Theme editor

lewdcorner being over run by spam / hacked accounts

highlrecommend

I read the news today.
Registered
Lewd
Prestige 1
Prestige 2
Prestige 3
Prestige 4
Prestige 5
Prestige 6
zoidberg
Joined
Dec 1, 2025
Threads
26
Messages
3,554
Vouches
5
Likes
4,921
LewdCoins
⚡39,182
Donation coins
0
Platinum
0
adcoin
0
1/3
‎9 Months of Service‎
Thread owner
it seems there are a load of sleeper accounts that activate after 2 years or are hacked accounts with all the info wiped.
and a bunch of accounts getting hacked from malware from file hosting websites

if lewdcorner stops its members from using those questionable "free file hosts" that force feed noobs Trojans lewdcorner wouldn't have this problem

better fix it or there will be 50 bots / spammer accounts for each real person & the site will become unusable

@Jack Of Blades ☝️☝️☝️☝️☝️☝️ major problem to fix

also scan & delete / ban all sleeper accounts over 3 to 6 months old with no activity
this site has nothing for non active accounts
 
Thread owner
a real life warning for everyone

please run a deep virus / Trojan scan asap.
accounts are being hacked & turned into spam accounts

not talking about scanning with windows defender either, get an offline scanner that will really scan the fuck out of your machine

phone users ?
you are probably most at risk.



 
this is a cookies stealer, there is no way in hell i can figure out who is who, so not much admins can do.
 
If the cookies get stolen, will changing passwords invalidate them? If so, maybe forcing password resets might help.

I should also remember to change mine from time to time...
 
If the cookies get stolen, will changing passwords invalidate them? If so, maybe forcing password resets might help.

I should also remember to change mine from time to time...
technically yes, but doing so will probably piss users off that dont know their passwords, and will influx the ticket system with password resets manually.
 
Which file hosts are the most troublesome?
It’s easier to name the most reliable ones, such as Gofile, Pixeldrain, and Vikingfile. Even so, that doesn’t mean they’re completely safe—if you download something and the file itself is infected, you’re screwed. Nor does it mean that all of Buzzheavier or Datanodes are compromised; they’re generally reliable, though they’ve had some recent slip-ups.

My top recommendations for everyone remain the same:
  • Use browsers and search engines that block third-party cookies and trackers by default, and allow you to easily clear your browsing history.
  • At least once a month, delete ALL your cookies, scan your device, and every 6 months or once a year, change your important passwords.
  • Use two-factor authentication.
  • Never give anyone your personal information—whether from your real life or your online accounts—ever.
  • Always have three email addresses: one for personal use, one for professional use, and one for nonsense.
  • Do not click on ANY suspicious links.
  • Use ad blockers and pop-up blockers.
  • Always scan everything after downloading it.
  • If you download games, do so from trusted websites, and even then, you should check certain things. The most important thing is that the file size is correct.
  • Always make sure the URL of the page you're visiting is correct. This is especially important for download sites and sites where you enter personal information (banks, government sites, etc.)
  • Be careful with executable files.
  • If you’re asked to disable your antivirus to install something, delete the file—don’t fall for that trick.
I shouldn't even have to explain things that should be common sense, although some things aren't. You should always take precautions when browsing; using Google Chrome without any kind of protection is the most irresponsible thing you can do. Opt for browsers like DDG, Brave, or any other that can guarantee certain levels of security.
 
Last edited:
Mixdrop links seem a little suspicious. Links redirect to and downloads don't didn't wfm when I tried.
But I wouldn't assume that another site can easily steal cookies of another domain without either having a browser exploit, malicious extension or tricking you into downloading some malware. So, check your browser extensions too!

I thought about proposing to introduce checksums in game posts as good practice. That way, you know if the files themselves have been modified while re-uploading etc.
But maybe it's too hard to keep track if versions change frequently, maybe it's too much work. And do you hash the archive or the content (there will be a different hash for the same files in a zip and 7z, for example)?
What do you think?
 
Last edited:
Mixdrop links seem a little suspicious. Links redirect to and downloads don't didn't wfm when I tried.
But I wouldn't assume that another site can easily steal cookies of another domain without either having a browser exploit, malicious extension or tricking you into downloading some malware. So, check your browser extensions too!

I thought about proposing to introduce checksums in game posts as good practice. That way, you know if the files themselves have been modified while re-uploading etc.
But maybe it's too hard to keep track if versions change frequently, maybe it's too much work. And do you hash the archive or the content (there will be a different hash for the same files in a zip and 7z, for example)?
What do you think?
If you don't use an ad blocker or pop-up blocker, don't even think about using Mixdrop.
 
If you don't use an ad blocker or pop-up blocker, don't even think about using Mixdrop.
lol. My blockers work well enough that I don't see any of that - but it just didn't work and the site redirects. I wouldn't recommend a site like that if there are better alternatives.
 
