Gnutella Forums  

Go Back   Gnutella Forums > Current Gnutella Client Forums > LimeWire+WireShare (Cross-platform) > Open Discussion topics
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

Open Discussion topics Discuss the time of day, whatever you want to. This is the hangout area. If you have LimeWire problems, post them here too.


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old July 20th, 2002
Limewire User
 
Join Date: July 19th, 2002
Location: UK
Posts: 3
locust is flying high
Default unexpected asf files in search results- anyone else?

I'm seeing a pattern of results when I search for certain rare files. I'll get no results, except for either 6 or 12 .asf files, three of which are named "!!_", with size 301KB. Try it yourself with an obscure movie name or something. Try it a few times, it is not consistent. Is anyone else experiencing this?
Reply With Quote
  #2 (permalink)  
Old July 20th, 2002
Gnutella Veteran
 
Join Date: July 1st, 2002
Location: Oz
Posts: 123
bad_vlad is flying high
Default mystery files

yup - experienced something very similar except the files had a slightly different name - it seems someone is being a nuisance - I blocked the source host and haven't had the problem since (and it was happening EVERY search) - I blame Hilary Rosen myself

bad_vlad
Reply With Quote
  #3 (permalink)  
Old July 20th, 2002
VTOLfreak
Guest
 
Posts: n/a
Default

Altough that malicious client renames the file every time it gets a query it should be easy to block .

If we just had a feature to block files with a certain hash ...
Even if they rename the file , the hash stays thesame .
Knowing this , you can start building "blocklists" .
Reply With Quote
  #4 (permalink)  
Old July 20th, 2002
Connoisseur
 
Join Date: March 4th, 2002
Location: Tennessee
Posts: 354
bobomon is flying high
Default

Quote:
I'm seeing a pattern of results when I search for certain rare files. I'll get no results, except for either 6 or 12 .asf files, three of which are named "!!_", with size 301KB.
I have found it useful to (in addition to filtering the IP) also filter files with the unique string in them such as as !-! and !!_ that way I don't get the same files from other users who have inadvertantly left them in their shared folder. I actually filter out ASF all togther as I have never downloaded one that had the content I wanted.
Reply With Quote
  #5 (permalink)  
Old July 20th, 2002
Paradog's Avatar
Distinguished Member
 
Join Date: April 5th, 2002
Location: Germoney
Posts: 739
Paradog is flying high
Default

Isnt it possible to simply block the host?
Reply With Quote
  #6 (permalink)  
Old July 20th, 2002
VTOLfreak
Guest
 
Posts: n/a
Default

We need a fail-proof system .
Blocking by hash is one solution until they start to mutate the content of files .
Reply With Quote
  #7 (permalink)  
Old July 20th, 2002
Paradog's Avatar
Distinguished Member
 
Join Date: April 5th, 2002
Location: Germoney
Posts: 739
Paradog is flying high
Default

Well, I have thought about that problem (fake files) too..
If *they* (no idea who I mean) think a bit further *they* could code a client which sends queryhits to all queries with some better filenames like:
Query = gescheiterten existenzen vogel
Queryhit = "Gescheiterten_Existenzen - Vogel.mp3

You just have to set up a database of the artist or program name to do so.

Then *they* could just let *their* servent send 000000s
till the size of the file is reached. (Usually a mp3 song is about 4 mb big, so send a file with size = 4 mb + - Random value which has only 0s in that file.

Hashing wouldnt stop that either because the hash is different if you add some more bytes to that file, or am I wrong?
Reply With Quote
  #8 (permalink)  
Old July 20th, 2002
VTOLfreak
Guest
 
Posts: n/a
Default

You are right . But most of these clients only change the filename .
Reply With Quote
  #9 (permalink)  
Old July 22nd, 2002
Limewire User
 
Join Date: July 19th, 2002
Location: UK
Posts: 3
locust is flying high
Default

Good, I'm glad other people have noticed these anomalous search results. I blocked the IP, as bad_vlad suggested, and problem is solved, for now. It is interesting to note that blocking only one IP solved the problem (*IP address removed*) and that that IP address ia associated with a web hosting firm in Los Angeles.

It is possible to design a malicious attack based on the strategy of responding to every search string (a la Paradog) that is much more effective than what we are seeing now (assuming this is a malicious attack, of course). If this is an attack on the gnutella network, it is then reasonable to assume that it is just a trial run to debug, test expected bandwidth, etc., and that more sophisticated attacks will follow shortly. More IPs, more sophisticated file naming schemes, random file sizes, viruses, etc.

I read something a few weeks ago about some proposed legislation in the U.S. that would make this kind of malicious attack legal for "content owners" or something... does anybody have a link for more info on that?

OTOH, maybe it is not an attack, maybe someone is testing their new, poorly designed gnutella client.

Last edited by birdy; February 1st, 2008 at 04:42 PM.
Reply With Quote
  #10 (permalink)  
Old July 23rd, 2002
igalan's Avatar
Enthusiast
 
Join Date: November 27th, 2001
Location: Barcelona
Posts: 38
igalan is flying high
Default

Quote:
Originally posted by locust
Good, I'm glad other people have noticed these anomalous search results. I blocked the IP, as bad_vlad suggested, and problem is solved, for now. It is interesting to note that blocking only one IP solved the problem (*IP address removed*) and that that IP address ia associated with a web hosting firm in Los Angeles.
I have also blocked that IP because it was returning results for any query (fakes, of course). But later I have added a filter to block IPs in the Firewall, this way I block IPs from potentially unsafe IPs (Cyveillance, Warner, Media Force), this way I have protected every P2P prog that I may use . I keep the list of blocked IPs updated, just in case...
__________________
| Israel Galan

Last edited by birdy; February 1st, 2008 at 04:43 PM.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Seeing my own shared files in search results mjkohl Open Discussion topics 7 June 15th, 2007 08:05 PM
Fake files in search results Lord of the Rings Download/Upload Problems 0 August 21st, 2006 06:53 AM
small files and search results Glennmc7 Download/Upload Problems 0 March 16th, 2006 12:05 PM
Upload Files And Search Results? scott808 Download/Upload Problems 1 January 9th, 2006 03:57 AM
Only WAV files in search results Cheese Support: General 3 October 5th, 2002 07:11 PM


All times are GMT -7. The time now is 04:27 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.