![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#51 | |
Confirmed User
Join Date: Jan 2002
Posts: 2,025
|
Quote:
referal check?
__________________
LiveBucks / Privatefeeds - Giving you money since 1999 Up to 50% Commission! 25% Webmaster Referal Powered by Gamma |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#52 |
Confirmed User
Join Date: Feb 2002
Location: Toronto, ON
Posts: 962
|
Alright.. if someone knows of a module for pro_ftpd that allows you to run an executable after certain filetypes are uploaded (or for every upload), I will post a solution that strips warez from files as they are uploaded.
I'm still looking for a better solution, but this will solve 90% of the problem for most hosts.
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#53 |
Confirmed User
Join Date: Jan 2002
Location: Toronto
Posts: 1,227
|
there's no proftpd module, but there's another way to do it. You simply use "Custom Log" into some file which will record all filenames uploaded, and then run a routine script on it - thats atleast the way i do it
![]()
__________________
Alex - ICQ:61889253 - MSN:zubr_zubr at hotmail.com - Skype:zubrzubr |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#54 |
Confirmed User
Join Date: Apr 2002
Posts: 667
|
adultwire, could you just post the solution then we can figure out the best way to impliment it? monitor log files seems fine to me. maybe someone could offer a modified wuftpd or something... whatever.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#55 |
Confirmed User
Join Date: Jan 2002
Location: Toronto
Posts: 1,227
|
yeah, adultwire, what do you got there?
__________________
Alex - ICQ:61889253 - MSN:zubr_zubr at hotmail.com - Skype:zubrzubr |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#56 |
Confirmed User
Industry Role:
Join Date: Apr 2002
Posts: 231
|
interesting thread. detecting steganographic messages in images. does this help http://www.outguess.org/detection.php ?
cheers |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#58 | |
Confirmed User
Industry Role:
Join Date: Apr 2002
Posts: 231
|
Quote:
cheers |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#59 |
Confirmed User
Join Date: Jan 2002
Location: Toronto
Posts: 1,227
|
somebody has noticed here that they know what the http_user_agent values are for that software, but they didnt say exactly what
__________________
Alex - ICQ:61889253 - MSN:zubr_zubr at hotmail.com - Skype:zubrzubr |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#60 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Posts: 7,817
|
Hey, if anyone could contact me regarding a solution for this I'd appreciate it.
Email or ICQ works.. matt @ nysus.com or 129060301 Cheers, Matt |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#61 |
Confirmed User
Join Date: Nov 2001
Location: Glendale, AZ
Posts: 155
|
Hehe dork, of course they are hotlink protected.. the utility is its own web browser that downloads all the images.
__________________
Premium Tier1 Hosting/bandwidth $65/megabit: $.20/gig Way2Fast Hosting ICQ: 69658209, AIM: ProgGod123, Email: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#62 |
Confirmed User
Join Date: Feb 2002
Location: Toronto, ON
Posts: 962
|
Sorry.. I had to split for a while.. I have some work to finish, and then I'll post my make-shift solution.
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#63 | |
Confirmed User
Join Date: Jan 2002
Location: Toronto
Posts: 1,227
|
Quote:
![]()
__________________
Alex - ICQ:61889253 - MSN:zubr_zubr at hotmail.com - Skype:zubrzubr |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#64 |
Join The Royal Family
Join Date: Apr 2002
Posts: 25,463
|
yeah, I am glad people are willing to share ideas to stop cheaters. These warez guys are pretty hooked up. They upload many gigs in 1 night
__________________
Looking for a KICK ASS TEEN SPONSOR? Check out ROYAL CASH - THE KING OF TEEN!
Incredible webmaster tools FHGs, Morphing Blog and RSS Feeds, Embedded FLV & WMV Videos. With TOP RATIO Sites like ATMovs.com | iTeenVideo.com | TeenSexMovs.com | TeenSexMania.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#65 |
Confirmed User
Join Date: Feb 2002
Location: Toronto, ON
Posts: 962
|
Shitty.. my solution ended up causing problems with many images.. I think it's time to start coding. I just want to strip the warez in a non-lossy mannar (without changing a single byte of the valid image data) -- this requires parsing the file and rewriting the terminating block at the correct place.
