Show HN: This website moves your mouse cursor
attejuvonen.fi
attejuvonen.fi
I had just picked up Delphi and being the nerd I was, I wanted to make use of it anywhere I could. At the time, the Windows API was essentially completely open to mess with, and I had discovered a bunch of weird things, like the fact that setting (!) the mouse cursor position was even possible, and I knew the CD ROM drive could be opened with code as well.
I packed those things into a quick Delphi program, removed its main window (so like a daemon essentially) and then deployed it on our school computers (everything was open, I just put it into the Startup folder if I remember correctly).
Well, I had the daemon deployed on most computers eventually and it had a timer that looked up a file on the shared network drive, and depending on what was in that file, it would do something, or stay quiet in the background.
Since our IT classes were mostly just "doing stuff in Microsoft Word" (good old times), I couldn't hold off for too long and just added the magical "shakymouse" to the text file, a minute or two later, you would see everyone's mouse cursor start to wobble. It became next to impossible to hit a button or anything really, and I just had the time of my life as the teacher scrambled around to figure out what in the hell was going on.
I then changed the text file to "cd" and everyone's CD drive opened (one after the other as they all slowly picked up the command). It was SO AMAZING (just the choreography of it all), I literally almost shit my pants out of excitement.
Problem was, there was only one person in the entire school they felt was capable of such nonsense, so they had me at the principal's office an hour later. They made a big show out of it, and told me to go home as they'll come up with a punishment and they'll also need to talk to my parents.
I thought I was in massive trouble, didn't sleep at all that night. Next morning, I'm back at school, principal wants to see me, tells me I am free from having to attend the IT classes, as I clearly don't need them, and this reduces the chance of me getting bored. So it worked out quite nicely after all. Lesson learned... CRIME PAYS!!!
When the IT guy talked to me, he even said he'd seen Rainmeter in a magazine and tried it out at home and thought it was pretty cool. But the admins had watched Hackers too many times, it seems, and thought it appropriate to treat me like a delinquent :P
Edit: Looks like Rainmeter is still alive and kicking! Maybe I'll give it a revisit
In another school (where IT was much more advanced, likely a lot like you've encountered), I put a file called DukeNukem.exe on the school-wide network share, and it didn't take long for people to discover it. It just showed an error, game needs some extra permission, and asked you to enter the password to try again. Well, people did that of course and the game didn't work. But another file on the network drive collected EVERYONE's password, one after the other, it took a few weeks until they caught me. They were able to use some Novell admin ninja something something to figure out who placed the file there and again, I was kicked out of IT classes, no other harm.
They blocked executables on floppies, but if you copied something to a floppy as a .txt file to My Documents and renamed it, it was runnable.
They then blocked executables in My Documents, but if you put in a batch file, that'd still run.
They then blocked batch files, but if you created a shortcut to "cmd.exe" and ran that off a floppy, you got a shell prompt, from which you could run whatever you want.
They then blocked executing "cmd.exe", but the initial response didn't also include "command.com"...
_Unfortunately_, at that time, I'd already discussed the "cmd.exe" loophole with them, and the "command.com" loophole was basically the same thing that I'd already been told not to do... so I got detention for this one, and promptly stopped.
Ps. cd opening was there too :)
At school, it was sort of a cat-and-mouse game between the students and the sysadmin. Kids would find new ways of evading the school blocks (different proxies, someone getting a bypass login, etc so they could access myspace) that the admin would then catch a couple weeks later and close. A lot of these proxies were distributed on the fileserver that was shared between students.
One day, I wrote a small piece of software in my programming class (in VB6!!) that would wait a random length of time, and then open and close the CD tray. I wrote a short batch script that would copy that file to startup and then open the current popular proxy software. I then changed the icon on that script and placed it where people expected to find the proxy software, giving them reason to run my script.
Students then unknowingly disseminated my software all over the school, and the next day (after PCs were rebooted overnight) the software would take effect and randomly open/close the CD trays of computers all over the school.
