MySpace Private Pictures Leak 405
Martin writes "We all heard about the MySpace vulnerability that allowed everyone to access pictures that have been set to private at MySpace. That vulnerability got closed down pretty fast. Unfortunately though (for MySpace) someone did use an automated script to run over 44,000 profiles that downloaded all private pictures which resulted in a 17 Gigabyte zip file with more than 560,000 pictures. The zip file is now showing up on popular torrent sites across the net."
You know what to do... (Score:5, Informative)
fetch! [thepiratebay.org]
Re:You know what to do... (Score:5, Informative)
Re:Anyone know what the vulnerability was? (Score:3, Informative)
- The URI for the pics are based on a timestamp ... a combination of the above
- The URI for the pics are based on a sequential number
-
- The pics are not access-controlled in any other way than not being listed on a user's page
The hack was discovered when a user cut and pasted the URI of one of his private pictures, noticed one of the above and attempted to change a digit of the URI, then automated the process with a garden variety for() loop.
Crappy analogy: Even unlisted telephone numbers can be discovered by telemarketing wardialers.
Re:You know what to do... (Score:3, Informative)
Most other dogs attempt to fetch no matter what you throw: sticks that are obviously too heavy to fetch, snowballs, small objects which you only pretend to throw but actually hide inside your sleeve...
Lotsa phun...
Re:It bears repeating: (Score:2, Informative)
2) Money put in the bank is physically guarded. A robber would have to put life and limb on the line to get at it.
3) You can't identify me or anything about me from my money. Its just a pile of green paper.
NOTHING online is insured. And the hackers on steroids from Ebaumsworld are anonymous, so there's pretty much no risk to them haxing your shit.
Link at Pirate Bay (Score:1, Informative)
http://thepiratebay.org/tor/3985864/%5Btribalwar.com%5D_567_000_private_myspace_pictures [thepiratebay.org]
Re:Trap! (Score:3, Informative)
Re:Trap! (Score:4, Informative)
Archiving != compression (Score:3, Informative)
2) You can use zip with no compression for plain archiving
3) Since tar isn't that popular on Winblows it's pretty natural to use zip instead
There are plenty of benefits to using an archive
1) integrity checks
2) directory structures
3) single file vs thousands
etc
Re:Trap! (Score:5, Informative)
Re:A 17Gb zip??? (Score:3, Informative)
0.zip, 1.zip, 2.zip, 3.zip, 4.zip, 5.zip, 6.zip, 7.zip, 8.zip, 9.zip, a.zip, b.zip, c.zip, d.zip, e.zip, f.zip - The pictures, or so it seems. Haven't downloaded the pictures, yet. Each zip is ~1GB.
html.zip contains html files that link, supposedly, to the original pictures. It's ~30MB.
Out of sheer curiosity, I viewed the source of a couple of the html files - wanted to see if they contained any friendID's or anything else that could link the pics to the user.
The links do not contain a friendID or anything else that would tie the picture back to the user. Unless, of course, there is a rainbow table floating around that contains the hashes of the pics and the associated friendID's?
The html files, however, do contain FriendFinder spam. (iFrame, of course. pid=g872417-pmem, if anyone cares.)
Sorta stoopid, if you think about it. All the authorities would have to do, if they are interested, is contact FriendFinder (or the parent company[1]), and get the contact details for the affiliate.
Anywho. I hope this answers the size comment. I'm sure every prevert from here to China is part of the torrent's swarm.
[1] I don't know if FriendFinder is an indy company or owned by someone else. I don't even care enough to visit the site. Sorry. I'm tired and I've got a toothache.
I've looked. Yaaaaawn. (Score:5, Informative)
So far out of 4500 images, I found exactly zero images that I think anyone would give a crap about. I'm not even sure why the vast majority of them are even bothered marking private; nobody would care about them at all.
