5 ms·
also FYI a lot of places dont place limits on the size of their POST requests or timeouts. I have been able to send scammers 500MB+ POST requests just by makin
by m4jor 3y ago
also FYI a lot of places dont place limits on the size of their POST requests or timeouts.
I have been able to send scammers 500MB+ POST requests just by making the password field password=888888888888888888888888888888 (etc til its 100s of MB of data).
Use a tool like OWASP ZAP or Burp Suite and you can easily slam a scammers website full of 500mb+ requests that will quickly fill up their log files and cheap VPS harddrive and eventually the website will get an hdd full msg or just go offline til they fix it.
Cheap and easy way to take their website offline to prevent more people from getting scammed.
- jrockway 3y agoI always log requests as "http://example.com/foo/bar/ http://example.com/foo/bar/... [1234 bytes]".
- thephyber 3y agoIf a site is designed for scamming, it will likely log the contents of the form submissions -- sensitive fields like username + password combos or other PII.
- gibolt 3y agoEven better if they use AWS or other service, and end up with a huge unexpected bill at the end of the month
- vuln 3y agoEh, the malicious actor would typically be using a compromised or carded account.
- Scoundreller 3y agoWhich is another angle to suggest in reports to incentive quick action, because they’re losing money keeping the service up.
- mancerayder 3y agoThen the billing spike will be spotted by the victim of that compromise and likely report it, I'd expect..
- judge2020 3y agoYou'd have to find a reflection bug that makes them send everything back. Data into AWS is free https://aws.amazon.com/ec2/pricing/on-demand/#Data_Transfer https://aws.amazon.com/ec2/pricing/on-demand/#Data_Transfer "Data Transfer"
- deleted 3y ago[deleted]
- leoqa 3y agoI’m pretty sure this is a felony. I’m not against the spirit but want to warn others that you could get slapped.
- aardvarkr 3y agoIt’s now a felony to send api calls? Give me a break
- sneed_chucker 3y agoThe US unfortunately has intentionally vaguely written laws about misusing computer systems which can be interpreted to punish hackers and pentesters pretty harshly.
- callalex 3y ago[flagged]
- archgoon 3y agoThe US government did not murder Aaron Schwartz. The story is tragic enough without misrepresenting his mistreatment by the government.
- deleted 3y ago[deleted]
- Fatnino 3y agoVigorously prosecuted till death.
- thephyber 3y ago> the US government murdered him Clarification: he suicided while awaiting trial after the DoJ (and possibly MIT and the journal/publisher) threw the book at him in an effort to get him to plea out to a lesser felony.