|
"The many contradictions of the Web" Fravia's talk at the T2'05 Conference September 2005, version 0.95 The web: a sticky quicksand (Exploits & searching rules) Bigbrother hyper-control & Easy Anonymity (You'r your neighbor) Many new search engines (yet everyone uses google) Books & co (rapidshare & "long strings" approaches) Journals & scientific articles searching contradictions Examples of "web-multidepth" (how deep is deep?) Material Disappeared sites Netcraft -- Structure of the web FFF Music Anti-EULA Bk:flange of myth Languages Rose webbits! Assignement |
The web: Cornucopia of garbage |
Exploits & searching rules |
![]() | (Thanks blewtooth!) |
(Wardriving galore) |
-----------------------------------------
|
"Google alone and your search is never done" |
(some weapons for seekers) |
<script>var c = 58; fc(); function fc(){
if(c>0){document.getElementById("dl").innerHTML = "Download-Ticket reserved. Please wait " + c + ' seconds.
Avoid the need for download-tickets by using a PREMIUM-Account. Instant access!';
c = c - 5;setTimeout("fc()", 5000)} else {document.getElementById("dl").innerHTML = unescape('
%3C%68%32%3E%3C%66%6F%6E%74%20%63%6F%6C%6F%72%3D%22%23%43%43%30%30%30%30%22%3E%20%44%6F%77%6E%6C%6F%61%64%3A%3C%2F%66%6F%6E
%74%3E%20%3C%61%20%68%72%65%66%3D%22%68%74%74%70%3A%2F%2F%64%6C%31%2E%72%61%70%69%64%73%68%61%72%65%2E%64%65%2F%66%69%6C%65
%73%2F%31%34%33%38%37%35%39%2F%32%37%37%35%37%30%39%37%2F%4D%63%47%72%61%77%5F%48%69%6C%6C%5F%4F%72%61%63%6C%65%5F%41%70%70
%6C%69%63%61%74%69%6F%6E%5F%53%65%72%76%65%72%5F%31%30%67%5F%41%64%6D%69%6E%5F%48%61%6E%64%62%6F%6F%6B%2E%72%61%72%22%3E%4D
%63%47%72%61%77%5F%48%69%6C%6C%5F%4F%72%61%63%6C%65%5F%41%70%70%6C%69%63%61%74%69%6F%6E%5F%53%65%72%76%65%72%5F%31%30%67%5F
%41%64%6D%69%6E%5F%48%61%6E%64%62%6F%6F%6B%2E%72%61%72%3C%2F%61%3E%3C%2F%68%32%3E')
}}</script>
In this case you would just use following proxo filter (by Loki):
Name = "RapidShare" Active = TRUE URL = "*rapidshare.de*" Limit = 256 Match = "(var count?)\1 = [#0:45]" Replace = "\1 = 0"The other limit of rapidshare, the 'just one download' limit (that I bet some of you have already encountered in the past few minutes :-) can of course also be circumvented, for instance using rotating anonymous proxies, a task made easy(*) by our good ole PROXOMITRON.
----------------------------- FFF part ----------------------------
FFF part
----------------------------- FFF part ----------------------------
linguistic sine qua non -1 |
linguistic sine qua non -2 |
sine qua non |
All title and intellectual property rights in and to the content that may be accessed through use of this SOFTWARE PRODUCT remains the property of the respective content owner and is protected by applicable copyright or other intellectual property laws and treaties. This EULA grants you no rights to use such content.Now, we cannot accept this, because, to be frank with you, the very reason we might want to install this anti-streaming grabber on our laptop is to grab music that may happen to be patented :-)
| |
:4039BE E833DFFFFF call 4018F6 ; --> do incredibly complex calculations on the registration key :4039C3 85C0 test eax, eax ; --> test result of incredibly complex calculations. Al=0? :4039C5 7512 jne 4039D9 ; --> No: jne "good guy" :4039C7 6824D34000 push 40D324 ; --> Yes: push "U N R E G I S T E R E D V E R S I O N" and flag "bad guy"Should somebody want to be a "good guy" he may just modify the ONE byte in red above, turning that "jump if not equal" into a "jump if equal" (74) instruction...
:0040A5C4 68BE625000 push 005062BE <------ (Data Obj ->"RegCode") ... do stuff with & check length of previously entered strings "RegName and RegCode"... :0040A5D5 E8A62E0200 call 0042D480 <------ StreamDown.NEW_00_KEYCHK_CSD: mov byte ptr [00507FB5], 01 if legit key ... test return from StreamDown.NEW_00_KEYCHK_CSD