Live data from Hacker News

Using Goatse to Stop App Theft

joshcsimmons.com

131–140 of 464 posts

Re: Using Goatse to Stop App Theft

#131
post #109

Earlier quoted context omitted.

oh no -- it's actually vulnerable to xss...!!! https://joshcsimmons.com/post/eNpTVlaoKC5WSEnNzefisilOLsosKL... (this just injects a alert but.... that's bad) just tried contacting the author via linkedin (since I don't see an email address on their site) @joshcsimmons are you around?

The author is aware. > Every post that I want to publicly claim authorship of lives at the root of this site. If you are reading a post that I have claimed it will look like this page. Posts of unknown authorship have a disclaimer at the top of the page. https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...

for sure, there's awareness and then there's disregard of any basic web security.

the second they start hosting any application/backend/cookie-enabled thing on this domain name, anyone could inject a script via their /post/ gzip-base64 scheme, and do bad things...?

I don't think html sanitization would go against the principle of this idea. just... at the very least strip the tags! :-)

Re: Using Goatse to Stop App Theft

#132
This is pretty funny and reminded me of the first website I had ever made (probably sometime around 6th grade, back when was cool). I’d found that most of the flash games I enjoyed had either embed codes or could just be embedded manually using an iframe. So I made a library of my favorite embedded games in a small folder of HTML files, which I FTP’d onto some server I had access to for some reason. If this goatse alternative to CSP had been used I am sure I would have gotten in a lot of trouble, which is funny to think about today.

Re: Using Goatse to Stop App Theft

#133
post #109

Earlier quoted context omitted.

oh no -- it's actually vulnerable to xss...!!! https://joshcsimmons.com/post/eNpTVlaoKC5WSEnNzefisilOLsosKL... (this just injects a alert but.... that's bad) just tried contacting the author via linkedin (since I don't see an email address on their site) @joshcsimmons are you around?

The author is aware. > Every post that I want to publicly claim authorship of lives at the root of this site. If you are reading a post that I have claimed it will look like this page. Posts of unknown authorship have a disclaimer at the top of the page. https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...

> The author is aware.

Since the website is vulnerable to XSS, you could inject a script that removes the disclaimer.

Re: Using Goatse to Stop App Theft

#134

I run three word games, this stuff happens for all of them. It sucks but I would never do what they did, it's abusive to the people who just googled your game and ended up on the wrong site. I've had teachers and students reach out to me to say they play my game in class every day together. And parents who play with their kids every day, and adult who text their results to each other every day. It sucks if they end u…

+1 - this is a childish move and bad business imo. I'd guess the author is pretty young.

Life is a meaningless crawl towards the heat death of the universe. Childish behavior is the most appropriate attitude one can have towards most things.

Re: Using Goatse to Stop App Theft

#135
post #133
post #109

Earlier quoted context omitted.

The author is aware. > Every post that I want to publicly claim authorship of lives at the root of this site. If you are reading a post that I have claimed it will look like this page. Posts of unknown authorship have a disclaimer at the top of the page. https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...

> The author is aware. Since the website is vulnerable to XSS, you could inject a script that removes the disclaimer.

100%. poc:

https://joshcsimmons.com/post/eNqzKU4uyiwosUvJTy7NTc0r0UtPLX...

Re: Using Goatse to Stop App Theft

#137

Earlier quoted context omitted.

> This blog is now STATELESS. The entire post is contained in the URL that you are visiting now. All my "blog" is now is a hard-coded main page that contains links to posts I claim authorship of. Of course the entire post is contained in each of these links. https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...

doesn't this mean I could embed salacious material into a link and fool people into thinking the person who owned this website wrote it?

Yes...

https://joshcsimmons.com/post/H4sICIi6LmUAA3RtcC5odG1sADWMMQ...

Re: Using Goatse to Stop App Theft

#138

This is perhaps the most novel usage of a supply chain attack I've yet seen.

Nah, this technique has been used to "pwn" other sites ever since dynamic web serving has been around. So very nearly from the beginning. Traditionally by looking at the referer header.

Re: Using Goatse to Stop App Theft

#139
post #67
post #43

Earlier quoted context omitted.

The author said he’s not mature. His approach is much awesomer than the nature thing.

His approach is "funny" if you want, but it doesn’t help real users finding the real domain.

He mentioned that he found the imposters when a coworker happened across them on a search result page. Does Google apply penalties to the imposter sites’ search rankings when they serve shock content rather than what was being searched for?

It seems like that might reduce real users’ confusion as they try to find the real “sqword” puzzle.

Re: Using Goatse to Stop App Theft

#140
post #133
post #109

Earlier quoted context omitted.

The author is aware. > Every post that I want to publicly claim authorship of lives at the root of this site. If you are reading a post that I have claimed it will look like this page. Posts of unknown authorship have a disclaimer at the top of the page. https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...

> The author is aware. Since the website is vulnerable to XSS, you could inject a script that removes the disclaimer.

s/removes the disclaimer/exploits a browser 0-day/
Post reply on HN