Loading...
  Lost your password? Lost your Username? Make a new account!  
Torrent Invites! Get your free private torrent tracker invites !
Forum  
Old 10-08-2009, 09:51 PM   11 links from elsewhere to this Post. Click to view. #1 (permalink)
Vegas
Super Moderator
 
Vegas's Avatar
 

Join Date: Mar 2009
Posts: 830
Vegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond repute
iGiver: (122)
Vegas is offline
Default Security Warning (CSS Hack)

It has come to our attention that certain trackers, including x264, are utilizing an internet browser exploit to identify and ban TI members. The vulnerability is caused by some browsers' implementation of Cascading Style Sheets (CSS). This allows trackers to query your computer and identify which sites you belong to, including Torrent-Invites.com.


Is your computer vulnerable?

CSS Hack Test (without JavaScript)

CSS Hack Test (with JavaScript)


What can you do to protect yourself?


OPTION 1 - Disable CSS Visited Links [Firefox Only]
  • Type "about:config" in the address bar
  • Type "layout.css.visited_links_enabled" in the filter list
  • Change the default value of "True" to "False" by double clicking it
  • Restart Firefox
OPTION 2 - Disable Browser History [Firefox Only]
  • Tools --> Clear Recent History
  • Tools --> Options --> uncheck "Remember my browsing history"
OPTION 3 - Use a Different Browser for TI
  • e.g. Use Firefox for TI and Internet Explorer for Trackers
OPTION 4 - Temporarily Enable Private Browsing
  • [Firefox 3.5] Tools --> Start Private Browsing
  • [IE 8] Tools --> InPrivate Browsing
  • [Chrome] Press Ctrl+Shift+N (Incognito)
  • [Safari] Safari --> Private Browsing
  • [Opera] Does NOT have a Private Browsing option.
NOTE: You will need re-enable Private Browsing each time you start the browser.


Additional Information:
CSS History Probing Explained
Sniff Browser History Tutorial
BrowserSpy Test Site
StartPanicking Test Site


UPDATES [October 10th]

UPDATE 1 - HistoryBlock & NoScript Add-ons
  • NoScript only works with JavaScript based exploits
  • HistoryBlock does not work if you browse both sites at the same time*
*HistoryBlock utilizes the tab closed & download complete addEventListeners to initiate a history wipe. That leaves you exposed if you have both sites open in separate tabs at the same time or open TI from the same tab without going to an intermediate page first.

UPDATE 2 - Disabling Browser History
  • Does not work in IE
  • Does not work in Opera
  • Does not work in Safari
*Disabling history only works properly in Firefox.

Last edited by Vegas; 11-16-2009 at 06:46 AM. Reason: Updates
 
Reply With Quote
Santrex Torrent Seedboxes
Old 10-08-2009, 10:15 PM   #2 (permalink)
 
SilverSurfer's Avatar
 

Join Date: Aug 2009
Location: T-I Blvd.
Posts: 415
SilverSurfer has much to be proud ofSilverSurfer has much to be proud ofSilverSurfer has much to be proud ofSilverSurfer has much to be proud ofSilverSurfer has much to be proud ofSilverSurfer has much to be proud ofSilverSurfer has much to be proud ofSilverSurfer has much to be proud ofSilverSurfer has much to be proud of
iGiver: (56)
SilverSurfer is offline
Default

What about the chrome users ?

I guess deleting browsing history will work here too. Correct me if I am wrong.
 
Reply With Quote
Old 10-08-2009, 10:20 PM   #3 (permalink)
buckyshort
Donator
 
buckyshort's Avatar
 

Join Date: Jun 2009
Posts: 373
buckyshort is a splendid one to beholdbuckyshort is a splendid one to beholdbuckyshort is a splendid one to beholdbuckyshort is a splendid one to beholdbuckyshort is a splendid one to beholdbuckyshort is a splendid one to beholdbuckyshort is a splendid one to behold
iGiver: (97)
buckyshort is offline
Default

I like having my history, so i now use noscript, hope i will not get banned for using it !!
Thanks for the tip tough, highly appreciated.
 
Reply With Quote
Old 10-08-2009, 10:29 PM   #4 (permalink)
 
MaaNYaN's Avatar
 

Join Date: Aug 2009
Posts: 71
MaaNYaN is an unknown quantity at this point
iGiver: (1)
MaaNYaN is offline
Default

wudnt using one browser of T-I and another for trackers solve this prob...my guess is this might work 100%....with this users can keep their browse history without any fear of others finding out where else we r members of.

just my thots...dont know if it works this way
 
Reply With Quote
Old 10-08-2009, 10:30 PM   #5 (permalink)
Vegas
Super Moderator
 
Vegas's Avatar
 

Join Date: Mar 2009
Posts: 830
Vegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond reputeVegas has a reputation beyond repute
iGiver: (122)
Vegas is offline
Default

Quote:
Originally Posted by bmwxl33 View Post
What about the chrome users ?

I guess deleting browsing history will work here too. Correct me if I am wrong.
Disabling history ONLY works properly in Firefox..


Quote:
Originally Posted by MaaNYaN View Post
wudnt using one browser of T-I and another for trackers solve this prob...
Yes, a separate browser for trackers will also work.

Last edited by Vegas; 10-11-2009 at 12:07 PM. Reason: Updated disabling browser history response.
 