Then I want to compare the filesizes, and if they differ substancially, throw away the file. If they don't, use the stripped one (to save b-width)..
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#66 | |
Confirmed User
Join Date: Aug 2001
Location: New York, NY
Posts: 131
|
Quote:
__________________
-- cat: .signature: No such file or directory |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#67 |
Confirmed User
Industry Role:
Join Date: Apr 2002
Posts: 231
|
could someone who has some of these files post links to a few more gifs and jpegs? I saw the one gif posted earlier. That gif seemed to be identifiable as not being a valid image.
cheers |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#68 |
Join The Royal Family
Join Date: Apr 2002
Posts: 25,463
|
http://www.greenapple.verisexy.net/wezgina/
http://www.greenapple.verisexy.net/salamba/ Are these the type of files you guys are talking about? Looks, so weird by the way they are names and no sponsors or anything =/ I will trying to find more and post them when I do so people can see examples.
__________________
Looking for a KICK ASS TEEN SPONSOR? Check out ROYAL CASH - THE KING OF TEEN!
Incredible webmaster tools FHGs, Morphing Blog and RSS Feeds, Embedded FLV & WMV Videos. With TOP RATIO Sites like ATMovs.com | iTeenVideo.com | TeenSexMovs.com | TeenSexMania.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#69 | |
Macdaddy coder
Industry Role:
Join Date: Feb 2002
Location: MacDaddy pimp coder
Posts: 2,806
|
Quote:
If you need a bit of help, let me know...
__________________
MacDaddy Coder. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#70 |
Registered User
Join Date: May 2002
Location: Sacramento, CA
Posts: 64
|
That looks exactly like a recent user on my freehost. Exactly. Different file names, and the pics were asian, but the "Welcome to xxxxxx's Web Site", followed by the centered line of small images. Deleted his account after reading this thread.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#71 |
Confirmed User
Join Date: Jan 2002
Location: Toronto
Posts: 1,227
|
why would they use host for warez in the first place? isnt it easier to just get it off kazaa?
__________________
Alex - ICQ:61889253 - MSN:zubr_zubr at hotmail.com - Skype:zubrzubr |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#72 |
Confirmed User
Join Date: Aug 2001
Location: New York, NY
Posts: 131
|
You can't move ZIPs and RARs around on KaZaA (i think), two, that would require someone volunteering to dedicate their bandwidth to little .jp punks downloading warez all day, haven't you ever heard of freeloading at someone else's cost?
__________________
-- cat: .signature: No such file or directory |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#73 | |
Confirmed User
Join Date: Aug 2001
Location: New York, NY
Posts: 131
|
Quote:
__________________
-- cat: .signature: No such file or directory |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#74 |
Registered User
Join Date: Feb 2001
Location: Rockville MD USA (with Mountain View, CA on my mind)
Posts: 62
|
AdultWire - proftpd can use mod_autorun to run a script after upload...
Warez in files - Yeah... I've been noticing these bad boys for a while... my gif/jpg detection scripts aren't able to nail em either, grumble grumble... Ahhh jesus.. freehosting just isn't as fun as it was back in 99 ;) -- kevin -- adultserver.com
__________________
-- Kevin |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#75 |
Confirmed User
Join Date: Feb 2002
Location: Toronto, ON
Posts: 962
|
Shit.. I'm in meetings all day today.. so again, not much time to work on this.. But if anyone knows how to code, I think GIF's should be relatively easy to do without losing any data. You need to read the header for the size of the image, and then unpack lzw blocks until you've filled up the bitmap area with data. Then, discard any remaining blocks and write a header.
At least, this should work for 87a's, but probably not 89a's. With jpeg's, if you don't mind a slightly lossy method, nconvert will do the trick. The whole shebang can be glued together with mod_autorun, and that should be a working solution. I hope I get some time this evening and maybe we can fill in the rest of the blanks.
