10 ms·
Stunnel and Airline Wi-Fi
- BearsAreCool 7y agoNice breakdown! This makes me curious of just how many "free" wifi hotspots that allow access to a specific site can be completely bypassed.
- Pneumaticat 7y agoThank you! I suspect the answer is "most", especially if they allow HTTPS in any way. The way to solve this issue is to either whitelist IPs/host the site internally on the local network (e.g. most captive portals).
- nawtacawp 7y agoWhile interesting, I would have an uneasy feeling messing with the WIFI AP on an airplane. Perhaps there is a U.S. law this type of conduct would fall under specific to being on an airplane?
- gravitas 7y agoThe author does not "mess with the WIFI AP on the plane", they exploit a weakness in the design (failure by viasat to maintain an checksum IP mapping to their domain for the captive service) to simply bypass a trivial TLS header check in order to tunnel their traffic.
- behrlich 7y agoThis is almost definitely “hacking” under federal law.
- gravitas 7y agoThe person I'm replying to specifically said "mess with the WIFI AP" in order to present this as harmful or dangerous (FUD), it is not. It's a trivial header check bypass - whether or not that is "hacking" is a question for lawyers and a judge.
- behrlich 7y agoRight. I think all he’s trying to say is that it might be worse to hack something on a plane vs some other kind of computer system. I don’t think they were implying harm was being done to the ap. Colloquially I would definitely call this messing with the ap :)
- pessimizer 7y agoI was just bypassing a some trivial key check on the door. To say I was "messing with the door" is FUD, and whether I was breaking and entering is a question for lawyers and a judge.
- judge2020 7y agoThe owner gave me a key to the lobby so I could pay to get an all-access key. As it turns out, I can just walk past the lobby and that key actually opens all doors in the building. Whether or not it's illegal to use it to access whatever I want is a question for lawyers and a judge.
- rebuilder 7y agoThat's not what's happening here. This is more like trying the key on every door, finding a cleaning closet unlocked and crawling through the ventilation ducts to get in.
- judge2020 7y agoI think it's pretty close to the reality. The lobby is wide open (viasat's payment gateway), but if you just use the viasat lobby key (viasat.com SNI) on any other door (IP address) it allows you access. They could prevent you from getting to the doors in the first place (whitelisting MAC address to access anything other than a whitelist of IPs instead of just TLS SNI whitelisting) but they don't, as it's especially evident when they allow other protocols when the connection is not encrypted.
- 7y ago
- mightybyte 7y agoIANAL and all that, but my perception is that "hacking" is usually about breaking into someone else's computer / breaching someone else's privacy / accessing data that isn't yours / etc. If that perception is accurate, then I think it's really a stretch to call this "hacking". You're just moving bits around on network infrastructure designed to move bits around. Maybe I'm just looking for a loophole because wishful thinking, but this seems like a decent argument to me. Now, you could be violating their terms of service. But in this case there may be a good argument that you never accepted their terms of service since you wouldn't have had to click the "accept" button to do what the post describes.
- sfkdjf9j3j 7y agoRead up on this: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act The CFAA is pretty broad, and definitely controversial because of it. Look up Aaron Swartz's tragic case.
- dehrmann 7y agoThe old colloquial term for this is "phreaking."
- eeeeeeeeeeeee 7y agoThis is absolutely circumventing the intended usage of the system.
- kristianc 7y agoThis is hacking under federal law, as it should be. Likewise that if I break into your house by merely exploiting a weakness in the design of the lock, I am still committing a crime.
- Dayshine 7y agoIf someone charges for tours of part of their house, has two prices of tour, and you change the colour of your badge to let you access the part you haven't paid for, is that a crime?
- jfk13 7y agoSounds like some form of fraud to me. What's the difference between that and simply forging a ticket to an event instead of buying one? Or forging a currency note?
- Dayshine 7y agoOK, the better example from further down. You realise your badge lets you into areas of the premium tour, it opens all doors, not just the ones you paid for it to open. And even if it is fraud of some kind, the bar for charging someone with fraud (instead of just suing for damages) is fairly high...
- MikeKusold 7y agoYes. It’s trespassing.
- Asooka 7y agoWell yes, but bandwidth is practically free anyway. I'm not actually stealing computer resources. It's more akin to looking at the Mona Lisa through one of the Louvre's windows using a pair of binoculars.
