Using Goatse to Stop App Theft
joshcsimmons.com
joshcsimmons.com
Eventually the bandwidth was getting hammered by a huge number of leechers seemingly from some apps that had simply hard-linked to the resources.
After replacing said resources [0] they soon ceased but not without a slew of abusive and entitled emails demanding I restore the SFX.
Oh fun times!
[0] https://fukpig.bandcamp.com/track/all-of-you-are-cunts-and-i...
What an entitled bunch
So many downloads.
I'm downright shocked that this wasn't Rick Astley.
Or so he says, it may have been mostly copycats after a time.
Edit: It was a picture of a flower. I replied with some links.
Though if shall own any blame it's for being naive and inexperienced in the days before we all needed rate limiting against corporate bots.
As it goes, the whole shebang got archived on Wayback/Internet Archive so all the goodies remain up there for people to enjoy and I stopped needing to run a box and deal with misuse. God bless the Internet Archive I guess.
It's fairly surprising to see that approach from pretty large brands/companies. Some Indian ISPs are kinda notorious in that they'll just link to huge image files on third-party sites and just let their 300 million customers hammer the poor site into the ground. I guess it saves them bandwidth, but they also run a huge risk of pissing someone off and have that asset replaced by something nasty. When people use this kind of hard-linking/hot-linking of resource I don't think they do it to save money or to be evil, I think it mostly gross incompetence.
We had an issue where our product images would just be ruthlessly scraped, if there had been some rate-limiting in place we'd most likely just have allowed it or not noticed. Normally I just pointed the poor scraper to a multi-gigabyte file or funny and unrelated image, if you want to download the same image of a beaver 25.000 times go ahead.
But I also seen amateurishly search engines just pound a site to the point where it was easier to just deny all traffic coming from their crawler, as compared to try to reach out and figure something out. Say what you will about Google and Bing, their crawlers are well written and well behaved.
But Netflix was running at full HD with no problem. So they must have had local cache's with the ISPs.
source: I used to work at Akamai (it was a while ago). The myriad things they do with their edge servers is pretty amazing, but for simple CDN stuff, most of the time clients aren't shipping hardware to isps. That being said, if Netflix can convince an isp to pay its electricity and hardware maintenance costs for a popular isp's customers that's going to pay for itself very quickly. So, i can see why Netflix offers this. It's just not normal AFAIK.
And it's much harder now to have a caching server because everything is HTTPS, so you have to coordinate with both ends to make it work.
Given that Eternal September remains a thing to this day, I wonder if that remains the case?
As for Google Bot being well behaved - I'm glad to hear that this has changed because at the turn of the century (which is the last time I dipped my toe in to self hosting) it certainly wasn't well behaved in the slightest and it would ruthlessly crawl away, happily ignoring any robots.txt limitations applied.
Yes, I know it's also given us CDNs and Single Sign-On, but there are ways to implement SSO as a more active action without that, and I'm not convinced that CDNs are worth the cost we paid.
So I threw up a little 'surprise' for the ahem penetration testers ahem, if you feel brave: https://www.thran.uk/wp-login.php
There are moments I'm about to deploy something similar and by now what's stopping me are laziness and other higher priorities. I'm staring at these aggravating items in server log and maybe someday.
We slyly added referrer-based logic which would, with 1/20 probability, serve the Goatse.cx image instead.
Needless to say, within 48hrs we never received another deep link request from that competitor.
[0] - https://xkcd.com/1053/
edit: folks the xkcd lucky 10k reference was a joke, settle down
I've never understood that attitude.
That's not a large improvement.
But it was kind of a rickroll situation... yeah it sucks
Wasn’t it more like 3 hours to setup and get the network functioning, and hour of gaming?
Or goto a hosted one
e.g. NSFW https://goatkcd.com/1053/
If you don't know what that is, you might not want to search it.
And the normal game shows up in the iframe if you have looked at the real game before, and have data in your localStorage. I assume to not arouse suspicion from people ripping off the game.
I disabled tracking protection, and deleted localstorage on the real site. Then it showed up.
I've had teachers and students reach out to me to say they play my game in class every day together. And parents who play with their kids every day, and adult who text their results to each other every day.
It sucks if they end up doing it on an ad-ridden site when I built an experience that asks nothing of them. But it would suck even more to goatse them.
You can't protect your kids from the internet, you can only warn and educate them. I'm not saying to give them unlimited access from the get go, of course not. But I'm just saying you can't stop them either.
Look, RJ Reynolds was perfectly within their rights to market cigarettes to young children, and shops were within their rights to sell to young children. It’s not their job to parent children.
