0x0: Share Files from Terminal
0x0.st
0x0.st
They were friendly and I was never in cause myself, but I don't want to enable this kind of thing, or to have to deal with moderating content, even passively.
I'm happy other people provide such services, but just be aware they will inevitably be used for activities you probably don't want to facilitate.
This is a given (or at least I thought it was the usual) for many years now. Your only hope is that your service is too obtuse for the creeps/deviants to really grapple onto. Although considering how they are getting younger and younger (the perpetrators) even that is little condolence.
I've found myself in similar situations as yours, however now I just use other people's crap. I'm not willing to answer the phone like I was then; so yeah. It's a problem
a) unreliable (e.g. having opening hours a.k.a. intentional downtimes)
b) applying client side encryption a la https://privatebin.info
c) expire & purge the (encrypted) content quickly
would have mitigated your problem.
Could crib notes from olden days and have a public/ subdirectory where files you drop in there are available read only to the public internet via separate endpoint.
Can also have a blind drop box that does the other direction (but does not allow the public to read).
That way you are read / write from all your devices, can publish to anyone, and can let anyone share things to you, you just don't facilitate anyone sharing to anyone.
People distributing unmentionable content or using services for otherwise nefarious purposes are used to dealing with intermittent issues like that. It'll get rid of some but not all of them.
> b) applying client side encryption a la https://privatebin.info
> c) expire & purge the (encrypted) content quickly
If your site turns out to be being used by a group that is raided, this will not stop your services being confiscated and very thoroughly investigated. You might be legally in the clear, but it may cost you time and hassle (and potentially money if you need to take on the services of a lawyer to help prove you did not intentionally aid/abet).
Also an end-to-end encrypted solution like that might be rather attractive to users both illegal and otherwise, so be ready for a huge bandwidth bill if/when a sizable group latches onto it!
usually there's always one solution to get rid of all but that's prbly not what you think of.
So getting rid of some is what it's about, isn't it? And some more by another means.
Like, if the service provided just encrypted blobs + a piece of JS to decode them (with say URL containing the password), would you be in the clear or the police/law would just go "see I click the url that leads to your site and get the Bad Stuff, it's on you"
I mean the police aren't going to say oopsies based on your argument no matter how logical it sounds. They are there to serve the warrant.
In fact, as a host (as opposed to an actual producer of illegal content) taking such steps to evade law would probably be rather counterproductive, compared to simply cooperating with law enforcement, since it would be difficult to claim acting in good faith.
And that's if you are content with simply hosting child porn until the police tells you you are.
And in some jurisdictions you may be guilty of a lesser crime just be inadvertently aiding/abetting. The current UK government keeps trying to push through legislation that is a little scary in that respect.
Alternatively, you can check out magic wormhole (for a more secure transfer of files between two terminals): https://magic-wormhole.readthedocs.io/en/latest/welcome.html...
There are sone public instances too:
I have found two different options worth sharing: https://github.com/orhun/rustypaste (very lean and minimal) and https://github.com/9001/copyparty (someone's pet megaproject with features from WebDAV to a tracker music player).
There is also https://chunk.io/ in the https://transfer.sh category. It requires free registration by emailing the owner. It has some interesting features, like uploading multiple files in one HTTP request and syntax highlighting for source code. Files are associated with your account, so you can delete them without a per-file token and list them.
https://github.com/schollz/croc is like Magic Wormhole but can send multiple files and resume transfers. It is written in Go. It releases official static binaries, including for Free/Net/OpenBSD. (Magic Wormhole has alternative implementations with static binaries: https://github.com/psanford/wormhole-william, https://github.com/magic-wormhole/magic-wormhole.rs.)
python -m http.server 8000
Then I do a quick look at my IP and pass it. If we're not on the same network, then I quickly create on with lnxrouter: https://github.com/garywill/linux-routerThe next weak point is the centralization around the tracker. You can solve this by sharing all the tracker information on Nostr [2], maybe?
ipfs add file_name
share the hash with whoever
and they run
ipfs get hash
It is a really elegant and ergonomic way to transfer files between computers. It doesn't need any preparatory setup like launching a "server", as with ssh or http. A single, short command line on each computer, and the file is copied.
The only pre-requisite is that both computers are actually connected to the internet. Unfortunately, NAT and other shit broke the internet so this is a difficult pre-requisite to fulfill nowadays. A sad tragedy of our times.
It still often works to transfer files directly between computers in the same lab.
dest$ nc -l > file
src$ nc $IP_DEST < file
On some installs of netcat you'll need to specify a port because they don't have a default one (typically 31337). Look at the manpage to see what is the case for yours.Listener:
nc -l 19000|bzip2 -d|dd bs=16M of=/dev/sdb
Sender:
dd bs=16M if=/dev/sda|bzip2 -c|nc serverB.example.net 19000https://www.ndchost.com/wiki/server-administration/netcat-ov...
Whats the incentive for these sites? How do they stay operational?
> How do they stay operational?
By not growing too large (so costs don't explode) and the owner not minding to pay a bit to run it. Which usually means that they don't stay operational long-term-ish, or introduce stricter and stricter limits.
Image hosting sites are something where one could observe this very well over the years: an image hosting site launches and is fast and simple, operator offers generous service for free. Lots of people start using it. Bandwidth costs explode. Site adds advertising, cuts down on hotlinking, strictly limits free tiers ... to make some money back. Users get annoyed. Among them is a techy who thinks: "I can pay for a server or two, I'll launch a better image hosting site, without all the ads!". Such repeats the cycle of life (of image hosting sites)
Scale really hurts here - many people can easily run a service that doesn't have too many users (or many users that don't create much load) for years, but scale quickly pushes it out the side-hobby-thing budget.
Intelligence gathering operation?
There is no "fhost.c" in the repo, though there is an fhost.py. https://git.0x0.st/mia/0x0
Ah, I see. If I go back to an old version of fhost.py, the error you're seeing is just a big hardcoded string. So there is a deliberate handler, made to look like a crash. Strange.
def notfound(e):
return u"""<pre>Process {0} stopped
* thread #1: tid = {0}, {1:#018x}, name = '{2}'
frame #0:
Process {0} stopped
* thread #8: tid = {0}, {3:#018x}
fhost`get(path='{4}') + 27 at fhost.c:139, name = 'fhost/responder', stop reason = inv...
https://github.com/mia-0/0x0/blob/714de58180072a5563ae1f3d96...Quite interesting.
{% set pid = range(20,100)|random %}
<pre>Process {{ pid }} stopped