- pessimizer 7y agoMy guess would be that getting caught doing this could get you federal terrorism charges. I don't even think it's a safe assumption that the network is isolated or properly insulated from pilot instrumentation.
- deleted 7y ago[deleted]
- _underfl0w_ 7y agoIf that assumption isn't safe, then neither is the plane. Having ANY access AT ALL whether via "hidden" backdoor or authorized login to plane instrumentation from the WiFi would be an insane setup. Just because they're both invisible to you doesn't mean they're connected in some way. Could you imagine the attack surface? We'd be hearing about terrorist attacks leveraging that design flaw.
- xedeon 7y agoPlease actually read the article. The author did not “mess” with WiFi radio. It was all done on the network layer.
- ThinkingGuy 7y agoHow well do you trust that 12 jury members would understand the distinction?
- oh_sigh 7y agoThat wasn't the point OP was making.
- grepthisab 7y agoNo way to convince a jury of this, for real. Not worth the risk of trying to explain the distinction versus being prosecuted.
- cosmodisk 7y agoWas going to write the same. Prosecutors would have easy time convincing judge that hacking+ doing so while airborne should result in many years behind the bars, especially knowing how punitive the legal system in the US can be. The article itself is very interesting though.
- Pneumaticat 7y agoA good point. To be fair, though, even Lifehacker has posted a similar writeup [1] (linked in the article) and I don't think they've been threatened. Getting caught in the air - now, that's a different story ;) [1]: https://lifehacker.com/get-free-unlimited-wi-fi-on-flights-and-bypass-paywall-1788148516 https://lifehacker.com/get-free-unlimited-wi-fi-on-flights-a...
- gpvos 7y agoGetting caught in the air seems nigh impossible, since by using this trick you aren't giving them any way to identify you.
- bspammer 7y agoThey'd have your stunnel server IP, so if they were really, really determined they could probably track you down by forcing your ISP/VPS provider to identify you. I doubt they'd bother for $45 worth of WiFi, but personally I would err on the side of caution.
- goblin89 7y agoWhile in general bypassing Wi-Fi restrictions is indeed dubious from legal standpoint, it’s most likely as safe on an airplane as anywhere else. If in-flight Wi-Fi provider’s AP was in any way part of aircraft control system network, I would be surprised if overseeing such a design flaw weren’t a crime.
- dboreham 7y agoIt's also, you know, wrong. Old fashioned wrong. Stealing.
- thomasfedb 7y agoNice write-up. Found it very clear (and thanks for the SNI primer) except perhaps the port-soup near the end. Might have benifitted from a little diagram or flowchart for that bit.
- Pneumaticat 7y agoThanks! Let me see if I can add an mspaint diagram. edit: added! try refreshing if you don't see it.
- NKosmatos 7y agoNice post and well written. I’ll have to try something similar with stunner for my office connection (heavily filtered and firewalled), to allow me to reach my raspberry back home.
- spydum 7y agonot sure office == work place, but most workplaces have policies around intentionally bypassing network security/firewall rules. If your workplace has any kind of security operations/threat detection, you could find yourself explaining why exactly your host is reaching out over suspiciously encrypted channels?
- ThrowawayR2 7y agoSpecifically, https://en.wikipedia.org/wiki/Egress_filtering https://en.wikipedia.org/wiki/Egress_filtering. If the OP's company has restrictive firewalling and filtering already, they also probably have egress filtering and monitoring as well.
- NKosmatos 7y agoI agree with you, this will surely raise a red flag in our administrators panel and this isn't my intention. I'm mainly interested on the technical side of things. I know that most ports and traffic types are already blocked. What about outgoing https traffic, this is encrypted and should be allowed to pass...something like an https tunnel.
- aisofteng 7y agoJust note that doing that is probably a fireable offense.
- lalabert 7y agoDefinitely agree! Irrespective of motive it would raise questions about integrity! You don’t want to be going there!!
- Scea91 7y agoThis seems quite unethical to me.
- facorreia 7y agoIt is theft of services. Ironical in this website since ycombinator companies are mostly about selling services via the Internet.