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#76 | |
Confirmed User
Join Date: Jan 2002
Location: Toronto
Posts: 1,227
|
Quote:
__________________
Alex - ICQ:61889253 - MSN:zubr_zubr at hotmail.com - Skype:zubrzubr |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#77 | |
Confirmed User
Join Date: Apr 2002
Posts: 667
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#78 |
Confirmed User
Join Date: Feb 2002
Location: Toronto, ON
Posts: 962
|
mod_autorun is hardly resource consuming... I get what you're saying, but trust me when I tell you the load difference from this to a scheduled event will be negligable, and this solves the problem before it can become one.
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#79 | |
Registered User
Join Date: May 2002
Location: Sacramento, CA
Posts: 64
|
Quote:
Heh, hey kev you may want to change your signature line. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#80 | |
Registered User
Join Date: May 2002
Location: Sacramento, CA
Posts: 64
|
Quote:
Spanky, yes that helps a lot; thank you. All: As Spanky referenced, there is a utility called STEGDETECT that may help us out. I just downloaded it and did a preliminary test, with positive results. STEGDETECT tests if information has been embedded in files using jsteg/outguess/jphide/invisible secrets(wtf?)/F5/camouflage/or appendX. Here are my initial findings: STEGDETECT run on a normal JPG file that has not been embedded: [root@SERVER_3 munimuni]# stegdetect 11544r033.jpg 11544r033.jpg : negative STEGDETECT run on a JPG file that has been embedded [root@SERVER_3 munimuni]# stegdetect Kurumi01_3204.jpg Kurumi01_3204.jpg : jphide(***) appended(560)<[random][data][7|FG7.w.P=...x.J]> |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#81 | |
Confirmed User
Industry Role:
Join Date: Apr 2002
Posts: 231
|
Quote:
cheers |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#82 |
Confirmed User
Industry Role:
Join Date: Apr 2002
Posts: 231
|
helo, just a couple of thoughts about all of this.
It would seem like detection would be preferable to processing every file. The gif file that I got had an invalid header but it's probably safe to say that most do have valid headers. The gif licensing is pretty restrictive so processing every file may not even be an option. At a company I used to work for we decided not to compress gifs after we spoke to unisys about the licensing costs. Decompressing gifs is ok, compressing with unisys algorithms is not without a license. Couldn't the files be identified by establishing a 'normal' ratio of bytes/pixel for each file type and testing the abnormal bytes/pixel ratios of these warez files against this normal? So far it looks like the jpeg headers contain the height and width of the valid image data with the rest of the crap tagged on to the end. Let's that the r=b/(h*w) where r is our ratio, b is the number of bytes and h & w is the height and width reported in the header. I grabbed 5 of the files posted earlier: AGF2nd811.jpg 146618/(100 x 118) = 12.4252542372881 AGF2nd812.jpg 163365/(200 x 160) = 5.10515625 AGF2nd813.jpg 161336/(126 x 176) = 7.27525252525253 AGF2nd814.jpg 104842/(116 x 150) = 6.02540229885058 AGF2nd815.jpg 121379/(93 x 160) = 8.15719086021505 Compared with 5 (non warez) files reasonably compressed: minnkim-035.jpg 34981/(600 x 457) = 0.127574762946754 minnkim-036.jpg 35846/(600 x 457) = 0.13072939460248 minnkim-037.jpg 30728/(600 x 457) = 0.112064186725018 minnkim-138.jpg 46571/(457 x 600) = 0.169843180160467 The ratios of bytes/pixel are severely out of whack with these warez files. It would seem as though some c or asm code could read the headers of all new files on the system (either through hooking into ftp events or cron jobs on log files, doesn't really matter), compute the ratio of bytes per pixel, compare that against the normal and flag any abnormal ratios for delete or human examination. any thoughts or comments on this? cheers |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#83 |
Confirmed User
Join Date: Feb 2002
Location: Toronto, ON
Posts: 962
|
The problem arises with animated gif's (which could be any number of frames, and could also be severly out of wack based on the imagesize:filesize ratio)
All one really needs to do is get a piece of code that unpacks a gif -- unpack the gif, and see if there is more than a few bytes of trailing data. If there is, the file is warez. Most code that does this is written in C, and my C coding has become very rusty over the years.. haven't really done any hardcore coding of that nature since the 68000Assembly demo days on the Amiga.
