, the domain is currently in a 30 day grace period in which only the original owner can renew it. After that will be another 30 day redemption period in which the owner can recover it for a fee, or the registrar can auction it - it looks like most namecheap auctions start at $15 but no one really knows what will happen at that point. After that if it has not been recovered or bought, it will enter a 5 day "pending delete" period where no one can touch it, and after that it will be available to the public for registration. https://www.namecheap.com/support/knowledgebase/article.aspx/9916/2207/tlds-grace-periods/

Dumb question here. Has anyone actually reached out to the owner of FxDeviantArt and checked to see what they want to do?
At first I figured it was just a short thing that maybe they forgot to renew.

@thetacola
Copy link

fwiw, namecheap has a grace period with recently expired domains bought through them where, although it goes to their landing page, the owner of the domain can still renew it without worrying about it being taken for about a week or two.

@Tschrock
Copy link

Dumb question here. Has anyone actually reached out to the owner of FxDeviantArt and checked to see what they want to do?

@Atreidae As best they can, yes, though it looks unlikely the owner will respond. You can follow this issue on the fxdeviantart repo for updates: daisyUniverse/fxdeviantart#4

Further discussion should probably happen there so we're not filling up fxtwitter's issues.

fwiw, namecheap has a grace period with recently expired domains bought through them where, although it goes to their landing page, the owner of the domain can still renew it without worrying about it being taken for about a week or two.

See the comment I posted earlier #677 (comment) for more details and a link to Namecheap's expiration policies.

@EpicLPer
Copy link

Currently trying to contact the original creator of fxdeviantart to see if I can reach her. It seems she went "offline" a couple months back and hasn't posted anything since on any platform that I could find.

I'm also currently in contact with Namecheap to see if I can somehow prevent the domain from fully expiring and falling into shady hands.

@EpicLPer
Copy link

I just made a payment towards Namecheap to get "fxdeviantart.com" renewed for another year via a third-party request.
If the original buyer doesn't decline the payment within 24 hours the domain should be up and running by that point again.

Hope this means that no scammer or other bad actor will get control of the domain meanwhile.

@EpicLPer
Copy link

EpicLPer commented Mar 15, 2024

The domain "fxdeviantart.com" is safe again!

I was able to make a "third party payment" towards Namecheap which now reinstated the domain, this means it's safe for another year ❤️
You can safely use it again to link to art there!

@dangeredwolf dangeredwolf unpinned this issue Oct 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests