Skip to main content

Home/ Memedia/ Group items tagged Hack

Rss Feed Group items tagged

2More

Inside the precision hack « Music Machinery - 0 views

  • At 4AM this morning I received an email inviting me to an IRC chatroom where someone would explain to me exactly how the Time.com 100 Poll was precision hacked. Naturally, I was a bit suspicious. Anyone could claim to be responsible for the hack - but I ventured onto the IRC channel (feeling a bit like a Woodward or Bernstein meeting Deep Throat in a parking garage). After talking to ‘Zombocom’ (not his real nick) for a few minutes, it was clear that Zombocom was a key player in the hack. He explained how it all works. The Beginning Zombocom told me that it all started out when the folks that hang out on the random board of 4chan (sometimes known as /b/) became aware that Time.com had enlisted moot (the founder of 4chan) as one of the candidates in the Time.com 100 poll. A little investigation showed that a poll vote could be submitted just by doing an HTTP get on the URL:        http://www.timepolls.com/contentpolls/Vote.do ?pollName=time100_2009&id=1883924&rating=1 where ID is a number associated with the person being voted for (in this case 1883924 is Rain’s ID). Soon afterward, several people crafted ‘autovoters’ that would use the simple voting URL protocol to vote for moot. These simple autovoters could be triggered by an easily embeddable ’spam URL’. The autovoters were very flexible allowing the rating to be set for any poll candidate. For example, the URL           http://fun.qinip.com/gen.php?id=1883924 &rating=1&amount=160 could be used to push 160 ratings of 1 (the worst rating) for the artist Rain to the Time.com poll.
  • “Needless to say, we were enraged” says Zombocom. /b/ responded by getting organized - they created an IRC channel (#time_vote) devoted to the hack, and started to recruit. Shortly afterward, one of the members discovered that the ’salt’, the key to authenticating requests, was poorly hidden in Time.com’s voting flash application and could be extracted. With the salt in hand - the autovoters were back online, rocking the vote.
3More

Magazine Preview - Malwebolence - The World of Web Trolling - NYTimes.com - 0 views

  • That the Internet is now capacious enough to host an entire subculture of users who enjoy undermining its founding values is yet another symptom of its phenomenal success. It may not be a bad thing that the least-mature users have built remote ghettos of anonymity where the malice is usually intramural. But how do we deal with cases like An Hero, epilepsy hacks and the possibility of real harm being inflicted on strangers?
  • n June, Lori Drew pleaded not guilty to charges that she violated federal fraud laws by creating a false identity “to torment, harass, humiliate and embarrass” another user, and by violating MySpace’s terms of service. But hardly anyone bothers to read terms of service, and millions create false identities.
  •  
    That the Internet is now capacious enough to host an entire subculture of users who enjoy undermining its founding values is yet another symptom of its phenomenal success. It may not be a bad thing that the least-mature users have built remote ghettos of anonymity where the malice is usually intramural. But how do we deal with cases like An Hero, epilepsy hacks and the possibility of real harm being inflicted on strangers?
1More

Solidot | Adobe Flash 零日攻击进行中 - 0 views

  • 恶意代码正在注入到总计约2万个网页的第三方网站,这类似以前的SQL注入攻击,这些网页被重新定向到有恶意Flash文件的站点。
1 - 7 of 7
Showing 20 items per page