They ended up tracing it back to me (windows user permissions/ownership, probably) and I was promptly banned from computers at school through the end of the year and for most of the next.
Also, I quite like the cat-and-mouse analogy you mention, because I feel it was (mostly) a harmless way to hone skills, to level up knowledge essentially, with a (at the time) reasonable amount of risk involved, which kept it exciting enough to learn more. It would be cool to see schools have a bug-bounty type of environment here or there, just for those few kids who actually want to spend their time on getting better at networking.
Cant say my school had anything of the sort (they'd prefer to punish and force you back in line with other students) and while I like the idea, I know that in HS it'd feel too akin to snitching on my classmates to participate in that.
If you left the floppy disk in, I took over the boot-process and displayed "Uploading Virus" in a loop. Which of course, didn't do anything.
A few weeks later, all the floppy-drives were removed from the library's computers, lol
Don't tell, but I knew how to pop into windows and play games, and the machines were networked so I had everybody's classwork sitting right there. They can't catch you cheating when the assignment is to copy the same damned text. Teach lost me on day 1 when I did 65wpm on the 5wpm test, all like "no, you can't skip ahead, you've demonstrated can type at 5wpm, now you need to take the 10wpm test"
But then they taught us how to use macros in a word processor. I don't know how or why, but the computers had a shared namespace for these macros. We were only supposed to use them, but I figured out how to make and edit them. Told a friend about it. The friend promptly changed the macro the class was meant to use. With recursion. And that was Trouble. Who gets the blame? Kid with their name on all the autoexec.bat files, that's who.
Shortly after I got back from suspension, I talked to the IT guy, and became his unofficial TA, and fixed computers during that class period.
They were saved in the "normal" document template, probably, I guess shared to the network drive. My first tech job was interning with an insurance company which had some important VBA script saved in the template. I want to be charitable, but it was almost certainly out of cluelessness... the macro even included a check to only do anything when run from a specific document, so it's not like it was meant to run from every document.
Of course I didn't realize this and it bit me when I dutifully made a copy of the document before editing the macro... only to break something in "production" (or what passed for it...) and get yelled at for it.
Tangentially, not too long thereafter I replaced most of my job (and that of half my six-person team) with a short M4 macro (secretly, of course). Freed up many hours during the workday to work on my Perl chops and figure out how to get one of those sweet "GMail" invitations.
I found myself sitting in the vice principals office, as a kid, all alone with his password under his keyboard. I thought long and hard about going to the local library, dialing up to the school network (modem days) and changing a bunch of grades of students to improve my GPA. That reason you called out is the only reason I did not. All eyes would be on me.
So I resorted to just mild pranks
- took a virus from my library and submitted it with homework
- found someone trying to install sub seven on my girlfriends computer. I reverse subseven’d him and socially engineered him to give me his address. Used mapquest and showed up at his house
- made a fake virus that pretended to run format c: on my moms computer. My mom had the principals office call me out of class in 6th grade. I remember laughing my ass off that I got called out of class for that prank
- in college I wrote a program that would split up audio files into variable lengths up to 1 second and send them to a list of servers (sun ultra 60s) then run auplay to play the audio of the files out of the speaker. The controller would keep track of which system had which part and would plAy the audio in sequence across the various systems. The sun servers were lab computers with users on the console. Imagine their surprise when Mega TeamFortress sounds start playing in surround sound out of all of the systems around them.
- scotch tape over the very end of Ethernet cables on desktops (fun!)
- vb or c# program that “jiggles” the mouse pointer. I made a coworker throw out three mice because of it
- redirecting a coworkers network drop to a spare Linux computer in my office running tc introducing random latency
- control-alt-down on windows computers
- random times in cronjobs that runs shutdown or randomly kill shell process on unix boxes/accounts that were left unlocked
There’s probably more, but whew I haven’t pulled a prank in over a decade!
