avatarEmily B

Free AI web copilot to create summaries, insights and extended knowledge, download it at here

3375

Abstract

    </a>
    </div><p id="b56b">BuiltWith told me it was a UK server, but not much else. Doing a WhoIS search was a little more helpful in determining an Icelandic domain host (Namecheap), server in the UK, and privacy settings on (unsurprising).</p><div id="d489" class="link-block">
      <a href="https://www.whois.com/whois/mirror-medium.com">
        <div>
          <div>
            <h2>Whois mirror-medium.com</h2>
            <div><h3>Whois Lookup for mirror-medium.com</h3></div>
            <div><p>www.whois.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*iL_NQJPNQml1H5R7)"></div>
          </div>
        </div>
      </a>
    </div><div id="dfd4"><pre><span class="hljs-attr">Domain name:</span> <span class="hljs-string">mirror-medium.com</span>

<span class="hljs-attr">Registry Domain ID:</span> <span class="hljs-string">2656501240_DOMAIN_COM-VRSN</span> <span class="hljs-attr">Registrar WHOIS Server:</span> <span class="hljs-string">whois.namecheap.com</span> <span class="hljs-attr">Registrar URL:</span> <span class="hljs-string">http://www.namecheap.com</span> <span class="hljs-attr">Updated Date:</span> <span class="hljs-number">2023-10-22T07:03:35.35Z</span> <span class="hljs-attr">Creation Date:</span> <span class="hljs-number">2021-11-21T15:02:04.00Z</span> <span class="hljs-attr">Registrar Registration Expiration Date:</span> <span class="hljs-number">2024-11-21T15:02:04.00Z</span> <span class="hljs-attr">Registrar:</span> <span class="hljs-string">NAMECHEAP</span> <span class="hljs-string">INC</span> <span class="hljs-attr">Registrar IANA ID:</span> <span class="hljs-number">1068</span> <span class="hljs-attr">Registrar Abuse Contact Phone:</span> <span class="hljs-string">+1.9854014545</span> <span class="hljs-attr">Reseller:</span> <span class="hljs-string">NAMECHEAP</span> <span class="hljs-string">INC</span> <span class="hljs-attr">Domain Status:</span> <span class="hljs-string">clientTransferProhibited</span> <span class="hljs-string">https://icann.org/epp#clientTransferProhibited</span> <span class="hljs-attr">Registry Registrant ID:</span> <span class="hljs-attr">Registrant Name:</span> <span class="hljs-string">Redacted</span> <span class="hljs-string">for</span> <span class="hljs-string">Privacy</span> <span class="hljs-attr">Registrant Organization:</span> <span class="hljs-string">Privacy</span> <span class="hljs-string">service</span> <span class="hljs-string">provided</span> <span class="hljs-string">by</span> <span class="hljs-string">Withheld</span> <span class="hljs-string">for</span> <span class="hljs-string">Privacy</span> <span class="hljs-string">ehf</span> <span class="hljs-attr">Registrant Street:</span> <span class="hljs-string">Kalkofnsvegur</span> <span class="hljs-number">2</span> <span class="hljs-attr">Registrant City:</span> <span class="hljs-string">Reykjavik</span> <span class="hljs-attr">Registrant State/Province:</span> <span class="hljs-string">Capital</span> <span class="hljs-string">Region</span> <span class="hljs-attr">Registrant Postal Code:</span> <span class="hljs-number">101</span> <span class="hljs-attr">Registrant Country:</span> <span class="hljs-string">IS</span> <span class="hljs-attr">Registrant Phone:

Options

</span> <span class="hljs-string">+354.4212434</span> <span class="hljs-string">@withheldforprivacy.com</span> <span class="hljs-attr">Name Server:</span> <span class="hljs-string">dns1.namecheaphosting.com</span> <span class="hljs-attr">Name Server:</span> <span class="hljs-string">dns2.namecheaphosting.com</span> <span class="hljs-attr">DNSSEC:</span> <span class="hljs-string">unsigned</span> <span class="hljs-attr">URL of the ICANN WHOIS Data Problem Reporting System:</span> <span class="hljs-string">http://wdprs.internic.net/</span> <span class="hljs-string">>>></span> <span class="hljs-attr">Last update of WHOIS database:</span> <span class="hljs-number">2024-02-22T23:31:37.70Z</span> <span class="hljs-string"><<<</span> <span class="hljs-string">For</span> <span class="hljs-string">more</span> <span class="hljs-string">information</span> <span class="hljs-string">on</span> <span class="hljs-string">Whois</span> <span class="hljs-string">status</span> <span class="hljs-string">codes,</span> <span class="hljs-string">please</span> <span class="hljs-string">visit</span> <span class="hljs-string">https://icann.org/epp</span> </pre></div><p id="8e5c">The next stop was much more interesting <a href="https://www.nslookup.io/domains/mirror-medium.com/webservers/">when I did an NS lookup</a> and found an IP address: <b>185.61.153.110</b>IPv4.</p><p id="0d59">And then it gets interesting:</p><figure id="a5f1"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*FMYAWGH4wU7i-OanrP9iNQ.png"><figcaption>Screenshot from author from Medium Discord</figcaption></figure><p id="a498">The iPv4 address into a checker and came up with this:</p><figure id="1917"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*Khyv1YPa1jH0k7OZF-xY-A.png"><figcaption>Screenshot taken by author</figcaption></figure><p id="7259">Okay. Interesting. I didn’t want to start accidentally doxxing some poor dude, so I googled the name and his location to see what came up: and got <a href="https://www.abuseipdb.com/check/185.61.154.51">two</a> <a href="https://www.abuseipdb.com/check/185.61.153.110">links </a>to Abuse IPBD. Here’s the summary for the TL;DR crowd (marked over names and unrelated chat banter):</p><figure id="1d7e"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*PWScm0Fnb-rUxCnaaLqvaA.png"><figcaption>Screenshot taken by author, reposted with permission from participants because wtf</figcaption></figure><p id="3543">Essentially, the mirror site was thrown up by a hacker from England who’s been active since around the time the pandemic started and a metric ton of paywalled content has been mirrored through the RSS feed. This seems like something <a href="undefined">Tony Stubblebine</a> might need to be aware of?</p><h1 id="6968">What Writers Can Do:</h1><p id="d0ea">As for everyone else, the best thing we can do is mass report the activity in order to get the site taken down ASAP (Thanks <a href="undefined">The Sturg</a>, for being so on top of this and getting the word out!)</p><p id="35d7">Also thanks to <a href="undefined">Mark Suroviec, M.Ed.</a>, <a href="undefined">The Accidental Monster</a>, <a href="undefined">Sam W.</a> and <a href="undefined">Binky Ink Writing</a> for taking part in the session to work out just what the hell had been happening here.</p></article></body>

