Over the last few weeks, I've gotten several spam emails from different friends that only contained links to different websites.
I would like to click on those links and see what's on the website. My reasons are curiosity, the ability to understand how dangerous the website might be, and to differentiate between a product-spam email ("Buy product XYZ!") and a website that tries to do something dangerous to a computer.
I do not intend to use a production system, a system with my personal data on it, or something I am not willing to lose in the process; I am really just curious.
So what measures would I need to take in order to safely1 click on those links?
My ideas so far are:
- Virtual Machine
- Disable Flash, Java, JavaScript2, ... in the browser
- Having an up-to-date OS / Antivirus
- Use NoScript
- Use external websites that check the linked website like: http://www.antihacksecurity.com/scan-a-website-for-virus-malware (link seems down?) beforehand
Footnotes:
- I am almost certain that there is no way to really safely click those links, so maybe this should be called "minimize the risk when you..."
- I am aware that disabling stuff might not give me a complete and real picture of the website, since I might not experience the intended effect and think "It's safe."
view-source:on chrome, save the html, disconnect the device from your network, and view it as a local html file? – WorseDoughnut Mar 17 '16 at 15:19view-source:works on Firefox too, so it's not browser dependend. But still, a good starting point I guess. – hamena314 Mar 17 '16 at 15:23<script>tag, so that's a bad idea. I'm surprised no one has suggested usingcurland viewing in your favorite editor, similar toview-source. – Brian McCutchon Mar 18 '16 at 05:46https://www.m¡crosoft.com? – dan Mar 18 '16 at 10:18Il1|...(capital I, small l, one [in some fonts / programs the one only has 1 stroke] and a pipe)visually with 100% certainty. EDIT: Fun fact - the font of the security.stackexchange editor and the markup seem to use different fonts, since the capital i in the editor only has 1 stroke and no serifs) – hamena314 Mar 18 '16 at 10:53Arial,Helveticawhich are the favourite ones of criminal hunting on this mines field). – dan Mar 18 '16 at 15:59