- teraflop 7y agoWell, the flip side is that Y Combinator has no qualms about funding companies whose business model relies on ignoring laws that are inconvenient. Here are two different YC startups that relied on tourists smuggling goods to avoid import duties: https://techcrunch.com/2014/08/13/backpack-connects-you-with-travelers-so-you-can-purchase-items-in-other-countries/ https://techcrunch.com/2014/08/13/backpack-connects-you-with... https://news.ycombinator.com/item?id=10998377 https://news.ycombinator.com/item?id=10998377
- jimhi 7y agoYou will be happy to know the send it on "airplane as luggage with passengers" business models are now seen as failures by most Silicon Valley investors as well as some YC partners. It's been 5 years and there were many of these companies - the investors got burned How do I know? I run a YC funded company that legally imports :)
- tidepod12 7y agoI'm a bit flabberghasted that so many commenters in this thread are apparently in favor of committing blatant theft.
- dehrmann 7y agoThis feels more like a complicated version of telling the world some grocery store entered store brand canned sardines wrong in their system and they'll ring up as $0. Sure, they're free, for now, but do you really want all those canned sardines?
- ajross 7y agotl;dr: The Vianet firewall is trying to do filtering of TLS connections based on the arbitrary and client-controlled host name string and not the destination IP address. It has no network-level routing control at all, it will allow a connection to any host on the internet, but will then terminate it after it sees that it's not going to (strictly, "doesn't look like it's going to") a permitted host. So the author set up a ssh server on the HTTPS port and connected to it with a faked host name. But seriously folks: this is (1) still a crime in basically all jusisdictions and (2) a crime on an airplane in flight, so have fun in jail.
- pritambaral 7y agoHow is this a crime (in _all_ jurisdictions)? The CFAA is US-only, and few other jurisdictions have as loose terms (or history of abuse) as the CFAA, when it comes to "hacking".
- ajross 7y agoIt's straight up unauthorized access to a computer system. They tell you they don't allow it and you have to pay for it, the author clearly knew that, and evaded the protections. Cite me a legal environment where that is not a crime.
- pritambaral 7y agoWhich computer system does this access that the user was unauthorized to access? The user's home server?! The made-for-DRM CFAA that might classify fooling a flimsy filter as "unauthorized access to a computer system" is very much US-specific. Over here on the other side of the world, I'm thankful I'm not subject to such legislation or judicial system, but to one which still has a sensible definition of "hacking".
- ajross 7y agoSigh. Routers are computers too.
- supahfly_remix 7y agoNice write up. I am curious how DNS works, and if that is an alternative protocol for tunneling in this situation.
- casi 7y agoCheck out iodine https://code.kryo.se/iodine/ https://code.kryo.se/iodine/
- jacob019 7y agoNot very well. Have used iodine tunnels for similar purposes, painfully slow.
- wdroz 7y agoThe latest iodine version is quick and works almost everywhere. Should work fine in the OP scenario. I also use SSH -D, then I use proxychains and it work fine.
- tbronchain 7y agoI'm actually surprised simple tunneling is working and they don't have additional protections. From my experience most of public networks won't let you do much this way. However, it seems it (as most captive portals) has access to DNS servers. There was this tool people were using to bypass VPNs blocking and throttling in China called kcptun. It was letting you tunnel tcp traffic over udp, then SSL tunnel on top of it. With a server listening on port 53, it was working awesome to avoid QOS and managed to 1- bypass authentication and 2- get absolutely amazing speeds on some airport wifis for example. You probably could do the same with an openVPN on UDP 53. However, it seems most public wifis are smarter and would blacklist your Mac address if either too much traffic is going through, or you say for too long. You can change your address, but it's not really usable. Still fun though! Also, it seems most public wifis now do more DPI and they won't let other traffic than DNS go on UDP 53. This in minds, another one I haven't been looking through much is DNS tunneling - would love to hear anyone's experience about it (I've heard it's very slow...) Edit: seeing a few comments about the unethical aspect of this. In some cases, it might be. In some others, it is about avoiding a system that tracks you and try to gather and resell as much information as it can about you (it varies a lot according to which country you're in).
- icebraining 7y ago> DNS tunneling I've done it a bit (using iodine[1]) and while it obviously depends a lot on the DNS server they're using, it can be surprisingly fast. I think I got over 300kbps regularly, which while not great for video streaming, is more than enough for HN and such. iodine in particular tries to use some less common DNS record types like NULL, which might support up to 65kb/reply, falling back to more common if those are not supported, so you can get decent download speeds. [1] https://code.kryo.se/iodine https://code.kryo.se/iodine
- PaulAJ 7y agoIn the USA this would be a violation of the CFAA https://www.law.cornell.edu/uscode/text/18/1030 https://www.law.cornell.edu/uscode/text/18/1030. Specifically, the router is a "protected computer" and the procedure described here is "exceeding authorised access" because it routes packets around a mechanism that was designed to stop them. Maximum penalty 5 years. (Some might argue that it was authorised because the computer let him do it. However the CFAA simply doesn't work that way. "Authorisation" is what the designers intended, and the initial paywall made that intention perfectly clear.)