Alert to Medium Writers: The Scrapers have Intensified

Something mirrored this way comes

Photo by Tianyi Ma on Unsplash

This Thursday, the Medium Discord sent out a mass message: someone had been scraping the paywall and mirroring their articles at least a week back.

There’d been a weird vibe going around in February already. A ton of Everyday Explorer domain accounts had been mass-liking and subscribing to accounts, amassing some pretty substantial follower numbers. On light examination, their content was all AI-generated (maybe 10–15 accounts), and a lot of people scratched their heads and blocked.

Now, the Mirror-Medium site had amassed a huge amount of content scraped directly from the Medium paywall:

The server was panicking. Here were the main issues (paraphrased from the chat):

  1. ‘The website scrapes the RSS feeds.’ (The Accidental Monster)
  2. ‘For anyone that deletes, revises and uploads old work, having someone else scrape and repost their work on another site could get them flagged with plagiarism and have them lose their account’ (Sam W.)
  3. ‘What is the site that republished Medium stories? It can’t be a mirror site. It needs to be flagged. Medium should have in its algo detection of plagiarism a way to see that it’s from that site and dismiss it right away.’ (Binky Ink Writing)
  4. Web scraping is only legal if it’s publicly available on the internet. If it’s behind a login, especially a paywall, the situation is different.

The Game is Afoot

I happened to be eating dinner when the mass message went out, so I started doing a few quick searches on my phone:

BuiltWith told me it was a UK server, but not much else. Doing a WhoIS search was a little more helpful in determining an Icelandic domain host (Namecheap), server in the UK, and privacy settings on (unsurprising).

Domain name: mirror-medium.com
Registry Domain ID: 2656501240_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.namecheap.com
Registrar URL: http://www.namecheap.com
Updated Date: 2023-10-22T07:03:35.35Z
Creation Date: 2021-11-21T15:02:04.00Z
Registrar Registration Expiration Date: 2024-11-21T15:02:04.00Z
Registrar: NAMECHEAP INC
Registrar IANA ID: 1068
Registrar Abuse Contact Phone: +1.9854014545
Reseller: NAMECHEAP INC
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registry Registrant ID: 
Registrant Name: Redacted for Privacy
Registrant Organization: Privacy service provided by Withheld for Privacy ehf
Registrant Street: Kalkofnsvegur 2 
Registrant City: Reykjavik
Registrant State/Province: Capital Region
Registrant Postal Code: 101
Registrant Country: IS
Registrant Phone: +354.4212434
@withheldforprivacy.com
Name Server: dns1.namecheaphosting.com
Name Server: dns2.namecheaphosting.com
DNSSEC: unsigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2024-02-22T23:31:37.70Z <<<
For more information on Whois status codes, please visit https://icann.org/epp

The next stop was much more interesting when I did an NS lookup and found an IP address: 185.61.153.110IPv4.

And then it gets interesting:

Screenshot from author from Medium Discord

The iPv4 address into a checker and came up with this:

Screenshot taken by author

Okay. Interesting. I didn’t want to start accidentally doxxing some poor dude, so I googled the name and his location to see what came up: and got two links to Abuse IPBD. Here’s the summary for the TL;DR crowd (marked over names and unrelated chat banter):

Screenshot taken by author, reposted with permission from participants because wtf

Essentially, the mirror site was thrown up by a hacker from England who’s been active since around the time the pandemic started and a metric ton of paywalled content has been mirrored through the RSS feed. This seems like something Tony Stubblebine might need to be aware of?

What Writers Can Do:

As for everyone else, the best thing we can do is mass report the activity in order to get the site taken down ASAP (Thanks The Sturg, for being so on top of this and getting the word out!)

Also thanks to Mark Suroviec, M.Ed., The Accidental Monster, Sam W. and Binky Ink Writing for taking part in the session to work out just what the hell had been happening here.

Writing
Medium
Intellectual Property
Community Engagement
Recommended from ReadMedium