One of the demo sounds shipped with SunOS was a little metallic "ding" which, if repeated fast enough, would sound just like a cooling fan with a loose bearing. When my co-worker across the way complained about a noise from his machine I told him to hit it on the side; he did, and of course the sound "stopped".
Might have been several days later when I got busted from laughing when hitting his workstation as hard as he could didn't "fix" it anymore. I have no idea how that hard disk survived.
Back in high school, I thought it was hilarious to swap around the numerals on the keyboard. My two favorites were: moving 0 to the beginning of the number row and shifting the remaining keys over by 1, and swapping the numpad to telephone order with 1 at the top left. Much more logical layouts if you ask me. Alas I don't think I got too many people with that one because our logins included our graduation year...
Back in 7th grade I stumbled upon the "net send" command. So, bored in the back of class one day, I sent a few messages and saw them pop up simultaneously on all the computers. I thought it was pretty funny. I didn't sent anything vulgar. Just something like, "yo", and "it's Evan" (yes, I put my name).
Well, turns out I sent those messages to every computer in the district. Three elementary schools, one middle school, one high school, and the administration building.
Maybe 10m later someone from the IT team came and asked who had computer #XX. Obviously was me. Principal claimed I hacked into all the computers and said he'd call me back in for an appropriate punishment.
Nothing ever amounted to it. Never got called back in so I had no repercussions.
One of the team leads was trying to figure it out, and sent a message to her group saying, 'if you can read this, please raise your hand.'
Of course, she got it wrong, and sent the message out to the whole corporation. No safeguards against that, at the time.
Nothing bad happened, other than severe embarrassment. But I still smile at the thought of the marketing department setting in their offices, hands raised, wondering if it was safe to lower them yet...
And I had even managed to figure out how to target it at specific logged-in users!
> "it's Evan" (yes, I put my name)
I just sent 'test' and I think it shows IP or computer name, but it didn't really matter, I had to confess when they asked the class who did it.
'net' has so much stuff crammed into it though, it's unbelievable. Feels like a skeleton key that just barely follows rules.
I got suspended for a week and banned from the computer room for a year.
I (in Australia) had to contact my brother (in Germany) urgently one day. So I 'rwall'd the machine that I knew he used most often. To great success.
Instead, I did target each keyboard's keys which - when being pressed - would play a sound using internal speakers. Deployed it on all devices in the room and once class started, we had a lovely concert going on.
Got kicked out of the room immediately.
Ah, and netsend was fun also :D
I thought better and that I could automate this task by writing a small background task in VB (4 or 6, I can't remember which year/version) which would listen for commands on UDP.
One such command would initiate an immediate shutdown. Without prompting the user to save open documents.
Only once I issued that command to the entire lab.
I didn't take long for everyone to find out who did it since my own machine was still logged in and working.
The next day I removed the process from the machines lest I get myself in any real trouble.
- someone was a bully. He talked about nfs 2. Sub7 him and deleted his saved games of it( a website catched his IP in logs, also msn could see the ip connected during a file transfer at the time - unrelated). I laughed silently, when he complained at school.
- distributed the twilight and crazy bytes CD/dvds at school. They compression was amazing! ( I know it deleted assets too)
My desktop contained 3 cd writers to burn things. Later on 3 dvd-writers.
- Didn't fiddle with hardware too much. But i remember doing modem bonding for double speed. I quickly stopped because my parents found out ( 2 phone lines occupied) and because of the high price... 5,6 kb. * 2 felt insane. It was a normal model though and seems a bit weird, telling it. Did anyone do this too? ( Don't remember it very well)
- chat logs of msn were amazingly simple and nice at the time! Xml with dtd. I still use it for a lot of things for templating client data and even generating html from it. Most useful thing from then, that i still use.
So I used it to have a look around and change the startup message to insult a friend. Then I told him how...and he told everybody. Next day all of the machines had obscene messages, and someone was caught doing it, they said my friend told them, and he told them that I told him. Thanks buddy.
