Skip to content
TORNLIFE More

captainhahnsolo: forum

captainhahnsolo [1354073] Level 100 Traveling Hookers n Blow HnB pimp

Forum posts (Torn's count)
156 observed
Archived posts
79
Threads started (archived)
19

Boards

From the 79 newest archived posts.

Threads started

Most-liked posts

Likes as archived at fetch time, adjusted for how long each post had been up. Scored posts only; the full score pass runs after the import.

Adios Subscribers! · · 400 likes

So, since I am apparently on several NSA level API watchlists, it is not really feasible for me to keep playing torn. I mean shit, I thought the government was bad but apparently everyone with half-a-decent scripting ability can monitor my account without my consent.

I have done a few test travels between the caymans and back and it seems that I am being actively watched. I get mugged within a minute of returning just about every time.

Since apparently my decision to invest in money first and stats second was a mistake, it doesn't really make sense for me to keep taking it up the butt while making big players bigger and rich players richer.

Not sure if I am going to quit, but I am "putting my money where my mouth is". I have been playing this game for just shy of 11 years and I have been a donator or subscriber for at least 10 of it.

Your PayPal subscription has been cancelled. Thank you. 12:46:0715/04/21

Not anymore...


Edit to respond to Ched's sticky:

Page scraping is already against the rules since the scripting ban rule requires you to user the API or "a page you have loaded manually and are currently viewing".

Do you not have the ability to enforce the rules?

Flight Arrival Lag/Exploit · · 53 likes

14:36:22 - 14/04/2021 You boarded a 0h 17m private flight from Cayman Islands to Torn
14:53:26 - 14/04/2021 Spliffy mugged you (with 2 others) for $1,603,470,351 sending you to hospital for 0h 39m

https://www.torn.com/loader.php?sid=attackLog&ID=a5cf98a28752e21917ec1f41331d60d2

1) The javascript timer does not start counting down until the page is fully loaded, inducing a 1-2 second delay on the timer.
2) There is a forced page reload upon the completion of the timer that is unable to be bypassed further adding a 1-2 second page load delay before a flier is able to interact with the tc website.

These series of delays provide a window from which it is impossible for a flier to interact with the torn website, while a prospective mugger is able to attack and steal money from players.

This issue is present on both flying to and from TC.

In my specific example, my browser refreshed me into the hospital without even presenting me with a normal unhospitalized index.php.

This issue presents an unfair and exploitable form of lag that can be abused to steal money from players that would be otherwise unable to be mugged.

Flight Arrival Lag/Exploit · · 16 likes

As a side note, this is further exacerbated by the requirement of CAPTCHAs prior to being able to interact with the TC website after flying to some locations. Specifically switzerland when flying to rehab.

Flight Arrival Lag/Exploit · · 9 likes

This is true, but this particular issue also impacts those that choose to fly to SA for xanax runs. They can get mugged before they even make it past the captcha. Or someone can get mugged in Switzerland before they make it through the captcha.

Just keep refreshing the page and mug new arrivals before they can complete the captcha to take their money on a smaller scale.

Also, regardless of the popularity of the problem currently. Dumping all my cash into a stock or vault within 2-3 seconds of landing IS possible, just like it is also possible that I can get mugged in the same time-frame. It is a race against the clock. My report was an attempt to outline a long standing issue that has been exacerbated due to the mas exodus of funds from the caimans before your April 20th fee deadline.

It takes 4 clicks to go from /index.php to dump my cash into stocks(even less to dump into vault). I click on my Nav bar stock icon, then the first stock, then "purchase", confirm. If I was on equal footing with an attacker, it really is a race to see who nails it first. There is no typing required by either party, just a couple mouse clicks on parts of the screen.

Currently, attackers/muggers have a nearly 2-3 second head start on fliers due to the fact that at least 1 full page reload is required after fliers land before they permitted to interact with the TC site to try and stash their funds. Attackers spam refreshing someone's profile do not suffer this same impact. In fact, given the caching enabled on the TC site, their refreshes are actually faster when bench-marked against the full reload of /index.php after flying.

Given that use of the API is allowing other users to target me explicitly during that 2-3 second window when I have no ability to do anything is problematic.

I am in the top 1000 published player list of high net worth. Anyone using the API to monitor other players for mugging would be smart to monitor those publicly listed players. Does that mean that I will forever need to pay a mugging tax if I ever want to take large amounts of money anywhere?

These instances are not isolated cases where some user walked away from the computer and got mugged. I was actively trying to refresh my page to stash my cash but was completely unable to compete against the attacker due to the required page load after landing.