Reply With Quote
The Following User Says Thank You to Vegas For This Useful Post:
Old 10-08-2009, 11:24 PM   #6 (permalink)
Dan
The Exalted
 
Dan's Avatar
 

Join Date: May 2009
Location: Australia
Posts: 1,036
Dan has a reputation beyond reputeDan has a reputation beyond reputeDan has a reputation beyond reputeDan has a reputation beyond reputeDan has a reputation beyond reputeDan has a reputation beyond reputeDan has a reputation beyond reputeDan has a reputation beyond reputeDan has a reputation beyond reputeDan has a reputation beyond reputeDan has a reputation beyond repute
iGiver: (54)
Dan is offline
Default

So they have moved up to banning T-I members with this now. Trackers such as GFT (I think) have been using this method to detect cheaters from forums such as SB-I for a while... bit of a shame they're using it on us now. Maybe it's becoming well known.
__________________
A mythical creature hunted since the beginning of time. Some say he is just a legend, others believe he is an immortal living among us. His face seen only by those whose lives he has spared. He is hunted by the governments of this world for bringing upon them death and destruction! Part human, part god, he is The Exalted!

Dark Angel - Fading memories of the past


looking for ____{f*n}____
 
Reply With Quote
Old 10-08-2009, 11:40 PM   #7 (permalink)
 
princest.zelda's Avatar
 

Join Date: Aug 2009
Posts: 320
princest.zelda is just really niceprincest.zelda is just really niceprincest.zelda is just really niceprincest.zelda is just really niceprincest.zelda is just really nice
iGiver: (45)
princest.zelda is offline
Default


If you are using mozilla:
First of all, open your history tabs, delete all with keyword torrent-invites.com.
Then install below plugin :
History Blocker
Add *.torrent-invites.com as your blacklist.

Now you can use browser freely, together with history feature. No worries.

Ive tested it. Works wonderfully.
I hope I'm helping out.
Cheers.
__________________
My big THANKS to: Pascualito, goover, konVILEeuted, smtsh, Knievel and The-Deh
 
Reply With Quote
The Following 17 Users Say Thank You to princest.zelda For This Useful Post:
Old 10-09-2009, 12:46 AM   #8 (permalink)
 
wtfmate's Avatar
 

Join Date: Aug 2009
Location: *cough* Demonoid
Posts: 226
wtfmate has a spectacular aura aboutwtfmate has a spectacular aura about
iGiver: (22)
wtfmate is offline
Default

Those big private trackers are such meanies :(

...lets DDOS them :D

Click the image to open in full size.

lol

But seriously: Download noscript set it to global whitelist in settings and find the blacklist exceptions and copy and paste all the URLs of every private tracker you belong too into that blacklist.

I have always found noscript to be a pain in the arse because it blocks everything under the sun under its default global blacklist. Change it to global whitelist so flash and other user friendly stuff isn't killed in the process and block your tracker URLs.

Last edited by wtfmate; 10-09-2009 at 12:57 AM.
 
Reply With Quote
Old 10-09-2009, 01:31 AM   #9 (permalink)
 
will.i.am's Avatar
 

Join Date: May 2009
Location: Im in your Closet!
Posts: 489
will.i.am is a name known to allwill.i.am is a name known to allwill.i.am is a name known to allwill.i.am is a name known to allwill.i.am is a name known to allwill.i.am is a name known to all
iGiver: (11)
will.i.am is offline
Default

x264 sucks anyway, so it really dont matter either way.

Oh and its only a matter of time before more trackers catch up.
 
Reply With Quote
Old 10-09-2009, 01:55 AM   #10 (permalink)
 
poasd25's Avatar
 

Join Date: Jul 2009
Posts: 100
poasd25 is an unknown quantity at this point
iGiver: (15)
poasd25 is offline
Default

This vulnerability that allows trackers to query my computer and identify which sites I belong to works only with Browser History or it also checks my cookies ?
Should I delete all my saved cookies ?
 
Reply With Quote
Reply

Tags
css, hack, security, warning

LinkBacks (?)
LinkBack to this Thread: http://www.torrent-invites.com/announcements-bittorrent-news/39723-security-warning-css-hack.html
Posted By For Type Date
ha.ckers.org web application security lab This thread Refback 10-30-2009 09:14 AM
Webappsec ha.ckers.org web application security lab This thread Refback 10-27-2009 12:51 AM
Google Reader - ha.ckers.org web application security lab This thread Refback 10-25-2009 01:59 PM
Google Reader - This thread Refback 10-15-2009 06:41 AM
Google Reader - This thread Refback 10-13-2009 03:55 AM
ha.ckers.org web application security lab This thread Refback 10-13-2009 03:46 AM
DELPAI : [CSS History Hack] 나는 당신이 어떤 사이트에 방문했는지 알고 있다. This thread Refback 10-10-2009 02:23 PM
www.okc2600.com :: View topic - Stealing Browser History - New Metasploit Module This thread Refback 10-10-2009 10:13 AM
ha.ckers.org web application security lab This thread Refback 10-10-2009 07:20 AM
Du hast die falschen Freunde (sagt dein Browser) partikelfernsteuerung This thread Pingback 10-09-2009 08:14 PM
CSS History Hack Used To Ban Torrent Users ha.ckers.org web application security lab This thread Refback 10-09-2009 12:15 PM

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Affilates : Torrent Invites | SceneW | Torrent Forums | Tracker Invites | Scene Releases | Seedbox Hosting | TI Folding Team


 
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright 2007 - 2009 Torrent-Invites all Rights Reserved
   
All times are GMT +10. The time now is 11:45 PM.