Static Content Server (Score:4, Informative)
When not working or browsing Slashdot, a friend and I will exchange URLs to profile pics of "interesting" looking women. If the profile is private, the URL to the private JPG is not protected and we would exchange those instead. I haven't spent any time trying to find a pattern in the seemingly-random JPG names, so it appears difficult to pull the private images of any one person, but in general everyone's pics are available if you know the URL.
Re:You know what to do... (Score:2, Informative)
Re:Trap! (Score:3, Informative)
Re:Dueling compression algorithms (Score:5, Informative)
Sure there is. Ignoring the way BitTorrent actually encodes the information, and assuming that somehow every file name could be stored as one byte (ignoring the obvious flaw with that), by keeping all of them at the torrent level you'd require "more than 560,000" bytes just devoted to file names. Since the general rule of thumb is to keep the actual .torrent file around 100KB, give or take, that's right out.
Now, throwing in the way the .torrent file actually stores the list of file names, you're looking at at least 21 bytes per file. Assuming 560,000 files, that bloats the .torrent file to over 11.2MB - and that's still not realistic, because it requires every file to be less than 10 bytes in size and all of them to have empty path names. (Which is obviously not valid.)
Throw in realistic constraints, and you're adding another 15 bytes, bringing us to a total of 36 bytes per file - bloating the .torrent to 19.2MB, just for file names.
So, in short, the reason to place them in a ZIP file and not use the multi-file feature is because using the multiple file feature would massively bloat the .torrent file. Now the final .ZIP file has similar requirements per file in the ZIP file, but that becomes payload as part of the BitTorrent download and not something that has to be downloaded via non-BitTorrent means first.
Finally, for an explanation of where those numbers above come from, the "smallest possible" form for a file would be:
"d6:lengthi0e4:pathlee" (21 bytes)
The "more realistic constraints" brings that to:
"d6:lengthi100000e4:pathl8:0000.JPGee" (36 bytes)
Yes, the .torrent file is essentially "plain text" although the piece hashes are stored as binary strings. It's encoded using "Bencoding [wikipedia.org]" - which isn't the most compact of formats.
Submitter should RTFA, bug was known for months (Score:5, Informative)
No it didn't. MySpace let this thing go on for months. From TFA:
The irony (and scandal) is that they not only failed to uphold their privacy policy despite being in the public spotlight over the last 2 years precisely for privacy issues, but that they didn't bother to acknowledge or fix this bug until a high traffic site reported on it.
Re:Dueling compression algorithms (Score:2, Informative)
Re:Trap! (Score:1, Informative)
Re:Trap! (Score:1, Informative)
Re:Trap! (Score:4, Informative)
Forgive me, but I didn't want to google child porn at work.
Re:I've looked. Yaaaaawn. (Score:1, Informative)
Re:Dueling compression algorithms (Score:3, Informative)
This is why if you download a single file out of a torrent, you will often get a certain percentage of the previous and following files completed even though you never checked them for download: the edges of the pieces weren't aligned with the file boundaries. If you uncheck, say, a "downloaded from foo" txt file, more often than not you'll get it anyway (the client stores the file anyway because it needs to store that portion of the block to be able to upload it to peers, since blocks are sent as full units).
The
Review of Part 1 (1GB out of 17) (Score:1, Informative)
approximately 5000 photos
70% - make you wish Kodak didn't bring photography to the masses
45% - angsty emo poses
25% - alcohol-related potentially embarassing photos (if you knew who these people actually were)
0.5% - nudity (one topless woman, several artistic nudes, a few pregnant women)
2% - people showing off bruises or injuries
30% - pets
1 - fetal ultrasound
4% - people sleeping
7% - anime, cartoons, photoshopped artwork
10% - cars
(Sum exceeds 100% because of pics like the shirtless drunken emo guy with his puppy)
Lesson: If you want scandalous amateurs, go to xtube.
(That won't stop me from getting the rest of the torrent and seeding till you get your fill, though!)