Flight Arrival Lag/Exploit · · 8 likes

Possible fixes for the issue would be to:

A) Implement a X second timer after a flight where which the player can not be attacked
B) Do not clear the "flying" status on a player until after the /index.php has been loaded post flight.

Ideally, to be most fair to both attackers and fliers, the flying flag should be removed on "index.php load" OR "60 seconds", whichever comes first.

That provides an acceptable amount of time for a player to respond to a captcha and it will allow attackers the ability to attack as soon as the flier is able to interact with the website themselves.

The issue of "who has the fastest internet connection" is still in play here, but at least the attacker would not have a 2-6 second advantage due to required page loads.

Recent archived posts

n/a ·

N/A

Looking for Work? Post your Stats here ·

Hired

Raw JSON on /crimes.php ·

Sorry, i didnt register the whole "Where is the red box" thing...

https://www.torn.com/forums.php#/p=threads&f=19&t=16258622&b=0&a=0

Probably the same issue just in a different spot?

Raw JSON on /crimes.php ·

I have identified a bug on /crimes.php where if you perform the following steps, you will produce page output like that in the screenshots attached.

I was able to separately reproduce the issue by following the following steps:

1) Have Nerve
2) Commit Crimes (I was doing Warehouse Arsons)
3) Receive RED result (hospitalization)
3) On /crimes.php, click on the link to view "Criminal Record"
4) See Screenshots

https://imgur.com/a/HtNPdjj

Adios Subscribers! · · 4 likes

ISPs tend use sticky reservations to prevent people from trying to game the system for new IP addresses.

Most of these reservations expire after a set amount of time. Expiring an IP ban after 1 day would not largely impact any ability to sign up even if the IP addresses move around. It would require a user to have 1 IP address per multi that they wished to sign up for.

Generally, most auto-ban systems are specifically looking at non-residential IP addresses. If a VPN is generating Multis, thats blockable. If a residential IP address is generating multi's, they are the end user or part of a botnet.

Torn already tracks IP addresses for the sake of determining if 1 account is the same as another. I would be curious to find out how many actual sign ups would be prevented by a 24 ban on "new signups", not logins, from a problematic IP address.

EDIT: I know, this is kind of off topic, but there are solutions that exist to this problem. Websites and applications can restrict traffic from known botnets and problematic IP addresses. There are DNSRBLs, published blacklists, and pattern matching altorighims that exist to identify and dynamically track sources of these problems. There are always exceptions to many rules and some will slip through, but that is why it is an evolving issue that pits the people running the site against those trying to scam it.

My objections to ched are not requests for these specific features, but simply pointing out how despite his claims "there is nothing i can do", there are many options available to him to target problematic and abusive behavior.

Adios Subscribers! · · 2 likes

The problem isnt that they are obtaining freely available information. The problem is that they are FARMING it in bulk across hundreds of profiles at the same time.

Your rate limits on the IP mean absolutely nothing when sharing of API keys is allowed... I personally own an entire /27 IP address block. Give me 50 api keys and I can make thousands of requests per minute...

Adios Subscribers! · · 15 likes

  • Restrict profile information to logged in users, you now know who they are
  • A new account that doesn't commit crimes, spend energy, or acknowledge the rules and only looks at 1000+ profiles without spending a single point of nerve or energy, thats gonna be a bannable multi. Hell, i would automate those bans to run every 10 minutes.
  • If an account signs up, and that account gets banned for Multi/Abuse. All IP addresses used by that account are no longer permitted to sign up for new accounts for X days. If the same IP receives a X day ban more than Y times, that IP address gets a Z month ban from new account sign ups.
  • Netflix, Hulu, and a dozen other services restrict their services so that VPN users cant use them to get around region controls. I don't think that Torn is big enough of a problem to be blocked even by the great firewall of china.... Why does VPN use need to be allowed? There are lists for that sort of thing. Even if you dont choose to block VPNs, bullet point "three" can mitigate these issues.
  • You use Cloudflare for DDoS protection, thats not a genuine argument...
Cloudflare has a CDN where they will provide you with the ability to cache "/profile.php?...." URLs for 300 seconds before it requests a new one for the server. If making the API slow requests is going to cause people to scrape, giving profiles the same X minute delay solves the "still use the API problem."


You are absolutely correct that these issue are difficult to address and require a great deal of creative effort to solve. They are not unsolveable.

I was a software engineer at a datacenter where our "abuse" staff was larger than our "support" staff to deal with all the issues of spammers, child pornographers, virus hosting, etc... If you run an internet service, the problem with NEVER go away. Giving up does not solve the problem, it just makes the problem a community one instead of an administrative one...