And if I want to open up a strip club across the street from the neighborhood public school, why should I be prevented by zoning laws? It’s not my responsibility to parent someone else's kids.
I want to emphasise, again, that we're talking about clicking on a word game here.
I'd guess the author is pretty young.
Definitely childish though.
It’s bad for their image and so for any business they may work on now or in the future.
It's very crude, but satire often is and is one effective way of driving change in society around us.
It sent me to a 1998 page about phrenology, the 'science' of determining someone's mental traits based on indentations in their skull: https://www.phrenology.org/index.html
I happen to run a directory of 'escapist/artistic' websites, if a second instance of self-promotion is permissible: https://wmw.thran.uk
I'd guess you're pretty old.
My sympathies are entirely on the side of the game's author. It's just an obscene image -- the "collateral damage" in this case is perfectly acceptable and imo fair because it damages the brands of the illegal hosters.
However as a gay nerd I'm not really interested in having children, so I'll just have to leave it up to the village.
I think you'd probably agree that, say, overwriting every file on the end user's computer with a text file complaining about how the iframe-wielding website steals content would be an unacceptable thing for the author to do. But the only difference would be the degree of suffering inflicted on the innocent bystander.
If you think this image is acceptable to show to young kids, are there any images you think are unacceptable to show them?
Also the phrase "you think this image is acceptable to show to young kids" subtly alters my position in a disingenuous and (I think) intentional way. My position is not that you should "show young kids goatse" but that "a young kid seeing a flash of goatse isn't really a big deal". They might laugh, they might be a little grossed out, they might be curious why someone would do something so strange. I think the idea that they would be "harmed" or "traumatized" is pure adult projection.
I think there is a genuine change in meaning, coming from your use of the word "should":
>My position is not that you should "show young kids goatse
But that's not a word I used (or intended).
ETA: Agree on images of violence.
A very annoying, loud, visually busy animation would've sufficed. Baby shark at maximum volume, or a continuous fart sound, or maybe just a high pitched beep would also sufficiently scare away people.
By showing porn in a place that he knows minors and other protected groups will visit, they violate decency laws in a whole bunch of countries. They probably wouldn't if this was accidental (i.e. they sold their domain to a third party that turned it into a porn site) but in this case they admit this was very much intentional.
For example a woman breast-feeding or a man peeing on a tree on the side of the road.
They may have had a defence if this hotlink prevention was already there from the beginning, but this post explicitly admits that this was added intentionally in response, and that there were plenty of other options that could've been taken.
When it comes to many laws, intent matters a lot. You can make technical arguments about the nature of all networking all you want ("technically HTTP is a request/response system so if I just requested the server to delete all customer data I didn't hack it the system just foolishly accepted my request") but the real world doesn't really care about CORS and iframe policies as it does about not being exposed to some guys erect penis and stretched out anus.
The most frustrating thing for me is fucking Google. Their search results are so bad these days I can't get my game to the top even though thousands play it every day and link to it on social media. I'm at the top of Bing, DDG, Kagi. These sites run links to each other and Google's dumb algo loves it. Usually they don't use iFrame but proxy the whole request. Since using CloudFlare as my CDN a few of the app thieves have been defeated.
Some of the sites that host their own cached copy even go out of the way to remove the credits and contact info from the page.
For instance, the UK has a cyberflashing law which allots a two year custodial sentence for sending a graphic image (by any means) with intent to cause distress.
He's the one specifically replacing one thing with another under some circumstance. Not the person embedding it or the one hosting the image.
https://www.jdspicer.co.uk/site/blog/crime-fraud/uk-indecent...
Then again, I doubt someone is going to file a police report, especially when the URL of the page would bring the reports to an entirely different web page in the first place.
Ultimately it depends on what he's charged with and if it's found they can be extradited for it...
If you want a good preview of what trying to enforce UK law on US citizens looks like look no further than the New York Libel Terrorism Protection Act later passed federally as the "Speech Act" preventing US courts from enforcing British Libel judgements referring to you lot colloquially as "Libel Terrorists"
https://www.npr.org/sections/parallels/2015/03/21/394273902/...
Insofar as action purely in the UK well Europe is 10M sq miles the US 3.8M whereas the UK is a 94,000 sq mile island on the way to nothing else.
If they want to commit at minimum thousands of dollars in resources they can at great expense reduce by 1 the potential tourists spending money on their island I suppose.
It's the reference example for what a "shock image" is. How in the blazes is the choice of that particular image over practically anything else based on anything but its capacity at causing distress?
