Live data from Hacker News

Using Goatse to Stop App Theft

joshcsimmons.com

361–370 of 464 posts

Re: Using Goatse to Stop App Theft

#361

Once, out of the kindness of my foolish heart, I ran a server with a lot of great sound effects for all and sundry to download. Eventually the bandwidth was getting hammered by a huge number of leechers seemingly from some apps that had simply hard-linked to the resources. After replacing said resources [0] they soon ceased but not without a slew of abusive and entitled emails demanding I restore the SFX. Oh fun time…

> simply hard-linked to the resources It's fairly surprising to see that approach from pretty large brands/companies. Some Indian ISPs are kinda notorious in that they'll just link to huge image files on third-party sites and just let their 300 million customers hammer the poor site into the ground. I guess it saves them bandwidth, but they also run a huge risk of pissing someone off and have that asset replaced by s…

Yeah, if it were someone as important as an ISP doing it, you could easily be very petty and change it to an image that read " officially endorses " (say, the statehood of Taiwan)

Re: Using Goatse to Stop App Theft

#364
post #166

Once, out of the kindness of my foolish heart, I ran a server with a lot of great sound effects for all and sundry to download. Eventually the bandwidth was getting hammered by a huge number of leechers seemingly from some apps that had simply hard-linked to the resources. After replacing said resources [0] they soon ceased but not without a slew of abusive and entitled emails demanding I restore the SFX. Oh fun time…

In the days of P2P file sharing I used to share files with file names and metadata indicating they were rare Metallica live recordings of Metallica songs and other metal band's songs.... but instead https://www.youtube.com/watch?v=hwK_WOXjfc0 So many downloads.

Was expecting to be rickrolled!

Re: Using Goatse to Stop App Theft

#365

Earlier quoted context omitted.

hm... https://joshcsimmons.com/post/H4sIAA6yLmUA/wVAwQnFIAxd5ZGL7c...

Awesome - and the first time I've actually had someone "post" on my site.

You're welcome. :D

The client-side XSS is mostly harmless (assuming you don't have any other sensitive services running with cookies scoped to this domain), although it's technically a persistent XSS, which means it could be indexed by search engines.

But is there a server-side component to this? I noticed that the "disclaimer" is added in the source returned by the server, so I assume there is some code that checks whether the post is present on the home page? If so, that could be dangerous, if there is a bug in that code such that a malicious payload in the URL could get RCE in your server process.

Re: Using Goatse to Stop App Theft

#366
post #313

Earlier quoted context omitted.

100%, and not just as devil's advocate. Let the punishment fit the crime. My sympathies are entirely on the side of the game's author. It's just an obscene image -- the "collateral damage" in this case is perfectly acceptable and imo fair because it damages the brands of the illegal hosters.

You’ll feel different about collateral damage when you have children of your own.

I already do.

Re: Using Goatse to Stop App Theft

#367

What is with the crazy URL to this blog post? I was going to share it with some friends, but then I copy/pasted the link and I'm not sharing that monster with anyone.

See the explanation on the blog itself [0]

[0] https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...

Re: Using Goatse to Stop App Theft

#368

What is with the crazy URL to this blog post? I was going to share it with some friends, but then I copy/pasted the link and I'm not sharing that monster with anyone.

See the explanation on the blog itself [0] [0] https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...

Wow... that is pretty janky.

Re: Using Goatse to Stop App Theft

#369
post #336
post #94

Earlier quoted context omitted.

I've managed to never see goatse so far. Not because I'm new or innocent, but because I've learned my lessons. I don't think the 10,000 really applies to this situation. It's certainly not something that everybody needs to see at some point in their lives (or so I've been lead to believe).

Welp perhaps you'd enjoy an album of other people seeing goatse for the first time: https://www.flickr.com/photos/mrneutron/albums/1568481/

That was great. Risky click of the day, but well worth it. I think my favorite was Ron Jeremy, of all people, being super dismayed by goatse.

Re: Using Goatse to Stop App Theft

#370

Earlier quoted context omitted.

I wish there was still more of a genuine whimsical side to the Internet or even businesses. The attention economy isn't the same.

I found a link on HN a while ago that shows you just that, it's a randomizer (like the old StumbleUpon) that sends you to random "old internet" webpages: https://wiby.me/surprise/ It sent me to a 1998 page about phrenology, the 'science' of determining someone's mental traits based on indentations in their skull: https://www.phrenology.org/index.html

Wiby is a great resource. My roll took me back to 'nam: https://jackrvn70.neocities.org/

I happen to run a directory of 'escapist/artistic' websites, if a second instance of self-promotion is permissible: https://wmw.thran.uk

Post reply on HN