sherlock icon indicating copy to clipboard operation
sherlock copied to clipboard

cgtrader is returning false positives

Open thedaryltan opened this issue 2 years ago • 8 comments

Checklist

  • [x] I'm reporting a website that is returning false positive results
  • [x] I've checked for similar site support requests including closed ones
  • [x] I've checked for pull requests attempting to fix this false positive
  • [x] I'm only reporting one site (create a separate issue for each site)

Description

cgtrader is returning a false positive on all usernames.

I believe the issue is that the data.json file identifies it as a errortype: Message but the current website has changed to return a 404 error instead.

On further testing, I found that even when I changed it to an errortype: message to try to address the false positives, it continues to have the same issue. From some of the data I see in Burpsuite, it seems like cgtrader may have cloudflare protection. If someone knows how to verify and confirm this then I suggest we remove cgtrader from the list of sites.

thedaryltan avatar Feb 26 '24 18:02 thedaryltan

Same here. Also got false positives for Coders Rank.

SourGeckoo avatar Feb 28 '24 03:02 SourGeckoo

Same here. Also got false positives for Coders Rank.

Oh. I haven't encountered that. Does it happen for all usernames or just some specific examples?

thedaryltan avatar Feb 28 '24 05:02 thedaryltan

the vast majority of usernames return a false positive, but not all. It's quite strange...

SourGeckoo avatar Feb 28 '24 05:02 SourGeckoo

Seeing false positives on these 10 currently:

[+] Archive.org: https://archive.org/details/@______ [+] CGTrader: https://www.cgtrader.com/______ [+] Coders Rank: https://profile.codersrank.io/user// [+] G2G: https://www.g2g.com/ [+] Linktree: https://linktr.ee/______ [+] NationStates Nation: https://nationstates.net/nation=______ [+] NationStates Region: https://nationstates.net/region=______ [+] Oracle Community: https://community.oracle.com/people/______ [+] SoylentNews: https://soylentnews.org/~______

JonUleis avatar Mar 04 '24 14:03 JonUleis

Contently (https://username.contently.com) gives a false positive too

orimandel avatar Mar 09 '24 02:03 orimandel

f.txt

chris3857 avatar Mar 11 '24 14:03 chris3857

https://github.com/aip-dev/google.aip.dev/compare/master...jgeewax-patch-2 f.txt

chris3857 avatar Mar 11 '24 14:03 chris3857

I'm getting false positive on these:

[+] Archive.org: https://archive.org/details/@9278HG374G327G23B80 [+] BitCoinForum: https://bitcoinforum.com/profile/9278HG374G327G23B80 [+] CGTrader: https://www.cgtrader.com/9278HG374G327G23B80 [+] CNET: https://www.cnet.com/profiles/9278HG374G327G23B80/ [+] Euw: https://euw.op.gg/summoner/userName=9278HG374G327G23B80 [+] HEXRPG: https://www.hexrpg.com/userinfo/9278HG374G327G23B80 [+] Linktree: https://linktr.ee/9278HG374G327G23B80 [+] NationStates Nation: https://nationstates.net/nation=9278HG374G327G23B80 [+] NationStates Region: https://nationstates.net/region=9278HG374G327G23B80 [+] Oracle Community: https://community.oracle.com/people/9278HG374G327G23B80 [+] Polymart: https://polymart.org/user/9278HG374G327G23B80 [+] Slides: https://slides.com/9278HG374G327G23B80 [+] YandexMusic: https://music.yandex/users/9278HG374G327G23B80/playlists

eduardogott avatar Apr 03 '24 05:04 eduardogott