Question Which one is the real "Have I Been Pwned" website?

Please provide comments and solutions that are helpful to the author of this topic.

Parkinsond

Level 62
Thread author
Verified
Well-known
Dec 6, 2023
5,043
14,202
6,069
The "i" one is genuine. The "l" one is remarkably suspicious. The Belgian company, EASI SA, the non-redacted owner of the domain, does exist, is in the business registry, and appears on Google Maps. What's the purpose? An archived mirror? Who knows? I would stay away from it.
 
The "i" one is genuine. The "l" one is remarkably suspicious. The Belgian company, EASI SA, the non-redacted owner of the domain, does exist, is in the business registry, and appears on Google Maps. What's the purpose? An archived mirror? Who knows? I would stay away from it.
VT report for the second one
1.jpeg
 
The second one is fake. It doesn't work at all, and has issue with display.
VT report for the second one
Don't bother checking websites on VirusTotal; it's useless. Antivirus companies don't have any sophisticated tools that check if website is malicious or not. Malicious websites are added manually and by the time they get into their database, malicious sites are dead.
The "i" one is genuine. The "l" one is remarkably suspicious. The Belgian company, EASI SA, the non-redacted owner of the domain, does exist, is in the business registry, and appears on Google Maps. What's the purpose? An archived mirror? Who knows? I would stay away from it.
It's a fake site because "l" in question s lowercase L, uppercase I.
 
Antivirus companies don't have any sophisticated tools that check if website is malicious or not
Especially phishing websites; I have found Symantec browser protection and Norton safe web extensions more effective than Kaspersky extension for blocking phishing websites.
 
I personally stopped using "Have I Been Pwned" since the release of "Mozilla Monitor". It automatically searches and sends reports monthly, eliminating the need for manual searching.
Looks more reliable for me than Have I been pwned; I will use it instead; thank you.

The LetsEncrypt cert is free. Thus cybercrooks tend to use that. That said, when I was hosting my own site, I used LetsEncrypt too.
Yes, I know; as you have just stated, it can be used by honorable persons, so cannot rely on completely for discriminating between the original and the fake website.
 
Last edited by a moderator:
  • Like
Reactions: lokamoka820
I couldn't even reach the fake site due to "insecure connection" error.
It doesn't work correctly anymore as a lot of resources simply can't be loaded. It used to load just fine.
It was reachable with valid certificate by Let's Encrypt until today, when it is blocked by NextDNS.
uBlock Origin now blocks access to page too if OISD filter is used.
 
It doesn't work correctly anymore as a lot of resources simply can't be loaded. It used to load just fine.

uBlock Origin now blocks access to page too if OISD filter is used.
Was not detected by K neither earlier nor today; phishing websites and scripts are the Achilles tendon.
 
  • Like
Reactions: Marko :)

You may also like...