- Hitton 7y agoNot a lawyer, but you could argue that he wasn't really accessing the router, he was accessing his own server at home.
- PaulAJ 7y agoHe was accessing the router by sending packets through it. Authorisation to do this was only granted in return for payment, and he hadn't paid.
- shawnz 7y agoFrom your link: > the term “exceeds authorized access” means to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter; The information they were accessing didn't come from the computer. And this doesn't say anything about using a computer service in an unauthorized way, which is what it sounds like you're describing here
- PaulAJ 7y agoThe output buffer on the Internet side of the router is information in the computer. It was modified without authorization when packets were sent through it.
- themark 7y agoSweet to see another guy that tests with zombo.com!
- AndrewBissell 7y agoThe infinite is possible!
- myrandomcomment 7y agoThe comment about the 24Mbps is pretty impressive. My experience every month on the JAL flights SF to Tokyo and Tokyo to $SomeOtherAsianCity is pretty crappy. I wonder if doing this it also bypasses some QoS filters? For example on a flight I tried to open the XM app on my iPad and could not stream a thing (it's pretty low but rate). Slack connects and disconnects all time. Email works but is slow. Webpages take minutes to load. Every flight for the last few years so...
- kemitche 7y agoI bet that viasat.com "connections" are given priority and not throttled for bandwidth - or perhaps since he never registered with the system, it never applied a throttle, under the assumption that blocking access negated the need for a throttle.
- UperSpaceGuru 7y agoThat’s because you’re traveling in airspace covered by different Satellite than the one that covers The American continent. Top speed should actually be ~74MBps. I was one of the people who helped build the system (not at Viasat)
- a012 7y agoIt's almost a 1Gbps over sat link, are you correct?
- UperSpaceGuru 7y agohttps://en.m.wikipedia.org/wiki/ViaSat-1 https://en.m.wikipedia.org/wiki/ViaSat-1 Apparently it’s been benchmarked doing even better speeds. There was supposed to be new satellites launched over Europe and Asia, but at the time, this was the fastest one.
- jeffmcjunkin 7y agoYou're not far from agreeing with each other: (74 megabytes per second) / (1 gigabit per second) = 59.2 percent
- Hitton 7y agoToo bad he didn't try other protocols. I wouldn't be surprised if DNS or ICMP tunnel worked too.
- Pneumaticat 7y agoBut iodine [1] is very slow ;) (Also with the satellite roundtrip, it probably would've worked, but super slowly.) [1]: https://code.kryo.se/iodine/ https://code.kryo.se/iodine/
- byteCoder 7y agoIllegal and unethical: yes, in this use case. But, let's give Kevin serious kudos on his clever approach to solving this problem. This is the true hacker spirit that reaches across the decades. Bravo!
- batbomb 7y agoIt’s always easier to just wireshark for an IP address that has access (in hotels too) and then clone the MAC adddress.
- peterwwillis 7y agoYep, this is the easiest & most reliable method. Other techniques include tunneling over DNS, tunneling over ICMP, finding flaws in the HTTP parser, scanning the default router for open ports, scanning intermediate proxies for open ports, exploiting bad proxy redirect rules, finding protocols and ports that the firewall doesn't block outbound, and finding holes in the paywall's web apps. Once upon a time there was a pre-paid mobile internet provider that sold USB sticks. It turned out that once you had initially activated the stick, even without an account, it would always default to a paywall until you had an account paid up. The HTTP parser of the paywall proxy was so bad, it only filtered connections with CRLF as the line-terminator for HTTP requests... so a simple proxy that converted CRLF to LF bypassed the paywall.
- crankylinuxuser 7y agoI did this as well using Orbot (Tor software for Android) and an OBFS4 proxy. In Southwest (the airline), you connect to the wifi for watching the movie and where you are in air. But if you want internet, you pay. I have some of my applications always Torified on my phone. I opened my 3d printer app to view its status, expecting a hard fail. And... it loaded!
