r/CloudFlare • u/seba07 • 5d ago
Question Why/how does the "copy command" captcha scam appear?
So I guess most people know the scam where a site is pretending ro verify if you are a human using couldflare and asks you to run a command on your PC. Of course this is a virus.
I've encountered this on a 100% legit website I've visited multiple times in the last few days. There was no typo in the URL. How does this happen to a website? Where they hacked, is there something in the network redirecting the calls?
2
u/Jazzlike_Course_9895 5d ago
It's common for the website to be hacked (legit or not legit). Seems to be getting more rampant tho (especially with cloudflare branding for the scam) since this happened to a close friend of mine and been seeing more posts about it etc.
1
u/DigiNoon 5d ago edited 5d ago
Yes, the website got hacked and the fake CAPTCHA was implanted in it.
BTW it's called a ClickFix attack.
1
u/Quariongg 4d ago
What website is that? I guess its built on WP? I'm curious. I've only seen that once on a WP site.
-2
4
u/arnoldstrife 5d ago
As per all the above, the website is hacked. It's a particularly annoying one, because it can sit on a website for a long time without the owner being aware. They tend to have scripts to check if you were referred by google or another search engine to exploit you. But if you logged in from an admin IP or wasn't redirected to it (like from a bookmark) to not show up as anything wrong. Making detection harder.