WTV ARCHIVES: WAR
Updated 3-22-00
This page, and the uninformed speculations contained within, © 1998-2000 ulTRAX@webtv.net
NOTE: I use the term "war" in the loosest sense. Obviously the interests of both WTV and those who seek to understand WTV security (or worse, subvert it), are incompatible. I may at time get frustrated with counter-measures WTV introduces... as I did in some of these posts, but I do see it as part of the game. In the end it's wise to know what motivates your "adversary". Only in that way can you better predict his next countermove, and avoid providing inadvertant assistance.
We now have a pretty good idea from studying the last few upgrades just how WNI works. Some methods for killing URL access can be accomplished with a server-side modification or upgrade, others require a client upgrade. Knowing this provides some sense of predictibility.
From: ulTRAX@webtv.net
Group: alt.discuss.webtv.hacking
Subject: WHAT DOES WTV SEE AS A THREAT?
Date: Tue, Dec 8, 1998
If we try to get into the minds of the people who run WTV we might get a better idea what they consider a threat... and what they don't care about. The later is probably safe to post on. DragonLord's post falls into none of these categories.
#1: Money. this is the reason they shut down the StayConnected trick
#2: Security, both network and account. Intrusions into the network jepordize their trade secrets and arrangements with their partners. (see money). Key to maintaining security, at least from it's subscribers, is limiting access information on the system (so JS had to go) and access to WTV URLs. Often badmouthed as mere "Tricks", these are the URLs and Commands make our end of the system work and are necessary to hack. WTV has a pattern of systematically trying to eliminate our access to these URLs and Commands... though in doing so they are pushing us to bypass their main line of defense, the Client itself... and to use PCs. This approach may ultimately backfire on them.
#3: Public relations: to the press, the public, and Wall Street. (see money). No corporation wants a bloody nose. If there is a hacking scare, or problems with the network... it is less competitive. (Too bad WTV does not see putting out an inferior product by not having RA5 and personal Java as a black mark.... but then WTV is a mere tool in MS's grand strategic schemes)
From: ulTRAX@webtv.net
Group: alt.discuss.webtv.hacking
Subject: WTV HAS DECLARED WAR ON US
Date: Sat, Dec 12, 1998
With the past few upgrades WTV has systematically sought to limit our actions in every way they can.... from eliminating our access to WTV URLs to shrinking the sizes of form boxes we use for input.
It is IMPERATIVE that there be ABSOLUTELY NO OPEN DISCUSSION on new methods to access WTV URLs or on ways to make the JS Code Reader work.
WTV is tempting fate. It is forcing us into finding ways to bypass the [safeguards in the] Client entirely. Then what will they do? In a few months it may look back and wish they had never taken away what were in essence harmless toys.
From: ulTRAX@webtv.net
Group: alt.discuss.webtv.hacking
Subject: Re: WTV HAS DECLARED WAR ON US
Date: Sun, Dec 13, 1998
I know I am immensely frustrated... the last series of downgrades has ruined most of my plans for my HP.
Yet, I know if I were running WTV network security I might do the same thing.... then again, maybe not. On some level it's overkill.....
What are WTV's real priorties to protect? Subscriber accounts, network operations, info on future upgrades, info they don't want competitors or the press to get , etc. All of these concerns are legitimate... or at least necessary given corporate imperatives. But if WTV takes measures that exceed their legitimate intent, then we might rightly interprete it as overly aggressive. Even if we don't, there is a danger to WTV.
As I stated last June when WTV first tried stop bombing by limiting access to WTV URLs.... that the bombers were "driven", and would soon find a way to bypass WTV's latest counter-measures. [Within a few weeks the audioscope bomb arrived.]
Well, I fear the same problem here. That those driven to hack... some for malicious reasons, some just out of intense intellectual curiousity, now have little alternative but to probe more deeply into how WTV works.
WTV might have been better off trying to deal with brushfires that could be stopped with the changes in the Client. But if they are too aggressive in stamping out what might me non-threats.... they force people to think along new lines. That may be disasterous to them.... especially if this new line of inquiry is to bypass WTV's main line of defense.
In the end.... WTV may be a virtual network, but it's really all just out there on the open web.
From: ulTRAX@webtv.net
Group: alt.discuss.webtv.hacking, power.hackers, webtv.tricks
Subject: WHY SOME SECRECY IS ESSENTIAL
Date: Fri, Dec 25, 1998
[I have posted this] WTV Hit List before. But, it is important for everyone to realize why it is so critical NOT to post new tricks... especially regarding
1: how to get to WTV URLs
2: getting the JS code reader working again
These items are high on WTV's Hit List. If you don't believe me look at all the things WTV has taken away this year alone. To get into the brain of WTV I urge people who have no idea what we are up against to find my post called "what WTV sees as a threat". It should still be up in news:alt.discuss.webtv.hacking
JANUARY 98 DEMO CRACKDOWN:
Kiddie Filter put on.
Web access limited
Mail shut off (there was a trick around it) NGs access stopped (there were waysaround it) Chat access stopped.
MAY:
Hacking accounts stopped.
GoTo method to DEMO targeted.
SUMMER 98 UPGRADE:
Tricks removed from mail body
Tricks removed from Sig
Javascript removed from GoTo
User ID in Return Mail Reports stopped
Demo mail stopped
Demo NG access stopped
Misc Bomb codes deactivated
TRICKS CRACKDOWN (Aug-Nov 98):
Internal builds removed from Willie
Blocks put up to prevent access to TestDrive Access to tricks pages stopped. Bypass codes stopped StayConnected trick killed Stiffer penalties for Hacking TRICKS & INFO
FUNK 98 (NOVEMBER SERVER-SIDE UPGRADE):
Mailto: link killed
bgsound link killed
NG Search trick killed
JS Code reader killed
Doom no longer accessible
Jack no longer acessible
Testdrive no longer accessible (again LOL)
Many misc WTV-Trick URLs killed
To the Clueless who still think it's safe to post tricks: notice any patterns in WTV actions? WTV has made it a top priority to kill JS because we can use it to analyize the WTV pages and WTV is determined to prevent us from accessing WTV URLs since that is how hacking is done.
If anyone knows ways to get around what WTV has done.... please DON'T POST. Don't even CONFIRM that it can be done. Share info only with those who you really, REALLY trust. Just remember that the idiot blabermouths who are ruining things for all of us probably did not discover any of the tricks they post.... they got them from someone who foolishly trusted them.
Group: alt.discuss.webtv.hacking
Date: Mon, Feb 22, 1999
From: ulTRAX@webtv.net (///\ ulTRÅX \\\/)
DUMMY LINKS: how they work
It seems that the way (or "a" way) WTV disables WTV URLs in certain parts of the browser is by substituting dummy-links. How this is done is not well understood.... but I have a few more clues. Why is any of this important? Because if we can not access WTV URLs... we can not hack. WTV knows this and is working hard to cut us off at the pass. Word from Alpha, come the next upgrade we will lose more of the techniques we use.
Anyway, I was converting a TXT page at my HP to HTML.... knowing that I'd have to disable the HTML code in places if I wanted to illustrate some code. So I used XMP tags before and after the code segments. It worked pretty well.
It was not a problem until I had a