12 ms·
Evil.js: A JavaScript library for thwarting hot-linkers
- wincent 13y agoNot to be confused with evil.js: http://andjs.com/code/eviljs/ http://andjs.com/code/eviljs/
- eli 13y agoReminds me of a script I wrote when a site based in China cloned our entire domain and put it up at a new URL, complete with clumsily photoshopped logos. They left a single stray call to our ad server, though, and I was able to "hack in" and randomly flash a "This site is stolen!" message or insert an auto-playing Youtube clip of my choice.
- Xophmeister 13y agoYouTube is blocked in China...
- eli 13y agoFair point, though the audience for the pranks was more the people they were trying to sell advertising space to.
- brianpgordon 13y agoHe could link to Falun Dafa exercise videos and watch as their customers disappear one by one...
- laurent123456 13y agoThat will get his ad server blocked in China, which he might not want.
- tlrobinson 13y agowindow.location = "http://someone-elses-site.com/Falun_Dafa_exercise_video.mpg";
- laurent123456 13y agoTrolling the GFW... that could be an interesting experiment :) http://gov.cn/taiwan-is-a-sovereign-state/ http://gov.cn/taiwan-is-a-sovereign-state/
- thebiglebrewski 13y agoCan we get a demo?
- jamestanderson 13y agoFrom the github page: http://kitcambridge.be/evil.js/ http://kitcambridge.be/evil.js/
- thebiglebrewski 13y agoIs something supposed to happen interaction-wise when I go to that page though?
- de_dave 13y agoNo, it just prevents other scripts linked from the same page from working via sneaky, nefarious means that make it hard to debug.
- thebiglebrewski 13y agoOh! OK. cool.
- deleted 13y ago[deleted]
- welder 13y agocombination and minification also prevent hot-linking
- jdavis703 13y agoI've had experience where someone doesn't just hotlink a resource, but they "clone" it, and replace our ads with their ads. Assuming evil.js works by detecting host names, this would help prevent that.
- brianpgordon 13y agoIt doesn't, as a cursory glance at the source would show.
- toxicFork 13y agoThe server could check which page is embedding the script and then server evil.js instead of good.js :)
- Dylan16807 13y agoBetter hope they don't visit the real site after the fake site!
- cmelbye 13y agoDon't cache the fake version?
- matthuggins 13y agoThe documentation is lacking.
- kirkbackus 13y agoThe non-minified source is pretty self-explanatory. It modifies a lot of the standard javascript functions. My favorite is the document.write(element) is modified to surround the element with <marquee> and <blink> tags and then write that to the DOM.
- Jgrubb 13y agoI like Math.pow = function() { return "pow pow pow!"; }
- matthuggins 13y agoTo an extent, yes. I already looked at the source. But it just says to include evil.js on my site. How is that protecting my site from bandwidth thieves? Won't it also screw up my own site's functions?
- jt2190 13y agoVery cute. :-) Now that we've all had a laugh, wouldn't it make more sense to have the server respond with a redirect to a shared copy of the script hosted somewhere that provides bandwidth for free? (Perhaps this is a sign that the script should be open-sourced as well.)
- tibbon 13y agoBut bandwidth isn't free. Someone's gotta pay for it in some way or another, and if a major company lets say is using your hosted copy without asking, then perhaps they should host their own?
- ithkuil 13y agothere are cdns happy to host useful opensource scripts for free, assuming you want to release your script as open source.
- arcatek 13y agoThis script is used by rawgithub.io. It allows to punish the 'abusers'. There isn't really a notion of open-source in it. I think the idea is more that if someone is eating your bandwidth by hotlinking your jQuery.js, then you can serve them this instead.
- orthecreedence 13y agoIf someone hotlinked one of my scripts, I'd update the head of the script and use the opportunity for free marketing: if(!window.location.host.match(/(www\.)?myapp.com/)) window.location = 'http://www.myapp.com'; I bet they won't hotlink after that.
- jt2190 13y agoI like this. I'd think it'd be even better if instead of getting them to stop linking, you could turn them into a permanent source of referrals.
- 13y ago
- owenversteeg 13y agoWhat if someone hotlinks evil.js?
- JeanSebTr 13y agoSo we can check the hostname from our code and hot-link evil.js from http://kitcambridge.be/evil.js/evil.min.js http://kitcambridge.be/evil.js/evil.min.js :)
- adamb_ 13y agoI did not realize until checking out this source that dividing by zero in JS outputs "Infinity". https://github.com/kitcambridge/evil.js/blob/gh-pages/evil.js#L87 https://github.com/kitcambridge/evil.js/blob/gh-pages/evil.j...
- wyuenho 13y agoNot always. 0/0 == NaN, but of course typing that into the console will yield false.
- _mtr 13y agoBecause, of course, NaN != NaN
- mbel 13y agoThis is happening because all numbers in JavaScript are IEEE 754 [0] double. +/-infinite may be returned for finite, non zero number divided by zero. This is also common behavior in many other languages with support for IEEE 754 floats, from the top of my head: JVM, .NET languages and Haskell do so too. [0] http://en.wikipedia.org/wiki/IEEE_754 http://en.wikipedia.org/wiki/IEEE_754
- RKoutnik 13y agoLonger answer on StackOverflow (including V8 source): http://stackoverflow.com/a/21893602/1216976 http://stackoverflow.com/a/21893602/1216976
- derefr 13y agoAnd, awfully-enough, even though Infinity is a required part of IEEE754, and happens all the time in Javascript, JSON doesn't recognize it.
- hrjet 13y agoIIRC, JSON is a strict subset of JS and Python.
- mixedbit 13y agoAs a "bonus" you will make your site unusable for suffix proxy users.
- tlrobinson 13y agoAnd the logical follow up, evil.css: https://github.com/tlrobinson/evil.css https://github.com/tlrobinson/evil.css
- dpweb 13y agoTo stop leechers - couldn't you just, in your script > (function(){ if(document.domain != 'mydomain.com') return; // my script })();
- jasonkostempski 13y agoBetter not minify the library with JSMin.