Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Thursday, December 16, 2010

Revving Chrome for a Cause

Google's launched this great initiative/Chrome extension called "Chrome for a Cause," where for every tab opened (up to 250 tabs/day) Google will contribute towards charity. You can download the extension here:

http://www.google.com/chrome/intl/en/p/cause/

Now let's say you're in the mood to speedily log 250 tabs open, but your Ctrl+T muscles are sore. Several code solutions have popped up, including a full-on Chrome extension which automates the process.

My question: why can't this run in Javascript?

My response: Chrome for a Cause Fastest bookmarklet

Here's the code:
javascript:i=260;function addTab(){if(--i==0){clearInterval(j)}x=window.open('');x.close()}j=setInterval('addTab()',1000);void(0);

Just let it run for ~5 minutes, and you're done. You've helped provide a year's supply of clean drinking water for someone on earth.

Saturday, January 30, 2010

iPads for Obama!

It's the latest trend in the world of online scammers. Someone makes a group on Facebook promising free merchandise/hidden Facebook features/true love if you join and invite all your friends. Of course, these pages restrict viewing of their Walls, so people must join before they find out that it's fake.

The second step is to connect some external website to the Facebook group, which you must visit after you join and invite everyone you know to the group. This web page is where the group creators may collect usernames/passwords with a fake Facebook authentication page, or collect names and addresses, or even credit card info. Whatever their motives, the group spreads too fast for the original adopters to warn those they've already invited about the site. And so, like a virus, the group grows and spreads.

Earlier today, I saw on my Facebook wall that someone I vaguely knew had joined a group entitled "Get a FREE Apple iPad Test Unit!" The group followed the usual procedure of adding all your friends and clicking a link. This time, however, I was curious. Without joining or spamming my friends, I clicked the link. I was greeted with this friendly page:

http://cpalead.com/adblock.php

As a rule, any site douche-y enough to restrict access based on an add-on doesn't really deserve your attention anyway. Still I pressed on. I discovered that cpalead.com (which is completely blocked by the EasyListUSA subscription list in Adblock Plus) was noticing that I was restricting the execution of its stuff and therefore redirected me from the original page to let me know that I was a bad person.

After fishing around for a few minutes, I discovered what .js file on cpalead.com was causing the matter and exempted it from screening. The site then loaded, Adblock Plus filter ignored.

That filter, for those of you who may encounter this in the future, is:
@@|*cpalead.com/mygateway.php?* UPDATE: This code wasn't covering all cases, so I had to tweak it. Use the current version.

---------

After finally accessing the web page, I was greeting with a page-covering DIV and a notice which said that I had to fill out a survey before I could enter my info, "to verify that I'm not a bot". Back on the Facebook group page, they did apologize for the system, but all I can think is, why not be like EVERY OTHER website and use, oh, I don't know, a CAPTCHA? I looked int he lower-left corner of the giveaway page, where a "HACKER-PROOF" logo made the non-https site look very secure. HACKER-PROOF? We'll see about that.

At first, I tried removing the div and just accessing the form directly. That triggered some hidden JS file and promptly warned that I had been "reported" for trying to "hack" the site. Excuse me, but editing local HTML source code for a loaded web page is NOT hacking. I could go on my YouTube channel page and locally edit the HTML to make it look like I have 9001 subscribers. That's still not hacking, because if I refresh, my hard work is gone. Still, at this point I didn't feel like bothering with the annoying .js file, so I decided to do as I was told.

I BS'd my way through one of their dumb surveys (which then started spamming me with product requests, so I'm glad I did not put a real email address. Unless "wmnbd1@a0l.com" is a real address, in which case, please forgive me.) Thankfully, the giveaway page at this point removed the blocking DIV, allowing me to submit my details in order to (potentially) receive a FREE iPad!

But then I noticed something. The form was in a frame. And I could load the frame in my browser independantly of the main giveaway page. And the frame was just the relevant form field which submitted my info, nothing more, especially no hidden JS files.

So wait a minute. I have to "disable" Adblock, not tamper with the HTML source code, and take a spam survey designed to steal my details, but you don't even bother to put security on the actual FORM?

For those of you not familiar with how these kinds of security measures interact, it's kinda like this:



So now I have unrestricted access to the form. The thing is totally unsecured. Hell, I could probably just re-send this form over and over--

It doesn't take long for me to complete a simple form submission page which uses GET variables from the URL to choose the name, address, and email you'd like to submit, and automatically on page load submits the form for you. Embed the form page half a dozen times on another page, set an auto-refresh system up on the meta-form page, and you've got a submission system.