The blog post both acknowledges it as such, and even says "Let this be a lesson to you", making it clear that its use is specifically meant to be go beyond stopping people and actively punish them. And even if it weren't for that straight up confession, it'd STILL be patently obvious that this is what they are doing. We are in clear-cut "shotgun booby trap" territory here. As others have pointed out, there are subtleties at play over who is ultimately responsible, but the author's intent to cause distress is not in question in any way shape or form.
As much as it's fun to see vigilante retribution like this (and boy is it!), that does not discount the obvious legal exposure at play.
I think goatse (I arrived on the internet in 1992 or so, so yes, I’m familiar with bothe the giver and the receiver) is somewhat conservative, actually, given the full realm of possibilities. I would be prepared to argue that to a jury in the right jurisdiction. I could convince twelve people who don’t care in New Jersey but probably not Mississippi.
I’d be very surprised if any prosecutor thought they’d have a substantial likelihood of a conviction. There is a very high probability that this immature outburst would not be prosecuted or that it would plead to something like disturbing the peace if anything at all.
Goatse is the internet’s way of saying “you don’t really want to look at this.” Hell, your parenthetical says as much.
It would have to start with an extraordinary effort by the UK to invest millions in getting a fellow and then the other nation being willing to set a terrible precedent to get the uk to fuck off.
Given the relative utility it would be easier to cut off the entire UK
That's not to say that Goatse wasn't the correct option in this case.
Fun fact: UK law exists only to make sure that every person in the UK is guilty of something by the time they reach adulthood. It serves no other purpose.
as there is no cyberflashing on the source website, when you go to verify
that how it ought to be, dunno uk law
It’s not worth worrying about such extreme what-if cases. If the Feds were so determined to destroy an innocent person in a kangaroo court, there’s easier ways of doing so. They could plant CSAM on the server. They could coerce an informant to accuse you of SA (like they did to Assange).
Realistically, the worst sanction this dev could reasonably expect, is to have their domain taken down. That’s what happened to the OG .cx domain, after all…
"To play Sqword, please visit <domain> directly. You are currently visiting a site that has put ads around the original game without the game creator's consent."
By replacing it with goatse, a number of people will think, "I wanted to play Sqword but now it's pornographic" and never play again.
https://joshcsimmons.com/post/eJyVlD2PgzAMhvf8Cm8HlcD76dSlf8...
Created using
wget "https://gist.githubusercontent.com/snipe/5512408/raw/db9f4051eeb1079de436ec5ae9ba9aff2a99549c/gistfile1.txt"
python3
>>> base64.b64encode(zlib.compress(b"<pre>" + open('gistfile1.txt', 'rb').read())).replace(b'/',b'%2F')>Yesterday one of my collaborators googled "sqword" and to his surprise, there were tons of first-page results that weren't the sqword.com domain.
His approach is much awesomer than the nature thing.
It seems like that might reduce real users’ confusion as they try to find the real “sqword” puzzle.
I found out because my host emailed me saying I had hit my bandwidth quota for the month... 2 days into said month. So digging through logs I found the biggest offenders, there were forums where people linked just about every image I had.
A little htaccess magic later, any request that came from a non-allowist referer was instead served a rather crude message I quickly put together in MS paint.
No one contacted me about it, but it was amusing watching these threads where people were getting upset when they thought they were going to see funny owl pics.
My solution (safe for work, not harmful): https://wordstream.freeloader.wtf/
OP is not emailing people, but it is the same thing: revenge using explicit imagery. Except not only might the people behind the sites see the image but their visitors which probably include minors will too.
If you email them explicit imagery and they automatically forward it, that's on them.
Not a crime, but a little crass in a funny way.
The parasite has to answer for the material it shows its visitors.
If a butcher delivers outdated meat to nowhere, knowing his van will be hijacked, how can he possibly be blamed when the hijackers sell it to their customers?
Edited to correct can (van!)
An obvious corrolary to this is the prohibition on booby traps.
As I understand it, the iframe is set up such that the users browser loads your site inside the frame and the intermediate site outside of the frame. If you serve a file then you are serving it directly to the browser. The intermediate site never sees it?
* The people you're hurting with the goatse image are mostly not the people wrapping your game in an iframe, but rather the people playing games on the game aggregator sites. Probably includes many teenagers and children.
* The game aggregator sites are bringing your game to a wider audience. For gamers who don't know the name of a specific game they want to play, it's nice to be able to browse through a directory of games. The game aggregator sites aren't competing with you in terms of Google search results, they're adding your game to their collection and sharing their collection with everyone. Yes, they're supported by advertising, but I'd argue game aggregator sites are still generating a ton of consumer surplus. (For example, many users are blocking ads.)
