6 ms·
Hi everyone! I did this. It was just a random cool idea I wanted to try. It worked a little too well and I quickly moved it to a disposable site to test if the
by dejanseo 8y ago
Hi everyone! I did this. It was just a random cool idea I wanted to try. It worked a little too well and I quickly moved it to a disposable site to test if the page will get penalised by Google. I got busy with other things and forgot about it. When I bumped into it again I decided to write about it, for two reasons: 1) To me it's hard to believe that Chrome would allow for this to happen in the first place and 2) that Google wouldn't penalise a site doing this. Well, since the story was published Google tracked down my test page (most likely by using the source code I revealed on my blog) and completely de-indexed the whole domain.
- TekMol 8y agoCopying someone elses site and tricking their users to use your copy is a copyright violation and fraud. Nothing cool about it.
- mosselman 8y agoYour statement is far too broad and lacks context. Where is this a violation and where is it considered fraud? There must be some countries where this isn't the case or at least where the article and non-commercial use of the technique are considered to be mitigating circumstances. Also, who doesn't find it cool? You don't seem to be saying that what is described in the article isn't cool, you seem to be making a broader claim that copyright violation and fraud aren't cool. Lets assume you find what is described in this article copyright violation and fraud, because after all, you said it is. Apparently some people on HN find what the author has done cool, judging by the comments. Ergo, some things that you, specifically, consider 'copyright violation and fraud' are in fact cool.
- fabricexpert 8y agoHe copied Google's SERP page, AND copied all of his competitors websites. That's definitely copyright infringement, you'd be livid if you were a competitor, and as a user you'd be pretty annoyed. It's still an interesting hack, so good to see it being talked about. But it is not ethical and definitely illegal in almost any jurisdiction.
- EdwardDiego 8y agoCopyright infringement is a civil case in almost any jurisdiction, not a criminal case. The USA is a notable exception, perhaps due to the vested interests with deep pockets.
- fabricexpert 8y agoA civil case you would lose though.
- jakoblorz 8y agoJust to be clear: you do not endorse copyright infringement for the sake of being cool, do you?
- mosselman 8y agoI believe much of modern copyright law in Europe but especially the US is broken, but in general I don't find crime cool, nor do I find 'cool' a justification in itself to do certain things. Not all laws are sacred though. I was merely reacting to broad nature of the claims in parent comment. There is a world beyond the US and Europe, laws are not universal truths, they are a representation of what we have come to agree upon as rules to play by. In copyright law specifically though there is often a chasm between what the people find good rules and what companies find good rules. But that is a different discussion.
- stef25 8y agoIt's a POC with no intention other than seeing if it would be possible, isn't it?
- dejanseo 8y agoNot the first time either. Every now and again I get an interesting idea, test it and share it with the world. The test that was left forgotten had no commercial impact on anyone and very low traffic.
- p49k 8y agoExcept for the part where he said he moved the code to another site five years ago where it has been running since and even ranks highly for some search queries? Unless I’m misreading that paragraph.
- rkangel 8y agoWhile that might mean that it's OK ethically (I'm not sure either way), that doesn't make a difference legally. If you go and pick the lock of a random house in your city and get caught by the police, I very much doubt that the defence "I was just doing it to see if I could" is going to help you.
- treerock 8y agoIf you didn't steal anything, what would the charge be?
- close04 8y agoBreaking and entering or trespassing at the very least.
- wongarsu 8y agoIf you get caught while doing it you would likely be charged with attempted burglary. It's up to you to convince jury/judge that you didn't intend to steal. If you only get caught after leaving the premises it is trespassing, since it's apparent you didn't steal. Picking a lock in order to trespass might make the sentence a bit harsher than normal.
- falcor84 8y agoIt's also a big trademark violation, right?
- code_duck 8y agoI would say copyright violation.
- falcor84 8y agoYeah, copying the content is definitely copyright violation. But I meant to say that by hosting these sites, the developer could also get sued for attempting to conduct business under the trade name of another entity. And that includes, in particular, hosting that fake Google SERP.
- Quarrelsome 8y agobut if you don't care so much about those things it is kinda interesting.
- tomp 8y agoCopyright violation? You're literally just "archiving" their website. Exactly the same as Google are doing themselves.
- mattmanser 8y agoNo, you're using their content to gain financially, and in this instance, at their expense. And that's putting aside all the other possible counter-arguments, of which there are many. I'm no fan of long copyrights, etc., but in this case to me it's a clear cut case.
- detuur 8y agoNo, you're not just "archiving". Besides the point that archiving itself is already in a legal grey zone, at the very least it has the defence that it presents the website unmodified, in exactly the same state for no other purpose than showing the web as it used to be. Like file-sharing websites, archive websites rely on the fact that it's an automated process and they can continue to host anything until they get a DMCA takedown. Not to mention organisations like Archive.org are literally run by librarians which gives their argument of preservation a lot more weight. When you're stealing assets and adding your own tracking code, you're transforming the work, which is a definite no-no for copyright and trademark law. Not to mention that by intercepting traffic which was meant for a competitor you're literally interfering with their business and risk fraud charges.
- 3eto 8y agoWhat's not cool at all is the fact exposed here that Google lets anyone trick their users.
- zepolen 8y agoI guess you don't put locks on your home because you have a 'dont come in' sign on the door right?
- tnolet 8y agoYay, you misled users and stole content! Seems like you are actually proud of this. I gather you realize this and did this in the best “white hat” spirit, although that’s not really what I get from your blog.
- dejanseo 8y agoWhere did I say I'm proud of this? Everyone keeps saying "proud". I chose to share it in public because it's a serious problem that others may be using it to do real harm. I blog about many things, most harmless and often very useful. I remember one other time when I exposed something broken in Google. I got penalised as a reward.