I remember being terrified as I told the deputy head how I 'cracked the code', but I think I just got a detention.
They promptly removed the Novell software from the start menu, but left the app installed. Some friends and I knew how to find it still and could still message each other during class.
I told a friend how I did it - of course he had to tell the others in class.. so the war began and everybody shut down their neighbors PCs!
We then invented "defense scripts" in batch, which basically ran `shutdown /a` in an infinite loop to cancel any shutdown requests.
In the end, the administrator disabled the shutdown command - the official reason was potential harm we could do concerning A-levels.
Good times.
Sometime in my senior year, I read that there was a PJL command that could set the ready message on networked HP printers.
Naturally, I wrote a script that walked the entire /16 and would attempt to set the ready text to "Low Toner". My girlfriend convinced me not to run it, so I changed it to "Low Mayonnaise" and ran that instead.
For the next few weeks, seeing "Low Mayonnaise" on printers was a pretty common sight. It disappeared on its own as printers were reset, or error conditions triggered, but it did feel pretty satisfying.
I figured out that if you removed the floppy before you tried to log in, it would assume you were setting it up for the first time. Then you enter in a new password, put the floppy back in, and hit enter. It overwrote the admin password and poof. “Hacked”. She was not happy. I wish I could remember more details but as you can relate it was a long time ago :)
I never did it at school but there was always the "fake prompt" trick. Do a few fun things -- throw up fake syntax errors (including transposing characters the user typed correctly) -- print out some rude error message or "formatting drive..." -- and then silently hand control back to the real shell.
I burned some CDs with an autorun executable written in VB6 that would play a certain Rick Astley number at maximum volume until the user logged off. Left them lying around with various enticing labels. The result was as predicted. Unfortunately, as in your case, I failed to realize that the list of students likely to do such a thing was a very short one indeed.
Later on in my school clown career, I reconfigured the printers to add a giant “CONFIDENTIAL” watermark across every page. This was the day before an important coursework deadline. That one did not go as planned: clients that had cached the malicious settings kept sending them back to the print server, and it couldn’t be fixed until everyone went home for the day.
It's still possible, I did that a couple months back while making Cyberpunk 2077 hacking mini-game autosolver
Interestingly, all of these computers were wired to a LAN. It didn't take long for me to install a proxy server on one of the library machines, allowing me and my friends to use the internet in the computer classrooms.
At some point the system administrator (who was also a German teacher) saw us browsing the web. Instead of getting mad, he just laughed and offer to pay me a bit of money to properly set this up for everybody.
Good times!
Well someone else discovered it and did a bunch of damage to a bunch of machines and got into trouble, but I got off clean as a whistle. Sticking to gray hat kept me outta trouble.
Of course they called me out of all the students and basically just told me "we don't care who did it, just remove it".
Another time someone downloaded pr0n on their account and pretended someone framed him; I was then confronted by the school bullies on why would I do such a thing.
I hate when people use meta game to find suspects
net send * "i know where you live"
on my school's network. If anything, I did them a favor. They didn't see it that way though.Not entirely unlike this April morning in 2021.
It's hiding your cursor while it's over the site, rendering an <img> of a mouse cursor at its location, and then moving that around a) when you move your real cursor, and b) with random perturbations
Note to the author: the illusion would be even better if you used the user-agent to render a system-accurate mouse cursor ;) (on macOS the real cursor is black and the fake one is white)
I've already seen sites that change the cursor's appearance, so I wasn't particularly "shocked" by that (I'm on a Mac).
However, what should improve the illusion would be to not move the cursor outside of the view area.
https://mdn.github.io/dom-examples/pointer-lock/
It's a bit odd to me that it doesn't ask for any kind of permission on Chrome, just that a user click initiates it. It does briefly pop a hint that "<esc>" will release the mouse.