If you still want to hurt the game aggregator sites for some reason, just include a message on the game loading screen that says "play without ads at sqword.com". Easy.
This is the equivalent of getting paid in exposure.
I'm not saying you're wrong. You're right, but at least it's for an interesting reason.
https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...
> Every post that I want to publicly claim authorship of lives at the root of this site. If you are reading a post that I have claimed it will look like this page. Posts of unknown authorship have a disclaimer at the top of the page.
https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...
(His permalinks are horrible, lol)
Problem is, the posts can contain <script> elements. So it's easy to just write a little JavaScript that removes the disclaimer at the top. See this hastily-made, immature example of mine:
https://joshcsimmons.com/post/H4sIABO8LmUC/3VT0W7aQBB85yu2QV...
As it stands, this really isn't the most secure system. Something much more malicious could be injected into this!
Either way, considering the submission we’re commenting on, the author of the blog may appreciate your humour.
The client-side XSS is mostly harmless (assuming you don't have any other sensitive services running with cookies scoped to this domain), although it's technically a persistent XSS, which means it could be indexed by search engines.
But is there a server-side component to this? I noticed that the "disclaimer" is added in the source returned by the server, so I assume there is some code that checks whether the post is present on the home page? If so, that could be dangerous, if there is a bug in that code such that a malicious payload in the URL could get RCE in your server process.
TBH I haven't thought about most of these things. Nobody typically reads my blogs when I've made them before and this is likely the only interest it will get for quite a while.
Can't promise I won't circumvent it when I've got some time...
If the wrong person publishes the wrong link, you can get your domain banned from Google and tons of other sites as a "security risk", which can spread to your email (if you use @joshcsimmons.com).
It's fine if you don't care about blacklists of course, but this kind of abuse can easily sneak up on you.
EDIT: understand you are not the OP btw, just wondering out loud.
It’s not a good use case IMO, but that is all I can think of lol
Doesn't need to release tools... gzip, base64 and uri encode uh huh.
https://joshcsimmons.com/post/eNpTVlaoKC5WSEnNzefisilOLsosKL...
(this just injects a <script> alert but.... that's bad)
just tried contacting the author via linkedin (since I don't see an email address on their site)
@joshcsimmons are you around?
> Every post that I want to publicly claim authorship of lives at the root of this site. If you are reading a post that I have claimed it will look like this page. Posts of unknown authorship have a disclaimer at the top of the page.
https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...
the second they start hosting any application/backend/cookie-enabled thing on this domain name, anyone could inject a script via their /post/ gzip-base64 scheme, and do bad things...?
I don't think html sanitization would go against the principle of this idea. just... at the very least strip the tags! :-)
Since the website is vulnerable to XSS, you could inject a script that removes the disclaimer.
base64 generates slashes, so the site (and I) run encodeURIComponent in the devtools on the resulting base64 to make sure it's completely url-safe.
---
the poc "payload" is
eNqzKU4uyiwosUvJTy7NTc0r0UtPLXHNSQUxi50qnXMSi4v9EnNTNdRzMtMzStQ1ow1i9YpSc%2FPLUjU0bfShmrm4lBVKMjKLFYAoKTEFACeDHYg%3D
which uri-component-decodes to:
eNqzKU4uyiwosUvJTy7NTc0r0UtPLXHNSQUxi50qnXMSi4v9EnNTNdRzMtMzStQ1ow1i9YpSc/PLUjU0bfShmrm4lBVKMjKLFYAoKTEFACeDHYg=
which un-base64+gzip's to (using the site I posted above):
<script>document.getElementsByClassName('light')[0].remove()</script>
# this is badIndeed, and it is well-represented here. In fact, I assumed we'd see some of it here and went looking for it. I was not disappointed. It means plenty of people missed the point entirely.
Those children over there… sending each other lemonparty (oh wait that was us)
Nah the kids now are watching cartel and Ukraine videos while going “bruh on god based uhuhuh”
While I was touring it, the smart home was hacked. And suddenly... goatse. In every room, on every surface, that same gaping orifice.
I woke up sure of one thing: Smart homes... not even once.
http://web.archive.org/web/20060113021154/http://aa419.org/v... (SFW)
LOL
@joshcsimmons it seems like sqword is reading local storage on this line:
this.localStorage = n.localStorage || globalThis.localStorage,
which leads to the following error: "Uncaught DOMException: Failed to read the 'localStorage' property from 'Window': Access is denied for this document."
you should do it in a try/catch.
But I guess it can happen on the original site if the user turns off cookies entirely.
OP you should follow this up by reporting all the said websites to google.
Ok, they could automate that, too. You'd need to checksum something from within. Where the problem arises: how to know the checksum before the code was fully minified.