Adios Subscribers! · · 2 likes

CRLF, I would double upvote you if I could.

Adios Subscribers! ·

Yea, that's gonna go over great lol.... At least with scamming you can avoid it by ignoring a player.

Since anyone and their cat can apparently watch ANY account with via the API... there is no "Opt Out" on this one...

Adios Subscribers! · · 2 likes

"If the software you're using makes non-API requests that are not manually triggered by you, it is not allowed and can be tracked."

Straight from the RULES link at the top of the page. Under "Scripting Abuse: Game Ban"


Even if they don't detect everything right away, nobody is perfect forever. Systems get patched, updated, improved. If they get detected at level 1 or level 100, Scripting abuse is still a game ban...

Rules don't apply less to lvl 100 players than they do to lvl 10 players.... At least they shouldn't.

Adios Subscribers! · · 4 likes

Not really. He just provided a legal avenue for abuse. If the API didnt provide the information, players would get Game bans for page scraping.

I am pretty sure that a ban hammer with data analytics behind it can reduce abuse a lot more than making abuse legal...

Adios Subscribers! · · 12 likes

I was bored and a bit butthurt. Sue me... :p

Heaven forbid I make a post with, maybe, some community relevance instead of the usual random trolling you see in General..lol

Adios Subscribers! · · 6 likes

In order for that to work, they would have to be multis so they could use burner accounts to scrape and get banned. Multi's are against the rules...

Curl was just an example. How about javascript ajax requests? How about perl mechanize packages? How about programmed text based browsers? How about greasemonkey macros and plugins?

The difference is that everything i just mentioned is 100% doable, and also against the rules.

Ched is "allowing" people to do all the banned actions through the API and calling it legal. Apparently because he is afraid people will break them?

Adios Subscribers! · · 2 likes

From the RULES link at the top of the page:

"The use of scripts, extensions, applications or any other kind of software is allowed only if it uses data from our API or a page you have loaded manually and are currently viewing."

Automated Page scraping is not "manual", nor are they often "viewed". It is already against the rules unless I am way off base here.

Adios Subscribers! · · 4 likes

No, literally any web analytics software can track page loads. It actually becomes even easier to determine "who is scraping pages" when the browser user agent says "CURL" or they end up loading 500 profiles simultaneously.

Aren't some of the important profile details behind a login wall? They would literally need to identify themselves to scrape the pages...

Referrer analysis, embedded page tokens, IP and username logging, etcs... There are dozens of ways that this information can be tracked and examined.

Adios Subscribers! · · 4 likes

Page scraping like that is against the rules, is it not? Do you not have the ability to enforce the rules?

Adios Subscribers! · · 12 likes

I got nothing against you :)

You used a valid and legal game mechanic to nail me in the ass so hard I tasted it. Good on you. This one is on ched for creating the problem in the first place by forcing people to exfiltrate billions under the gun of legal mugging scripts.

Adios Subscribers! · · 4 likes

In the past several years, I have seen far too many issues where shit hit the fan, then only a token effort is made to reverse the damage because outrage died out.

My subscription is yearly and doesn't end until August this year, but it is a symbolic action that both I and other players can take to express our displeasure in a way that is tangible and, most importantly, reversable.

You are right, maybe something will get done. Until then, I am going to do what I can to keep the pressure to make sure we get more than a token effort.

If the solution is sufficient, I will resubscribe. If not, then my money will never be spent on this game again.

Adios Subscribers! · · 5 likes

I am not going... not yet anyway. There is still some time on my subscription left and I do enjoy chatting with my faction and a bunch of other people here.

Yes, I would resubscribe if sufficient changes were made. I would like the API to be restricted to being ONLY able to access data from a players own account. I refused to share my api key with anyone, yet apparently I can still be monitored via the API... I don't think thats appropriate.

I have heard complaints about how "then people will just write scripts to scrape the site". Well, that's already against the rules and should result in fedding. If we are allowing the API to monitor other players as a cop-out to prevent people from resorting to a feddable offense, then WTF is scraping against the rules in the first place...

Adios Subscribers! · · 3 likes

lol, if you read it then you would know. I included the attack link in the bug report.

https://www.torn.com/loader.php?sid=attackLog&ID=a5cf98a28752e21917ec1f41331d60d2

Yep, but in real life, nobody knows what is in other people's carry on. In real life I would have wire transferred it instead of thrown it all in a suitcase. In real life, the TSA doesnt let you carry a Golden AK into the secure area of the airport...