- _underfl0w_ 7y agoGenuine question here - isn't Tor traffic reputed for having a certain "footprint"? I would be worried about accessing the Tor network over public WiFi, but maybe that's just me.
- crankylinuxuser 7y agoStandard Tor, sure. But when you start using pluggable transports, like Obfs4, you can defeat pretty much every captive portal or traffic analyzer. I'm sure there might be a way to detect even these. But remember that the real test of detection is the GFoC. Some piddly airline's offering of pay internet is not going to use nation-state level detection schemes.
- sroussey 7y agoI find that iMessage always works on my flights with United. No images though. I was surprised since the cell was off and it remembered the Wi-Fi but messages came through.
- eyeball 7y agoI’ve been able to get enough bandwidth to check email on delta by: 1) connect to WiFi and get to the sign up / credit card page 2) turn on PIA vpn client Seems to work. Very limited speed though. Email checks and not much else.
- cwyers 7y agoI'm seeing a lot of people say that airplane wifi is overpriced, and I'm kind of baffled. Yes, compared to terrestrial wifi it's expensive. But... you're in a fast moving object communicating with satellites (satellite launches are expensive!) and I don't really understand why people are so eager to call this bad pricing.
- maxerickson 7y agoI don't fly enough to care, but the pricing model has become a death of one thousand cuts. I can see why that is bothersome, even if it can be described as fair exchange of value or whatever.
- Sebb767 7y agoWell it turns out people prefer to pay 10$ and 5*12$ instead of 70$ for a flight, probably because it feels like you can save a bit. At the end the airline needs to get its bottom line green and airplanes and satellite wifi are not cheap, not to speak of the highly paid people needed to run it all. It's one thing to call that unethical, but at the end the market decides and it seems that all-inclusive deals simply do not resonate as well.
- UperSpaceGuru 7y agoWow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of me finds this Amusing, but I hope the author doesn’t face more serious consequences, primarily for having made this public knowledge. I have a sense the defense company that now owns the system being bypassed/broken will not find it amusing in the least bit. Disclaimer: opinions above are my own. I do not speak for or on behalf of any party in the article.
- pmontra 7y agoDefinitely, but it's worth for them to defend against or go after the few people willing to use this method to get free Wi-Fi on planes? IMHO they'll spend more than what they'll gain.
- deleted 7y ago[deleted]
- UperSpaceGuru 7y agoI fear that this would be viewed thru the lens of “PR” & “brand”, thing companies are rightfully keen in protecting. Unfortunately there’s a legal component to all this also. The knowledge itself is cool & even actual instances of a handful of people getting “free” internet probably wouldn’t register on their radar. But the publicity from being on the top of HN... that might be of significant concern
- xfitm3 7y agoWe shouldn't let defense companies push around the general public. I'm glad that the author is willing to shoulder that risk, we need more people like them.
- UperSpaceGuru 7y ago
- btgeekboy 7y agoIf your flight has GoGo, it’s easier to just remember which of your friends has a T-Mobile number, plug that in, and you’re in. They don’t actually verify it’s your number.
- dawnerd 7y agoThey used to offer all flight passes as well instead of the hour limit. I’d open up safari on my Mac, spoof the UA and have free internet that way. Also recently I think they’ve stopped giving T-Mobile numbers access to the higher speeds. Was fun while it lasted. I was able to clock over 50mbps on one of my flights. Kinda nuts.
- sitkack 7y agoReminds me a of a 2600Hz article from the 90s.
- anonu 7y agoToo bad that magazine has fallen to the way side. I still purchase it every now and then (when I'm in a Barnes and Noble). The letters from readers surprise me quite a bit: seems like it has decent circulation in the prison population. wonder why that is...
- INTPenis 7y agoAs someone who has created captive portal systems I have to say that this is a very poor system. My system tagged you in a firewall so your packets were not getting out until you had authenticated and ended up in an ipset list that bypassed the tag.
- Zenbit_UX 7y agoI guess the collected readership of HN wished you didn't do your job so well then...
- deanclatworthy 7y agoAn alternative to this is to scan for active Mac addresses on the WiFi and steal one and hope it’s someone paying for the premium WiFi already :) This works on almost all hotel WiFi too.
- baxtr 7y agoWouldn’t than both devices “fight” for the access? Who gets the packages?
- Zenbit_UX 7y agoYes, it makes both connections highly unstable. Not recommended.
