View Single Post
  #13 (permalink)  
Old May 27th, 2001
Serious
Guest
 
Posts: n/a
Exclamation Hacking packets

So lets see what we could do with a encrypted control packet if I was "in control".

I could send out a command that would:
- erase your hard drive
- remove my program because I am mad at everyone
- stop use of my program because I am not getting any $$ from some lame spyware company I signed up with like a idiot
- stop use of my program because I don't like you (ID via IP address)
- make it go and download a "plug in", but oops! I had a virus in that plug in so everyone on the network gets infected all at once, oh well! Read the EULA!
- erase your hard drive because you posted something against me on my forum
- erase your hard drive because you run another more popular client and I don't like losing control
- erase your hard drive because I just haven't grown up yet and think it's fun
- be cleaver and throw a few random bytes in a random number of downloads you have done just to drive you crazy, because I don't like you
- turn on a packet blasting sending thing that floods the network because lamewire 2.3.5 doesn't do what I wanted it to do, if I can't have it, no one will!
- send all your addressbook entries to the RIAA for personal identification along with a list of all the mp3 files on your system, drive C and D and E and....
- send out yourname@cookie.txt files so everyone knows who you are (note: already implemented in this version)
- turn your house lights on and off randomly via any connected X10 remote I can identify
- hang up and dial 911 over and over all day
- hang up and dial 1-900-bear-income over and over so I get paid
- hang up and dial the DOD computer over and over with a script that looks like you are trying to hack into DOD secrets, you get arrested and so I now don't have you posting complaints about my spyware
- email everyone you know and tell them they are a jerk and you never want to talk to them again
- email important people and make threats
- send any PGP private keys to me so I can black mail you
- anything I want to, whenever I want to because I like having total and complete control, trust me

WE DON'T KNOW WHAT THESE PACKETS DO!

Encrypted, closed control packets are a bad idea. What will it take for newbee programmers to wake up? How much political pressure does it take to get through a thick skull? After this, whats next?

Now think what I could do with this information if I was a hacker and de-compiled the software so I could make up my own packets and send them out over the network! Not that hard to do.

All Gnutella clients need to be open source!

Don't trust any client that isn't open source!

TRUST NO ONE!
Reply With Quote