Now all you need is a name, an address, and an email.

At this point, I think back to the State of the Union on Wednesday. Obama had said that "our economic growth increasingly depends on our ability to sell American goods and crops and services all over the world." Perhaps, then, Obama would know of some good places to put to use a few hundred iPads?

Name: Barack Obama
Address: 1600 Pennsylvania Avenue
Email: potus@whitehouse.gov (I doubt this is a real email address, but it sounded cool.)

I let the program run for around fifteen minutes, watching the giveaway's "Thank you!" page for successful submissions appear briefly before each refresh. So much for "hacker-proof".

------------------

I come back after a little while and notice that something had changed on my little form submitter: the "Thank you!" pages now read "403 Forbidden".

I had submitted at most 300 forms in that time-span. Surely that wasn't enough to take down the website in that time.

I did a little checking and discovered that the website was still online, but the owners had clumsily restricted the main directory, completely destroying the website's layout.

So what have I done? I've broken a scammer website, and I've requested 300 iPads for the President of the United States. That's a good day in my book.

-----------

UPDATE (2/21/10):
Their site's up and seems to have been back up for a while now. However, they have yet to fix the frame issue. Go figure. Also, as you'll note above, I fixed an issue in the ABP code to work around the ABP-blocker.

Monday, March 23, 2009

Node 3 Poll Final Tallies

According to AP, Colbert won the Node 3 naming contest. They say that Colbert shut out Serenity by over 40000 votes.

Let's take a look at the real numbers in play here. We'll be using this page's poll results and source code.

In total, 1190437 votes were cast in the poll. If you enter in the address bar

javascript:alert(document.getElementById( 'hiddenTotalVotes' ).value)

you'll see how many votes were cast for one of the four given options. I see that value as 265594. If 265594 votes were cast for the given options, then the remaining 924843 votes were for write-in suggestions.

Now Serenity received 70% of the given votes, or 185916 votes. If Colbert beat Serenity by 40000 votes, then Colbert had about 226000 votes.

How do those numbers stack up? Well, if you do an actual poll, Serenity received 15.6% of the vote, and Colbert received 19%.

At least it's now over until NASA announces their choice in April.

EDIT: Somehow, I missed the part of the AP release stating that Colbert got 230539 votes. OK, I wasn't too far off.

Saturday, March 14, 2009

Don't Hack the Vote.

It's been pointed out to me by one of the only people ever to actually read this blog that cheating is bad. This is true. However, it's quite clear that NASA isn't taking the poll very seriously either. If you read the Contest Rules, it becomes clear that NASA has included enough escape clauses to prevent any part of any NASA spacecraft from ever being named "Colbert," "Xenu," "Myyearbook," or anything else the public dreams up. NASA is not totally stupid, and is well aware of the legions of people who could destroy their polling system by brute force alone if necessary.

Still, I'd like to add that wonderful protection clause, in case NASA doesn't like what I've done:

THIS INFORMATION IS FOR EDUCATIONAL PURPOSES ONLY. Please don't actively try to ruin or tamper with the poll.

Hmm, I feel better. Cool.

conscience++;

Friday, March 13, 2009

Hack the vote: In-the-Moment Running Vote Tallies

It turns out the Javascript running the vote results' frame on NASA's site is flawed too.

Open the frame in its own page (or just click here) and open up the page's source code. Scroll about a quarter of the way through, and you'll see some lines of code which look like this:


var totalNumVotes = eval(totalOpinioVotes)+eval(totalCommentsCount) ;
document.getElementById('totalNumVotes').innerHTML = totalNumVotes + totalVotesText ;


If you play around a little bit in the Javascript, you'll discover that "totalOpinioVotes" is the number of votes for one of the given choices (Earthrise, Legacy, Serenity, Venture), and "totalCommentsCount" is the number of votes for a write-in suggestion. These numbers are great, but they're a little hard to find. To solve this, scroll a little farther down the page, and you'll see a link to http://polls.nasa.gov/opinio/ps?s=2253. If the page loads correctly in your browser (which won't be particularly happy, just so you know), you'll see a low-quality version of the poll and two boxes containing the two vote counts in the hundred thousands.

As I make this post, the numbers stand as 176257 votes for givens and 387731 votes for write-ins.

You know how NASA is setting up the poll so it looks like Serenity is way out in front with 3/4ths of the vote? It's almost certainly not. Serenity has 75% of 176257 or about 132193 votes. A write-in suggestion can beat that with 35% of the write-in votes.