I think there are companies, that specialized on tamper-proofing js-code with a lot of crazy tech, i lost some bookmarks for this and couldn't find it right now.
For example, use
base64.b64encode(zlib.compress(b"<pre>" + open('gistfile1.txt', 'rb').read())).replace(b'/',b'%2F')
To get gistfile1.txt shown in the page.Probably not, but that would be even better than a goatse troll.. actually hit them where it hurts; their ad revenue.
Of course the challenge there is good bot detection to not accidentally serve fake data to a legitimate user.
PS: NSFW in case the casual observer never encountered the horror that was goatse.cx:
NSFW https://web.archive.org/web/20010518002205/http://www.goatse... NSFW
...Yes, it does. What an odd decision. I'd link to the page where he explains it, but it also has a half-page URL.
The images of Kirk Johnson’s feat of butthole stretching started circulating in 1997.
https://www.gawker.com/finding-goatse-the-mystery-man-behind...
OP knows that
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...
Neither unauthorized hotlinking nor iframe embedding are “theft” or “steal”ing.
[0] https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...
In my opinion that's wrong.
This is one of the few parts of internet culture I hope to see the end of. We can be edgy and offensive without traumatizing each other.
My point is that OP could have used porn (or something else) as an alternative to shock/trauma imagery, because their goal was to be offensive. There was no need for OP to traumatize their audience.
same for hotlinking images, too
"Hey come check out this amazing magic eye". Boom!
I see what you did there.
I can't imagine that it's that they think children can be be damaged in some way by knowing how to curse.
I imagine it's more that children will think these words are fun new toys and will constantly repeat them, enjoying how much of a reaction they provoke. And that the parent 1. will feel sad that the child now has this verbal crutch that they may end up leaning into in the future in place of learning how to speak eloquently; and 2. will feel ashamed when others in the community see the child swearing, and assume that it's a behavior that the parent inculcated into them by swearing constantly in front of them, rather than a behavior the parent tried their best to prevent — but which the child inevitably picked up somewhere outside the home.
There's probably something analogous here, right? Being exposed to "graphic imagery" is not really damaging per se. Rather, seeing such things just shifts a child's potential repertoire of behaviors/responses slightly (think: being desensitized enough to such imagery to find it funny to use to troll others in a school computer lab), in a way that might be assumed by others to have been a direct consequence of the parent's actions (e.g. by having sex / watching porn in front of their children.) Such behaviors by the child will reflect badly on the parent's parenting, even if they were actually purely the result of the child's self-motivated idle curiosity.
In short, these things — a child swearing, a child sending pictures of gross buttholes to other children — are conflationary triggers for community shaming of the parents: they cause behaviors in children that could well have been caused by bad parenting, and so tar the parents with the brush of being bad parents, whether or not the parent is actually bad.
Parents don't tend to like being shamed by the community for bad parenting, when they don't believe themselves to be bad parents; so they treat any such "conflationary triggers" for that shaming, as taboos, things to avoid their children witnessing, even if those things aren't "damaging."
This is a selection bias. By definition, all the survivors of the most atrocious things can say "I went through XYZ and I’m still alive". That doesn’t make this XYZ something you would recommend to anyone.
Everyone has a butthole. Do kids never look in the mirror? Do kids never explore bodies? We spent 100k years or more looking at each other in the nude and somehow our species didn't all go insane.
Nakedness probably doesn't hurt anyone.
You were triggered, and so you lashed out with an attack aimed at bystanders.
"mature and responsible" have nothing to do with it. The word is: immoral.
I don't know why the internet insists on deriding anyone that reacts strongly to anything. It's something you ought to grow out of after middle school.
I'm all for strong reactions. Heated debate, swift actions, deep self reflection. Yes, all welcome. For example, if OP had password protected his site I would applaud.
But my personal views are:
- strong reactions aren't "justification" to further escalate violence.
- intentionally using that specific image to inflict harm on people is definitely violence.
So, I'm going to take a moment to advocate for that perspective, Even though I may not sway anyone. After all, silence is acceptance.(Some among whom are probably children)
But yes, won't somebody think of the children.
Just because people often say "think of the children" insincerely doesn't mean you should never think of them.
while one unrelated user is hurt in a substantial way (somewhere from pretty disgusted to mildly traumatized)
Does nobody see the obvious problem?
If the site is for fun and doesn't make money, then how is what these aggregators are doing considered "theft"? Theft of credit for making the app, I guess? I dunno--I'm surprised the article OP is so bent out of shape if it's just a fun throwaway project. I wouldn't care but maybe that's just me.
Morally, landlording is theft.