You're right, it would make the illusion better. I developed this on Ubuntu where the default cursor is black, and I did consider doing this. Eventually decided to just use the default white cursor from Windows because it has better contrast on the dark color scheme. I guess I could set up 3 different color schemes for 3 different cursors for Mac, Linux, Windows, but it may be a bit too much work. I think most people who notice the cursor is different will just think "oh, this website uses a custom cursor", they won't necessarily realize that it's just an image.
I think you could make these changes, but I think that's if you want to have fun doing it. The diminishing returns are tiny and the gag lands well.
With the Pointer Lock API, you can actually take the user's cursor https://developer.mozilla.org/en-US/docs/Web/API/Pointer_Loc... (but the browser will show a notice).
Place button A the user wants to interact with at position (X,Y), place iframe button B at position (X+W,Y), with as little a border as possible with the rest of the page, then offset fake cursor by -W. User will try to mouse over button A, mistakenly mouse over button B, and click it in the time it takes to register that the mouse pointer just jumped from the edge of one button to the edge of the other...
[1] Though I can see the trick below maybe working for some browser's permission request "tooltip" UIs...
Also, kind of obvious given I use a gtk+3 dark theme and the mouse they use is white.
With the genuine browser security concerns that do exist out there (and the often-exaggerated narrative around the degree of the problem), it's worth being explicit that this is not actually a real one
I had assumed there would simply be Javascript calls for this. — how is it a problem that this be possible? that it can make one click on links that can be activated with Javascript on their own already?
Of course it could move one's cursor outside of it's own rendered page that would be problematic, but this trick cannot simulate that either.
And even if there is no a.p.i., when a website does it via some creative hack then one can assume the hack is most likely to work inside it's own window only.
And finally, how would the average layman no there is no such a.p.i.? even the expert could not be sure it wasn't added yesterday.
I really cannot see why the first response would be to panic and think the website somehow found a way to tell the web browser to make X11 calls to move the cursor, which is quite unlikely; the first response would be that there is an a.p.i. to move the cursor inside of it's own window, which is harmless, and after that that there is a creative hack to simulate it, and again, it's very easy to verify whether the cursor can be moved by the website once it leaves the browser window, and it cannot.
What the site almost certainly does is hide the real cursor and display a "ghost" cursor that it then can move arbitrarily. Once you approach the edge of the site, the illusion breaks down, because your cursor will reappear when the real, not the fake, cursor leaves the site.
It was a bit more obvious for me because my default cursor looks different from the graphic the site uses for their "ghost".
With a user gesture (which the click on the button would be), the site can also take a pointer lock: https://mdn.github.io/dom-examples/pointer-lock/ (but this shows a browser-controlled "this site is controlling your pointer" message).
[1]: https://developer.mozilla.org/en-US/docs/Web/API/window/requ...
Via: https://news.ycombinator.com/item?id=14124285 (2017)
document.onmousemove = console.log
No console logs until I really move the mouse.
Then I opened Chrome DevTools and checked what resources are loaded on the network tab, once I saw this, I figured the trick:
https://www.attejuvonen.fi/mouse/arrow_m.png
Since I'm on Ubuntu like the author, the moust indeed seems like my original one. This is a fun one :)
e: The JavaScript can be found on the <head> section of the page btw
oh that's a marvelous bit of trolling
I've tried on Safari 14.0.3 / Mac OS 11.2.3 and while the cursor does appear to move, its actual position, as determined by what happens when I actually move it, doesn't seem to change.
For example, if I manually move the cursor almost to the top of the page, but not quite, it will move around. Sometimes it disappears "under" the fixed part of the browser. But if I attempt to move it manually, the cursor "teleports" to where I initially left it.
Thanks for reporting this. The behavior around the edges should be improved now.
no-scripting: * true
* * 3p-frame block
* * 3p-script block[edit] revised the rules above, the no-scripting: * true was blocking it. Disabling uBlock for the domain allowed it to work.