-------------

A side note: I talked to Dr. Tyson this evening, and I asked him about the Node 3 effort. He responded by saying that he wished Colbert would mobilize his viewers more productively, like to lobby Congress for increased NASA funding.

[Disclaimer: THIS INFORMATION IS FOR EDUCATIONAL PURPOSES ONLY. Please don't actively try to ruin or tamper with the poll.]

Thursday, March 12, 2009

Colbert Bump Bot

I ended up building an Applescript which will vote for Colbert once every two seconds. Behold, the Colbert Bump Bot:

repeat
tell application "Safari"
activate
do JavaScript "window.location = 'http://comments-submit.nasa.gov/commenting1/Comment.do?location=http://polls.nasa.gov/voteform.html&siteID=245486071&username=guest&email=guest@dummy.com&comment=Colbert'" in document 1
delay 1
activate
do JavaScript "document.frmcomments.submit();" in document 1
delay 1
end tell
end repeat


Note that it will bring Safari into window focus every second, so don't plan on working while this is running.

[Disclaimer: THIS INFORMATION IS FOR EDUCATIONAL PURPOSES ONLY. Please don't actively try to ruin or tamper with the poll.]

Wednesday, March 11, 2009

Colbert vs. Xenu

It's been a long time since I've posted (spring break is soon, so there should be a flood of posts), but I just wanted to add my two bits to a current hot topic: Colbert vs. Xenu.

It all began when NASA decided that it was going to open up voting to the public for choosing the name of Node 3 on the ISS. Many /b/tards and wanna-/b/tards caught hold of this, and XENU quickly rose tot he top of the list of Top 10 Suggestions.

On March 3, 2009, Stephen Colbert said this on his show:

Link (click it now)

Then, on March 4:

Link (click this one too)

Later that day, Anonymous responded:



And so the battle begins. Personally, I support Colbert, but only because I feel like I'd rather have someone win for a humorous purpose than for a humorous purpose at others' expense. (Remember, even though I hate the Co$, the people still inside the Co$ could easily be hurt by this.)

Regardless of what you support, there is an easier way to vote. Apparently NASA didn't think too hard about the voting system, as it seems to simply be a form which sends a string to a server.

I'm going to set this up for Colbert. If you're a die-hard fan of Xenu, you're probably tech-savvy enough to replace the name of a faux-conservative talk show host with that of an intergalactic overlord.

The key link is here:

http://comments-submit.nasa.gov/commenting1/Comment.do?location=http://polls.nasa.gov/voteform.html&siteID=245486071&username=guest&email=guest@dummy.com&comment=Colbert

After you type in your suggestion for Node 3's name on NASA's website, this box is what pops up, with a word verification CAPTCHA.

Unfortunately, someone made a rather large mistake when they put together the voting form, because it turns out that the CAPTCHA can be by-passed.

If you open up the vote verification page's source code, you see that the variables in the URL are actually part of a form document named "document.frmcomments". If you know some Javascript, you should find it rather easy to follow the source code and discover that the submission process of the form is only based on the passing of an "if" clause.


if (data==1) {
document.getElementById("imageResp").innerHTML="Word Verification Matched.";
alert ("Word Verification Matched. Comment Submitted");
document.frmcomments.submit();

}


The NASA programmer behind this voting program forgot to install a second verification that the user actually entered the CAPTCHA! Therefore, we can skip entering the CAPTCHA over and over again, and simply enter the following code into the address bar:

javascript:document.frmcomments.submit();

We can verify that it accepted this code two ways: one, it didn't bounce an error message (as it does when you simply click the SUBMIT button), and two, it brought us to the URL which it brings you to after you complete the word verification normally.

[Disclaimer: THIS INFORMATION IS FOR EDUCATIONAL PURPOSES ONLY. Please don't actively try to ruin or tamper with the poll.]

Monday, November 10, 2008

Hacking in SoHo

I went to SoHo yesterday, and lucky for me, it was a beautiful day, and almost no one was out. I stopped in one of the many furniture design stores in the area, and noticed that they had numerous computers set up to allow the customer to view more merchandise. I wanted to check something on Google, but they had set up strict parental controls.

Let the fun begin. Fortunately, the store, looking for the more upscale look, used Macs for the info consoles. It's harder to block certain actions on a Mac, so after a little experimentation, I found that the Command+Click system had not been deactivated. A few clicks, and I was on the desktop. From there, I was able to open up Time & Date, navigate back to System Preferences (many of the normal routes were blocked), and deactivate a few blockers. Then, back on the desktop, I made a new file, and started to rename it to http://www.google.com...