Mixdrop links seem a little suspicious. Links redirect to and downloads don't didn't wfm when I tried.
But I wouldn't assume that another site can easily steal cookies of another domain without either having a browser exploit, malicious extension or tricking you into downloading some malware. So, check your browser extensions too!

I thought about proposing to introduce checksums in game posts as good practice. That way, you know if the files themselves have been modified while re-uploading etc.
But maybe it's too hard to keep track if versions change frequently, maybe it's too much work. And do you hash the archive or the content (there will be a different hash for the same files in a zip and 7z, for example)?
What do you think?
Yeah I would never use miixdrop. They have issues and it doesn't seem like it's a concern to the site owners. I wouldn't be surprised if they didn't give a damn either.
 
lol. My blockers work well enough that I don't see any of that - but it just didn't work and the site redirects. I wouldn't recommend a site like that if there are better alternatives.
Mixdrop is hit or miss—sometimes it works, sometimes it doesn't. If you know how it works, it's not a bad option to have as an alternative, although it's never my first choice when I download something... and sometimes it gets slow as hell.

Come to think of it, when I set up mirrors, I never use Mixdrop; I usually use Gofile, Pixeldrain, Buzzheavier, Vikingfile, and ZeroStorage.
 
Which file hosts are the most troublesome?
Wouldnt trust any of them without at the very least running pop-up blockers and ad-blockers. That being said, touch wood, the only ones I've not had any issues with is gofile and pixel-drain. Also for what its worth if a site requires you to jump through hoops to get to the file host site, dont bother. You'll probably be able to find it on some other forum or imageboard.
 
please run a deep virus / Trojan scan asap.
accounts are being hacked & turned into spam accounts
Did that this morning looking for a cooty... Took for Fuckin Ever too.. Only 1 suspicious gam-hack file for a game on Steam..
 
it seems there are a load of sleeper accounts that activate after 2 years or are hacked accounts with all the info wiped.
and a bunch of accounts getting hacked from malware from file hosting websites

better fix it or there will be 50 bots / spammer accounts for each real person & the site will become unusable
Yeah, I came across three of the buggers last night.
this is a cookies stealer, there is no way in hell i can figure out who is who, so not much admins can do.
I wish you luck in your endeavors. I do hope there is an actual fix to this particular problem before it escalates.
You must be registered to see attachments
 

Attachments

You must be registered for see attachments list
Yeah, I came across three of the buggers last night.

I wish you luck in your endeavors. I do hope there is an actual fix to this particular problem before it escalates.
You must be registered to see attachments
the only way to fix it is the root, tell idiots dont install programs from discord and or untrusted sites lol.
 
[...]
My top recommendations for everyone remain the same:
  • Use browsers and search engines that block third-party cookies and trackers by default, and allow you to easily clear your browsing history.
  • At least once a month, delete ALL your cookies, scan your device, and every 6 months or once a year, change your important passwords.
  • Use two-factor authentication.
  • Never give anyone your personal information—whether from your real life or your online accounts—ever.
  • Always have three email addresses: one for personal use, one for professional use, and one for nonsense.
  • Do not click on ANY suspicious links.
  • Use ad blockers and pop-up blockers.
  • Always scan everything after downloading it.
  • If you download games, do so from trusted websites, and even then, you should check certain things. The most important thing is that the file size is correct.
  • Always make sure the URL of the page you're visiting is correct. This is especially important for download sites and sites where you enter personal information (banks, government sites, etc.)
  • Be careful with executable files.
  • If you’re asked to disable your antivirus to install something, delete the file—don’t fall for that trick.
[...]

I would add, even if this alone is not enough: never store your passwords in your browser, or even your computer. Use your head, bloc notes, or post it instead. And store it somwhere safe ofc lol i know many stories of passwords being leaked because of an innocent photo where said post it conveniently appeared
 
I would add, even if this alone is not enough: never store your passwords in your browser, or even your computer. Use your head, bloc notes, or post it instead. And store it somwhere safe ofc lol i know many stories of passwords being leaked because of an innocent photo where said post it conveniently appeared
this is why ive been using protonpass for the last 2 years and have had no issues
 
I get that not everyone is a big fan, especially after some online installers were compromised recently, but I've always downloaded files through JDownloader, and skipping the web portion of these hosting sites is often half the battle. Of course if the file itself is infected JD can't really do much about it.
 
I use AdGuard and AdGuard Extra, and I usually clear all my browser cookies every day, sometimes I do it every few days. However, it would be nice if, when a game is uploaded, the uploaders would post a VirusTotal scan and use only reliable hosting services. I don't trust MixDrop or MediaFire at all. I'm going to run a deep scan on my PC right now, just in case.
 
Back
Top Bottom