|
|
10-08-2009, 09:51 PM
|
#1 (permalink)
|
Join Date: Mar 2009
Posts: 830
|
Security Warning (CSS Hack)
It has come to our attention that certain trackers, including x264, are utilizing an internet browser exploit to identify and ban TI members. The vulnerability is caused by some browsers' implementation of Cascading Style Sheets (CSS). This allows trackers to query your computer and identify which sites you belong to, including Torrent-Invites.com.
Is your computer vulnerable?
CSS Hack Test (without JavaScript)
CSS Hack Test (with JavaScript)
What can you do to protect yourself?
OPTION 1 - Disable CSS Visited Links [Firefox Only] - Type "about:config" in the address bar
- Type "layout.css.visited_links_enabled" in the filter list
- Change the default value of "True" to "False" by double clicking it
- Restart Firefox
OPTION 2 - Disable Browser History [Firefox Only] - Tools --> Clear Recent History
- Tools --> Options --> uncheck "Remember my browsing history"
OPTION 3 - Use a Different Browser for TI - e.g. Use Firefox for TI and Internet Explorer for Trackers
OPTION 4 - Temporarily Enable Private Browsing - [Firefox 3.5] Tools --> Start Private Browsing
- [IE 8] Tools --> InPrivate Browsing
- [Chrome] Press Ctrl+Shift+N (Incognito)
- [Safari] Safari --> Private Browsing
- [Opera] Does NOT have a Private Browsing option.
NOTE: You will need re-enable Private Browsing each time you start the browser.
Additional Information:
CSS History Probing Explained
Sniff Browser History Tutorial
BrowserSpy Test Site
StartPanicking Test Site
UPDATES [October 10th]
UPDATE 1 - HistoryBlock & NoScript Add-ons - NoScript only works with JavaScript based exploits
- HistoryBlock does not work if you browse both sites at the same time*
*HistoryBlock utilizes the tab closed & download complete addEventListeners to initiate a history wipe. That leaves you exposed if you have both sites open in separate tabs at the same time or open TI from the same tab without going to an intermediate page first.
UPDATE 2 - Disabling Browser History - Does not work in IE
- Does not work in Opera
- Does not work in Safari
*Disabling history only works properly in Firefox.
Last edited by Vegas; 11-16-2009 at 06:46 AM.
Reason: Updates
|
|
|
|
|
The Following 55 Users Say Thank You to Vegas For This Useful Post:
|
Ammit, Beepin, buckyshort, Dan, dog2, Dorian, Dozer1979, DudeOnFire, duskasher, fahim, FileshareFreak, flutrose, gotsome, hi-jack, ichoshea, Incognito, James3kgtVR4, JaySean, Josh, JustJenna, liburator, MaaNYaN, Manchis, medschool, MikeD, MrInternet, neurowiz, OkIwont, olomon, paragon, poasd25, Pony, princest.zelda, Rawagan, rawr, Reducto, Remore, scoobydoo, Signus, SilverSurfer, smtsh, snurferst, Spunky787, Sraosha, staffrodore, Stellar, ston3d, Thirion, toptorrent, Veritas, WEiCH, wheeler66, whome?, wow123, YouNeverKnow |
10-08-2009, 10:15 PM
|
#2 (permalink)
|
Join Date: Aug 2009
Location: T-I Blvd.
Posts: 415
|
What about the chrome users ?
I guess deleting browsing history will work here too. Correct me if I am wrong.
|
|
|
|
10-08-2009, 10:20 PM
|
#3 (permalink)
|
Join Date: Jun 2009
Posts: 373
|
I like having my history, so i now use noscript, hope i will not get banned for using it !!
Thanks for the tip tough, highly appreciated.
|
|
|
|
10-08-2009, 10:29 PM
|
#4 (permalink)
|
Join Date: Aug 2009
Posts: 71
|
wudnt using one browser of T-I and another for trackers solve this prob...my guess is this might work 100%....with this users can keep their browse history without any fear of others finding out where else we r members of.
just my thots...dont know if it works this way
|
|
|
|
10-08-2009, 10:30 PM
|
#5 (permalink)
|
Join Date: Mar 2009
Posts: 830
|
Quote:
Originally Posted by bmwxl33
What about the chrome users ?
I guess deleting browsing history will work here too. Correct me if I am wrong.
|
Disabling history ONLY works properly in Firefox..
Quote:
Originally Posted by MaaNYaN
wudnt using one browser of T-I and another for trackers solve this prob...
|
Yes, a separate browser for trackers will also work.
Last edited by Vegas; 10-11-2009 at 12:07 PM.
Reason: Updated disabling browser history response.
|
|
|
|
|
The Following User Says Thank You to Vegas For This Useful Post:
|
|
10-08-2009, 11:24 PM
|
#6 (permalink)
|
Join Date: May 2009
Location: Australia
Posts: 1,036
|
So they have moved up to banning T-I members with this now. Trackers such as GFT (I think) have been using this method to detect cheaters from forums such as SB-I for a while... bit of a shame they're using it on us now. Maybe it's becoming well known.
__________________
A mythical creature hunted since the beginning of time. Some say he is just a legend, others believe he is an immortal living among us. His face seen only by those whose lives he has spared. He is hunted by the governments of this world for bringing upon them death and destruction! Part human, part god, he is The Exalted!
Dark Angel - Fading memories of the past
looking for ____{f*n}____
|
|
|
|
10-08-2009, 11:40 PM
|
#7 (permalink)
|
Join Date: Aug 2009
Posts: 320
|
If you are using mozilla:
First of all, open your history tabs, delete all with keyword torrent-invites.com.
Then install below plugin :
History Blocker
Add *.torrent-invites.com as your blacklist.
Now you can use browser freely, together with history feature. No worries.
Ive tested it. Works wonderfully.
I hope I'm helping out.
Cheers.
__________________
My big THANKS to: Pascualito, goover, konVILEeuted, smtsh, Knievel and The-Deh
|
|
|
|
|
The Following 17 Users Say Thank You to princest.zelda For This Useful Post:
|
buckyshort, fahim, Incognito, JustJenna, kevodgg, Maksimir, neurowiz, OkIwont, pagan, s2cuts, SimonSays, smtsh, snurferst, ston3d, TeraBytes, Vegas, VladTheRipper |
10-09-2009, 12:46 AM
|
#8 (permalink)
|
Join Date: Aug 2009
Location: *cough* Demonoid
Posts: 226
|
Those big private trackers are such meanies :(
...lets DDOS them :D
lol
But seriously: Download noscript set it to global whitelist in settings and find the blacklist exceptions and copy and paste all the URLs of every private tracker you belong too into that blacklist.
I have always found noscript to be a pain in the arse because it blocks everything under the sun under its default global blacklist. Change it to global whitelist so flash and other user friendly stuff isn't killed in the process and block your tracker URLs.
Last edited by wtfmate; 10-09-2009 at 12:57 AM.
|
|
|
|
10-09-2009, 01:31 AM
|
#9 (permalink)
|
Join Date: May 2009
Location: Im in your Closet!
Posts: 489
|
x264 sucks anyway, so it really dont matter either way.
Oh and its only a matter of time before more trackers catch up.
|
|
|
|
10-09-2009, 01:55 AM
|
#10 (permalink)
|
Join Date: Jul 2009
Posts: 100
|
This vulnerability that allows trackers to query my computer and identify which sites I belong to works only with Browser History or it also checks my cookies ?
Should I delete all my saved cookies ?
|
|
|
|
|
|