Upside-Down-Ternet
pete.ex-parrot.com
Upside-Down-Ternet
1–10 of 20 posts
Re: Upside-Down-Ternet
#2In 2013 I wrote an article about how to turn a Squid proxy into a code injection attack mechanism [1] (which many free proxies did at the time [2]). The most "harmless" would just replace the ads you see with their own, the worse ones used browser events to report all keystrokes or mouse positions to the attackers.
[1] https://blog.haschek.at/2013/05/why-free-proxies-are-free-js...
[2] https://blog.haschek.at/2015-analyzing-443-free-proxies/
Re: Upside-Down-Ternet
#3It's almost unimaginable today that browser traffic used to be unencrypted and people in your network or down the line to your target could see and modify your traffic. In 2013 I wrote an article about how to turn a Squid proxy into a code injection attack mechanism [1] (which many free proxies did at the time [2]). The most "harmless" would just replace the ads you see with their own, the worse ones used browser eve…
It's hard to ignore when randos are screwing with you in real-time.
I'm sorry that open view of the internet ended, but it also ended far later than it should have by rights.
Re: Upside-Down-Ternet
#4It's almost unimaginable today that browser traffic used to be unencrypted and people in your network or down the line to your target could see and modify your traffic. In 2013 I wrote an article about how to turn a Squid proxy into a code injection attack mechanism [1] (which many free proxies did at the time [2]). The most "harmless" would just replace the ads you see with their own, the worse ones used browser eve…
Re: Upside-Down-Ternet
#5It's almost unimaginable today that browser traffic used to be unencrypted and people in your network or down the line to your target could see and modify your traffic. In 2013 I wrote an article about how to turn a Squid proxy into a code injection attack mechanism [1] (which many free proxies did at the time [2]). The most "harmless" would just replace the ads you see with their own, the worse ones used browser eve…
And yet, every time there's an article about TLS, we have the same debate here with a few people arguing that their personal websites don't need HTTPS...
Re: Upside-Down-Ternet
#6Re: Upside-Down-Ternet
#7One of the slightly more subtle tricks that took a long time for people to identify was to modify ad banners so that they pointed to another provideur. Servers were fixed, image sizes were standardised, etc. This also required much less computing power and bandwidth.
There's a student residence that displayed a lot of ads for Bible studies and gay porn about fifteen years ago.
This wouldn't work nowadays if the majority of traffic was encrypted using TLS and authenticated using certificates.