I may be the only evil (bit) user on the internet (2015)
blog.benjojo.co.uk
blog.benjojo.co.uk
I wrote and tested the script under OS X and it worked fine. I then moved it to my Linux server on the same network and it couldn't connect to Verizon's web site.
After using tcpdump to figure out what the difference was, I noticed that Linux was setting the ECN bit. Verizon had a firewall in front of their site that was apparently dropping packets with the ECN bit set. ECN was only a couple years old at that point. I think I figured out that it was due to an out-of-date Cisco PIX firewall on the Verizon end, but I'm not sure how I would have figured that out.
The solution was to disable ECN on the Linux box.
https://en.wikipedia.org/wiki/Explicit_Congestion_Notificati...
I've only seen one-way (email-to-SMS); is there a way to do the reverse, too?
Just put an email address instead of a phone number.
Go ahead and try it out.
My man added a sockopt, ping(8) option, documented all these changes in the manual pages, and added some fun sysctls related to the functionality.
I played this on myself by setting X-Forwarded-For: '" which would trigger an sql error if someone assumes an IP address is safe to insert without escaping or parameterization. Very few sites broke, but the first one that did I remember sold TLS certificates.
https://www.theregister.com/2022/02/15/missouri_html_hacking...
If someone wants to take some random anecdote from some random guy on the internet as legal advice that isn’t really my fault or problem - I’m not prefacing everything I write with an arguably useless disclaimer to account for such an absurd scenario.
1. So if someone tells you they are a lawyer and then proceeds to tell you to do something illegal, they might be liable.
2. Some with engineers. If somebody tells you they make living wiring mains in houses and then proceeds to tell you to remove cover from a power supply and tweak it, they might be liable if you get shocked or your house burns down.
But I am not a lawyer.
For example, in Czech civil code there is something along the lines of:
> Section 5
> (1) Any person who publicly or in communication with another person presents themselves as a member of a certain profession or status, thereby indicating their ability to act with the knowledge and diligence associated with their profession or status, shall be held accountable if they act without the requisite professional care.
So then every comment ever made that wasn’t intentional trolling and fiction then. Must be a backlogged court system with all those cases of someone being held liable for the perception of another. How does one prove they perceived something as advice? Wouldn’t it be easy to throw out short of the comment literally saying, “my advice would be”.
> It is hard for a TCP packet to discern higher moral quandaries like the meaning of life or what exactly defines 'evil' and from whose perspective such a characterization is being made. However, developers of TCP-based applications MAY choose to see some activities as evil when viewed through their particular lens of the world. At that point, they SHOULD mark packets as evil.
1) add the check IP on the site to NFQUEUE
iptables -A OUTPUT -p tcp -d 185.230.223.37 -j NFQUEUE --queue-num 1
2) write a little python script using [0] netfilterqueue and [1] scapy from scapy.all import IP, TCP
from netfilterqueue import NetfilterQueue
# Callback function for handling packets in the NFQUEUE
def packet_callback(packet):
pkt = IP(packet.get_payload())
# Modify only outgoing TCP packets to the target IP
if pkt.haslayer(TCP) and pkt[TCP].dport == 3560 and pkt[TCP].dport == 3561:
# Set the reserved bit to 1
# 6 ist DN und evil
# 2 ist DN
# 4 is evil
pkt.flags |= 4
del pkt[IP].chksum
del pkt[TCP].chksum
pkt.show2()
pkt.show()
# Print a message indicating packet modification
print("Modified packet:", pkt.summary())
# Update the packet payload
packet.set_payload(bytes(pkt))
# Accept the modified packet
packet.accept()
# Set up the NFQUEUE handler
nfqueue = NetfilterQueue()
nfqueue.bind(1, packet_callback)
try:
# Run the main loop
nfqueue.run()
except KeyboardInterrupt:
# Cleanup on keyboard interrupt
nfqueue.unbind()
3) analyze your packages with wireshark and find that your script works!4) be sad because the response never arrives and your packages are treated as if they hadn't set the evil flag :(
EDIT: YES! I didn't see that he does 2 checks and the second uses a different port. NOW I'M EVIL!
Am I evil? I am man, yes I am...
The evil bit could be something of a self-fulfilling prophecy. Because no one uses it, that makes it a source of bugs/vulnerabilities; therefore, anyone setting it deliberately but not maliciously (such as for a joke) will want to turn it off; only those who want to exploit it maliciously will keep it turned on; hence, anything with an evil bit can be safely assumed to be, in fact, evil, and it should be filtered out automatically.
> Devices such as firewalls MUST drop all inbound packets that have the evil bit set.
> Packets with the evil bit off MUST NOT be dropped.
That seems to be at odds with standard firewall operation, that may choose to drop packets because of all sorts of reasons unrelated to the "Evil bit". This would seem to constrain their operations unnecessarily, and so I would say that it is in the best interest of security vendors to ignore most of this RFC as frivolous and not binding.
Otherwise, we're back to square 1, where you don't know what caused your packets to be dropped even though they are clearly and explicitly not evil!
Heck, from https://datatracker.ietf.org/doc/html/rfc5841
Some organizations are prohibited from using this mood by mission
statement. This would also prohibit using the security flag in the
IP header described in [RFC3514] for the same reasons.
I mean, that was obviously talking about GoogleI may be the only evil bit user on the internet - https://news.ycombinator.com/item?id=10632856 - Nov 2015 (36 comments)
(Reposts are fine after a year or so and links to past threads are just to satisfy extra curious readers!)
I ask as I ended up searching for this article earlier today and thought about resubmitting (but ended up not doing so). It just seems a strange coincidence, unless there's something we both saw that made us think 'evil bit'!
I've also had similar déjà vu moments where something I had only just read about would be submitted to HN.
I think I've also seen the inverse happen, where you see a post about some phenomena on HN and only a few days later some science/IT YouTuber covers the same thing. In those instances I do wonder if that YouTuber was reading HN and thought to make a video about it, or if the HN submitter and the YouTuber had both had their brains tickled by some other source (eg. a podcast).
Sometimes you'll even see things come full circle where that YouTube video itself is then submitted to HN.
> it’s not even recognized by Wireshark and other systems...It’s even harder to look for these kind of packet in tools like tcpdump...In FreeBSD someone actually did the work and made it a option for your IP stack link however the patch was only in FreeBSD for around 24 hours before being reverted link
Basically this provides a literally covert channel through which you can undetectably smuggle data between cooperating hosts. Lovely!
Because I heard they were just a bunch of
Exercise to be left to the viewer.
[1] https://twitter.com/FallGuysGame/status/1305486780851007489