__________________
SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#84 |
Confirmed User
Industry Role:
Join Date: Apr 2002
Posts: 231
|
unfortunately nobody has posted links to gifs other than the first one which was obviously not a gif so I haven't been able to look at any of these files as gifs. the bytes/pixel ratio should hold true for animated gifs by reading the framecount and dividing the total bytes by the number of frames reported r= (b/n)/(w*h) ... once again, I just have not seen any of the gif files though.
"All one really needs to do is get a piece of code that unpacks a gif -- unpack the gif, and see if there is more than a few bytes of trailing data. If there is, the file is warez. " I agree, this should work. Personally I am more interested in low impact detection so if anyone has some of these gifs could you let me know? cheers |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#85 |
Join The Royal Family
Join Date: Apr 2002
Posts: 25,463
|
Someone wanted a example of gifs. Here they are
http://www.greenapple.verisexy.net/t...bicross14.html
__________________
Looking for a KICK ASS TEEN SPONSOR? Check out ROYAL CASH - THE KING OF TEEN!
Incredible webmaster tools FHGs, Morphing Blog and RSS Feeds, Embedded FLV & WMV Videos. With TOP RATIO Sites like ATMovs.com | iTeenVideo.com | TeenSexMovs.com | TeenSexMania.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#86 |
Confirmed User
Industry Role:
Join Date: Apr 2002
Posts: 231
|
thanks, I grabbed a few and I'll take a peek. at first glance these gifs don't seem nearly as sophisticated as the jpegs, I wonder if it's the same program used to generate them both?
pretty clever really, they even include a checksum file. not as clever as it could be, but pretty clever. cheers |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#87 |
Confirmed User
Join Date: Sep 2001
Location: Boston
Posts: 4,873
|
if you ban .jp it will cut your warez problems down 70% :o)
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#88 |
Confirmed User
Join Date: Sep 2001
Location: Boston
Posts: 4,873
|
here is the code I wrote, put this in a script and run it at upload time it checks for correct start of GIF file and correct header and footer of a JPEG
it uses sysread to be more efficient instead of usual perl file shit # example - $pathfile = "/path/to/uploaded/file.gif"; if ($pathfile =~ /.gif$/gi) { open (TEST,"<$pathfile"); sysread (TEST,$check_header,4); close (TEST); $header = "GIF8"; unlink ("$pathfile") if ($check_header ne "$header"); } elsif ($pathfile =~ /.jpg$/gi) { open (TEST,"<$pathfile"); sysread (TEST,$check_header,4); sysseek (TEST,-2,2); sysread (TEST,$check_footer,2); close (TEST); $header = "ÿØÿà"; $footer = "ÿÙ"; unlink ("$pathfile") if ($check_header ne "$header"); unlink ("$pathfile") if ($check_footer ne "$footer"); } don't diss da jungle |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#89 |
Join The Royal Family
Join Date: Apr 2002
Posts: 25,463
|
![]() Ok, heres some warez file names that I found on the server. Please share them =) Wait till traffic builds up and then delete the files and send the warez downloaders to popup hell.
*AGF1* *AGF2* *AGF3* *AGF4* *0425_do* *kyohaku* *elfan* *wind_disc* *eroken* *dojin* *ouma_disk* *nsmdvd* *kuraemon* *mikoava* *kango* *zeroone* *ayu* *BB1WA* *sp10* *arisapv* *ign0* *ign1* *ign2* *ign3* *ign4* *minid* *kiwoku* *cubicross* *afgan* *megami0* *megami1* *megami2* *ove0* *ove1* *ove2* *ove3* *ove4* *IBM0* *eva0* *ds1* *ds2* *kojin*
__________________
Looking for a KICK ASS TEEN SPONSOR? Check out ROYAL CASH - THE KING OF TEEN!
Incredible webmaster tools FHGs, Morphing Blog and RSS Feeds, Embedded FLV & WMV Videos. With TOP RATIO Sites like ATMovs.com | iTeenVideo.com | TeenSexMovs.com | TeenSexMania.com |
![]() |
![]() ![]() ![]() ![]() ![]() |