Wikimedia narrows down the app sendin 90M requests to a pic of flower
phabricator.wikimedia.org
phabricator.wikimedia.org
Looks like a case that the developers carelessly copied and pasted some "sample code" into the app...
> [...] it seems that there is no good way to get in touch with them through email (I sent an email to all publicly available channels, only to get back an autoresponder that assumes I'm an user of the app and asking for my phone number). I eventually resorted to DM their CEO on twitter.
Resorting to Twitter for support is increasingly common. The importance of having an "abuse@" email (and possibly some social media bots to DM all sysops when a mail arrives)...
On the other, it made "Copy Paste Programming" go to eleven. (There was even a C# example the other day that famously broke in a big project but I can't find it)
Maybe it would be a case of Stack Overflow linting examples to remove stuff like builtin urls and such.
I've seen "developers" complaining that example code with a very explicit >replace this part for your use case< complaining that the example didn't work. I guess making some things harder would just be an overall gain.
Possibly the SO question in question: https://stackoverflow.com/a/522874/615306
> I know it has something to do with some mythical thing called a mutex, rarely can I find someone that bothers to stop and explain what one of these are.
Oh my
I would love a bet it list of common use case templates which can just pop up when I use visual studio.
Or maybe a sort of snippet box to drag and drop in my code. For example reading and writing a file in C sharp isn't something I exactly know off the top of my head.
Always maintain some out of band support system. If that's email, so be it.
If there's business owners watching this, please do not make Twitter (or any other social media) your primary point of contact for support or abuse. I stay far away from Twitter such that I don't have an account and can't even see a single tweet without jumping through some hoops. I've learned via posting here that I'm not alone in this and that this trend will likely grow as time goes on.
We've contacted the manufacturer and I think it's been patched but the life time of installed equipment is long...
Yesterday: over a billion HTTP requests...
I’d like to explore mechanisms for tests that detect IoT devices that misbehave this way (and other ways as well). Your anecdote sounds interesting. Is it unrelated to time servers? Unrelated to internet connectivity tests?
> We then found the specific app that was making the request by matching the time when it was opened and the time image was requested from our servers, restricting the results to the User-Agent '-' and from the IP we tested.
Unless I missed something, running mitmproxy/Charles etc. in front of the phone would have been way easier than querying the entirety of Wikimedia server logs and trying to match IP & timing windows.
Edit: after looking into this a bit, this is pretty nuts. How do enterprises inject certificates now?
They don't. It's been made increasingly clear that allowing certs roots to infect unrelated apps is a Bad Thing. MDM profiles etc presumably allow internal certs to be deployed, but those are hopefully limited as countries, let alone companies, have attempted to use those mechanisms to spy on millions of people.
> To further confirm this finding and to ensure that we had the correct app, we decided to log DNS queries from a phone by setting up a local resolver to capture DNS traffic. After pointing the phone towards it and launching the app, we noticed that it was indeed the one looking up upload.wikimedia.org on startup.
> We did this by opening the popular apps one-by-one and noting down the time
If you are familiar with "querying the entirety of wikimedia server logs" and do it all the time (the word "entirety" makes it seem like a big deal, but they clearly have tools meant for this that they use all the time)... and have never learned to use "mitmproxy/Charles etc" before....
It sounds like the "querying the entirety of the server logs" for this task probably took them tens of minutes at most. It would probably take me at least an hour or two to learn how to use "mitmproxy/Charles etc".
So "way easier"?
If you have to do this sort thing all the time, it might be useful to install and learn how to use "mitmproxy/Charles etc", why not? Certainly worth considering. But if the tools you have are working for you...
I mean, what they did seems like it worked to get them the answer and was pretty efficient, using the toolset they use all the time for dealing with wikimedia ops... Seems like some good detective work to me. I get the desire to point out other tools that would be well-suited for this kind of task, but why the need to point it out as if they did something wrong or not "way easier"? Sounds like what they did was pretty easy for them, and they didn't need to learn new tools to make it "way easier".
I enjoyed hearing about how they tracked this down, and found it useful. Pointing out how they didn't use the "right" tools just makes it less likely people will be willing to share their processes.
It does say later in the post that they used a local proxy to confirm their findings, too. Maybe they wanted to check from both sides, just to be sure.
The analysis stops right when things start to become interesting. I was hoping there'd be a decompiled code snippet to see what the app in question is actually doing with the image, since it's not displaying it.
What I'm trying to say is, the image is a plant
> We will thus hold back the banning of the url for now [...]
If on the other hand it's really just some benign leftover example code downloading the image and not doing anything with it later as has been suggested and is indeed the most likely, there'd be no harm in confirming that's the case.
They went to great lengths with their investigation, and this would be the obvious final step to wrap it up. Posting a couple of the relevant .smali lines wouldn't have to reveal the name of the app in question (which at this point can be identified by anyone sufficiently motivated anyway).
> it is a popular chat/social media mobile app used in India
> it sets the User-Agent and Referer to '-'
> it fetches the image from Wikimedia Commons but does not display it
And then they identified which app it was, but it is not revealed
[1] https://news.ycombinator.com/item?id=26073450 has located the actual app and intended purpose, for your information.
If I were to guess, they use the picture as a connectivity/speed test. They probably figured Wikipedia has unlimited free bandwidth, so they didn't care.
However the image is in fact 160 kilobytes, so I suspect whatever speedtest is being done is getting the wrong results...
Is an app downloading, but never displaying, creative commons content infringing on copyright (by not showing correct attribution and violating the CC terms)?
Besides copyright, could this be considered theft of service?
Is it? If you make a resource freely available to people online, and people access said resource, what's the legal ramification there? It would appear there is no malicious intent which would be necessary to make the case for abuse, and theft of service would be a stretch given that Wikimedia doesn't charge for their service.
Very unlikely anyone will care...
>Disrupting the services by placing an undue burden on a Project website or the networks or servers connected with a Project website;
NTP domains have had a history of similar problems, and they seem to be resolved by apologizing, fixing the problem, and sometimes a donation.
In any case let's not get carried away. 90 million requests for a 70KB file is only 5.8 TB. Wikimedia mentions in their about pages that they are hosted on bare metal servers in various places around the world. Just going on the bandwidth charges of the first provider in the list, that'd be about $30 USD per month if they have the "bulk" pricing or $300 USD per month if they use the list pricing. I don't think that is worth going to court over for the Wikimedia foundation.
Indians of Hacker News, what are the likely candidates?
There are a lot of apps that have launched in India around that time frame with huge numbers of users thanks to nationalistic rhetoric. They are terrible apps, but they are made in India terrible apps, and that apparently is enough to get a large following in India of late.
Now, what the U.S. excuse is for its terrible apps, I'm not sure...
That's awesome!
Every app has to start somewhere. I mean, even ISRO started by transporting rocket parts on bikes, and now has a satellite around Mars.
https://www.indiatimes.com/technology/science-and-future/fro...
* Ask HN: What does traffic to example.com look like?
It makes sense that's still included deep down in some copy/paste app stuff.
More discussion https://news.ycombinator.com/item?id=26072025
If only for the outrageous user agent.
Just don't link to bug trackers, ever.