- deanclatworthy 7y agoIt works flawlessly. You can go further to end up kicking them off with some more shady tools. Not that I’d approve of that.
- baxtr 7y agoI guess some friend of a friend told you?
- makefu 7y agoI was pleasantly surprised to see the appropriate NixOS configuration in the middle of the article. NixOS stream-lines the whole configuration process to a couple of lines of configuration which can be copy-pasted without changing anything.
- ksahin 7y agoA bit off-topic but I'm curious: Which laws applies on a plane?
- MrMorden 7y agoWhatever country's airspace you're in and whatever country the plane is registered in. (Probably an oversimplification, but IANAL and I definitely ANYL.)
- Asooka 7y agoI can't open this page on my chromebook, I'm getting a NET::ERR_CERT_COMMON_NAME_INVALID Subject: dns.google Issuer: Google Internet Authority G3 Expires on: 10 Sep 2019 Current date: 20 Jul 2019 With a further message that You cannot visit potatofrom.space right now because the website uses HSTS.
- casefields 7y agoCached view: http://web.archive.org/web/20190720131624/https://potatofrom.space/post/viasat-airline-free-wifi-stunnel/ http://web.archive.org/web/20190720131624/https://potatofrom...
- nealabq 7y agoThe site's down for me. I got a 404 and a few minutes later a Firefox "Did Not Connect: Potential Security Issue" followed by this explanation: Firefox detected a potential security threat and did not continue to potatofrom.space because this website requires a secure connection. What can you do about it? potatofrom.space has a security policy called HTTP Strict Transport Security (HSTS), which means that Firefox can only connect to it securely. You can’t add an exception to visit this site. The issue is most likely with the website, and there is nothing you can do to resolve it. You can notify the website’s administrator about the problem.
- judge2020 7y agoArchive: https://web.archive.org/web/20190720140005/https://potatofrom.space/post/viasat-airline-free-wifi-stunnel/ https://web.archive.org/web/20190720140005/https://potatofro...
- judge2020 7y agoThe website itself is up https://potatofrom.space/ https://potatofrom.space/ so looks like the author decided to take it down, odd. Maybe he got a cease and desist from Viasat.
- Rafert 7y agoStill available on the GitLab instance linked from the home page: https://gitlab.potatofrom.space/kevin/potatofrom.space/blob/0f2048ff5124327e27aca76e2c98d16be076e400/content/post/viasat-airline-free-wifi-stunnel.md https://gitlab.potatofrom.space/kevin/potatofrom.space/blob/...
- l1n 7y agoAll HN submissions are archived at archive.is, you can access this one at http://archive.is/https://potatofrom.space/post/viasat-airline-free-wifi-stunnel/ http://archive.is/https://potatofrom.space/post/viasat-airli...
- habosa 7y agoLast year I was on a flight and my phone buzzed, which was odd. I looked down and it had somehow connected to the WiFi without my doing anything and started getting chat messages. I tested further and my WiFi was totally unrestricted. I was able to download a show from Netflix at 20Mbps+ ... does anyone know what happened? I didn't even think planes had WiFi that fast and I definitely thought they blocked all streaming video domains.
- sabujp 7y agoanother way is to use DNS. Most captive portals allow UDP/DNS. You can craft a proxy to do proxy via 53/udp.
- lefstathiou 7y ago@HN admin I think it’s a good idea to remove this post. The author fucked up, I think it’s worth doing what we can to prevent further collateral damage to them.
- Topgamer7 7y agoQuick, everyone ignore the security issue, if we don't look it's not there!
- nabakin 7y agoAnyone else getting a 404 error?
- jitbit 7y agoMeanwhile the site is down (503)
- hansdieter1337 7y agoReminds me of DNS tunneling. But this approach is probably faster.
- Pneumaticat 7y agoHey guys, thanks for all the comments! I realized that it was not an ethical idea to post, so I decided to take it down. I did not get a cease and desist, but I would appreciate if you could refrain from reposting it. If you are interested in seeing some of my other (more ethical) work, check out Delphus [1], an open research study management platform which I am working on at my new startup ;) [1]: https://delph.us https://delph.us
- bin0 7y agoI'm not sure about this, still. I'd consider it roughly equivalent to posting a POC for an exploit: it could be abused, could be uses for academic learning, or could be used to improve systems. It's not inherently bad.