- tnolet 8y agoYou are right, you never used the word “proud”. You also did not use the words “problem” or “harm” in the post. So the “pride” thing is mostly tone, subtext or between the lines if you will. This is just my opinion so YMMV
- kentrado 8y agoAs long as it is subtext and tone you can claim anything regarding another person's character and they have no recourse to argue against you, because it is all in your mind. Well done.
- saiya-jin 8y agoLets sum it up - you revealed a bug, and eventually reported it. Good. Showed some technical tricks and creative approach. Thank you. Bad - amoral and most likely illegal theft of copyrighted content. "Just for fun" ain't gonna cut it. You hurt real businesses, probably because you don't give a f*ck about them, fun is more important. Is it hard to see that this would stir some controversy to say at least? Btw calling this "random cool idea" seems like you are proud of this and want some appreciation, hence sharing. If you would be concerned about security, you would share this bug immediately, which is definitely what you didn't do according to your own words. Things can look significantly different from the other side. You know, the side of the rest of the world.
- pakitan 8y agoIs Chrome the only browser this trick worked on?
- superasn 8y agoIt's sad that everyone is being so harsh to you just because you decided to post about a vulnerability that who knows thousands of other people are quietly exploiting for their own benefit. If anything I am happy that instead of trying to misuse it or keeping it a secret you made it public knowledge so that there can be something done about it. Yes you could have handled it more appropriately and you probably will in the future too. I just don't understand the harsh attitude and all this legal nonsense and insults being hurled at you for no big reason.
- shawn 8y agoHowdy, former Matasano pentester here. FWIW, I would probably have done something similar to them before I'd worked in the security industry. It's an easy mistake to make, because it's one you make by default: intellectual curiosity doesn't absolve you from legal judgement, and people on the internet tend to flip out if you do something illegal and say anything but "You're right, I was mistaken. I've learned my lesson." To the author: The reason you pattern-matched into the blackhat category instead of whitehat/grayhat (grayhat?) category is that in the security industry, whenever we discover a vuln, we PoC it and then write it up in the report and tell them immediately. The report typically includes background info, reproduction steps, and recommended actions. The whole thing is typically clinical and detached. Most notably, the PoC is usually as simple as possible. alert(1) suffices to demonstrate XSS, for example, rather than implementing a fully-working cookie swipe. The latter is more fun, but the former is more impactful. One interesting idea would've been to create a fake competitor -- e.g. "VirtualBagel: Just download your bagels and enjoy." Once it's ranking on Google, run this same experiment and see if you could rank higher. That experiment would demonstrate two things: (1) the history vulnerability exists, and (2) it's possible for someone to clone a competitor and outrank them with this vulnerability, thereby raising it from sev:low to sev:hi. So to be clear, the crux of the issue was running the exploit on a live site without their blessing. But again, don't worry too much. I would have made similar errors without formal training. It's easy for everyone to say "Oh well it's obvious," but when you feel like you have good intent, it's not obvious at all. I remind everyone that RTM once ran afoul of the law due to similar intellectual curiosity. (In fairness, his experiment exploded half the internet, but still.)
- Improvotter 8y agoThanks for publishing this. I guess that's not said enough with all of the butthurt people here.
- 3eto 8y agoYou did good by publishing this. I've seen that you're updating your blog post based on what people are saying here, you don't have to do that, you don't have to answer to people attacking you on a forum. What you have exposed has the potential to affect a large number of Google users and unfortunately the community has chosen to attack you over attacking Google. Which could say a lot about the state of the community. So thanks again for bringing this vulnerability to our attention.
- AndrewKemendo 8y agoyou don't have to answer to people attacking you on a forum Maybe you don't feel like you have to, but I can tell you from experience, that when an entire community of your peers piles on to you, there is a significant emotional response that you're being rejected. That's just my personal experience, but it seems pretty common to want to respond when those you respect and work with (or might work with) respond negatively to your work.
- technotarek 8y agoI'm curious, how did you generate your content for the spoof SERP page? Was it dynamic to somehow reflect the content of the user's original SERP page (which could be subject to the user's location, browsing history and other factors in G's algorithm)?
- code_duck 8y agoI don’t think anyone is objecting to what you did as much as how you did it, and how you seem to be proud of flagrantly abusing your ability to duplicate other people‘s intellectual property. I’m hardly a champion of copyright laws or IP in general, but running duplicates of someone ese’s site feels completely wrong to me without thinking twice. Like the suggestion from the pen tester here, which you posted on your blog, this would be a lot different if you had written the article about conduct that seemed professional, respectful and legal.
- aaaaaaaaaab 8y agoHow is it different from archive.org snapshots from an IP perspective?
- code_duck 8y agoGreat question. How about we invert that, and you tell me what IP laws justify operating a functioning duplicate of someone else’s entire website, full of copyrighted and trademarked content, for the benefit of your business? By this logic, I could duplicate any website in the word and operate a copy for my private business. While I am not a lawyer it seems clear that this is not legal (and as if this is the first time the concept occurred to someone!) I assume archive.org falls under Fair Use. Check these guidelines. https://tinytake.com/screen-capture-copyright-violation-or-fair-use/ https://tinytake.com/screen-capture-copyright-violation-or-f... Duplicating your competitors website for analysis to benefit your business fails the first condition. If it were academic research or some sort of public benefit, that’s different than for-profit republishing for your SEO business.
- deckar01 8y agoAs a person who has wasted a lot of time trying to convince Google that a vulnerability is worth fixing, I have no sympathy for them finding out about a vulnerability via a public disclosure like this. They probably would have spent weeks/months failing to understand the implications of the vulnerability only to have the report closed with an auto generated response about phishing not being considered a vulnerability. Keep thinking like an attacker and sharing your findings. It is the best way we can make software more secure.