Reddit's collectible avatar link can be used for phishing

All of the collectible avatars have links to IPFS gateway reddit.infura-ipfs.io and they don't block non-reddit CIDs or text/html content type. So, the links could be used for phishing since it can load any content hosted on IPFS.

submitted by /u/JeffreyEpsteinAlive
[link] [comments]

from hacking: security in practice https://ift.tt/Dkw4peZ

Comments