..when an attendant started walking over. I quickyl went back to the screen, pretended to ponder the merchandise for a few minutes, then walked out.

I had, however, left them a little present: I changed the display's sleep settings, so it goes to one of Apple's nice screensavers every 5 minutes. After all, what's a hack without a signature?

Friday, October 31, 2008

Owning Freewebs

My "homepage" is set up on Freewebs, mainly because I'm too lazy and cheap awesome to pay for a real website. However, free websites have their disadvantages: in Freewebs' case, all of my pages have to have a Freewebs promotion on the bottom.

That is, until now. I tired of the banners on the pages, and have managed to disable them. Yay! Here's what I did:

1. In my source code, I located the .js file which defines the banner.
2. I opened the .js file, and copied the text.
3. I created a new page on my site which I called "strechtest.js" and pasted in the code.
4. Then I altered the new .js file, by setting all widths and heights to 0 pixels.
5. Finally, I edited all of my pages to refer to my .js for the banner instead of Freewebs'.

It works! Check it out!

In case you want to do something similar for your Freewebs account, feel free to copy my .js alteration. Access it here:

http://www.freewebs.com/scikidus/strechtest.js

Tuesday, October 28, 2008

An Unorthodox Proxy

Proxies are a pain, mainly because a lot of websites block proxies, too. Here's a system I developed for bypassing restrictions imposed by the webmaster overlord near you.

1. Search for "source code viewer" on Google. Open a few of the first few links, as sometimes one of the sites won't work. I normally use this site.

2. Search for "HTML test bed" on Google. The first result works very well for what we are going to do.

3. In the source code viewer website(s), enter the address of the website you wish to view. When the source code of that website comes up, select the entire source code and copy it.

4. Now go to the HTML test bed, remove anything default text that might be in it, and paste the source code.

5. Hit the "test" button, and enjoy the website! (Note: Links will most likely not work, but will probably sitll show up, so you can copy and alter appropriately to render the next page.)

An explanation: this really is a very simple way to do things. HTML Source code is the code that defines the layout and content of a web page. You have two websites open: ones that fetches the source code for you, the other that displays the site for which the source code codes. And because external websites are the only ones interacting with the forbidden webpage, you can view the web page unhassled.

P.S. It is possible that the webmasters near you are rather clever, and so have blocked not only by URL, but also media content like images. The way around this requires the addition of another website: thumbalizr, which takes a snapshot of what the page looks like and brings it to you. Besure if you take this route that you click "page" instead of "screen"; otherwise, you only get a part of the page.

-----

Hmm, maybe it would be good to set this kind of thing up as a website. *idea*

Saturday, October 4, 2008

Internal Recording

I dislike torrents, mainly because I'm impatient. I mean, they're great for things like games, but when I just want to listen to some Bob Dylan, it's ineffective.

I little while back I find a website called GrooveShark, which allows me to listen to a huge collection of mainstream music for free. From online, that is. downloads are 99 cents a pop.

I was rather bummed out until I read about and straightened out a nice little solution to this problem. Basically, I set up a simple internal recording system for my Mac (sorry, PC users, I haven't figured out the Windows equivalent for this).

Here's what you'll need:
1. GrooveShark, open (don't bother to download the free listening software unless yu have a really slow connection; just stream it from your browser)

2. Audacity: if you don't have this, get it. It's a wonderful (free) audio-editing app.

3. SoundFlower: this is the essential piece. If you can't get this, just go back to your torrents. An it's free, too.

That's it. Now you've got to configure.

1. Launch Audacity. Under Preferences, click "Recording" and set the Input to "SoundFlower (2 channels)."

2. Launch System Preferences-->Sound. Under "Sound Effects," make sure that the box labelled "Play user interface sound effects" is unchecked. Under "Output" and "Input," set "Soundflower (2 channels)" as the device.

3. In Audacity, click "Record."

4. Launch GrooveShark in your browser of choice. Play whatever songs you want.

5. When the songs finish, in Audacity click "Stop."

6. Sleect the parts of the audio that make up the sons, and click File-->"Export Selection to MP3..."

7. Fill in the asked-for data, export, and open the mp3 files in iTunes. Tada!

Note: This system is known as internal recording, because SoundFlower is acting as a virtual sound card and redirecting the outbound audio back in as input. In other words, you can record in this manner anything that comes out of your speakers.

If you can figure this out on a PC, let me know!

DISCLAIMER: Do not use this system to illegally steal music and distribute it. This is for educational purposes only. Also, be aware that copyrighted music streamed and saved in this manner can be used only for "personal use only."