Author Topic: FurAffinity's data scraping  (Read 2374 times)

Conan

  • Sean Piche Wannabe Club
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 603
  • E-points: +33/-9
  • ¯\(°_o)/¯
    • View Profile
FurAffinity's data scraping
« on: May 14, 2011, 04:56:18 pm »
This morning someone on Lulz found links in the leaked notes to some journal data scrapers hosted on Yak's subdomain on FA. The ones that were found include "http://yak.furaffinity.net/php-stuff/journals_about_inkbunny.php", "http://yak.furaffinity.net/php-stuff/journals_about_antheria.php" (Antheria = 2gryphon's vanity con), and "http://yak.furaffinity.net/php-stuff/journals_about_allan.php". The first two were shared with their respective management, the third one is some creepy monitoring of people talking about Dragoneer's favorite person.

So remember, Yak doesn't have the time to fix FA, but he does have the time to code journal scrapers to find topics that are of interest to the FA admins.

These scripts were later removed and now redirect to YouTube.

a pigeon

  • Cabalistic Fuckhead
  • ***
  • Posts: 352
  • E-points: +35/-1
    • View Profile
Re: FurAffinity's data scraping
« Reply #1 on: May 14, 2011, 05:02:01 pm »
For the record, here are the saved PHP scraping pages:

http://www.mediafire.com/?9wx1c7anqaj6wrf

Hundreds of journals about Allan, Inkbunny and Antheria.
then he hent that noble prince by the hand,
and said "welcome my soueraigne King HENERY!
chalenge thy Herytage and thy Land,
that thine owne is, and thine shall bee."

camellia sinensis

  • Winner: Worst Username on Viv 2011
  • *
  • Posts: 86
  • E-points: +12/-2
  • Drink me
    • View Profile
Re: FurAffinity's data scraping
« Reply #2 on: May 14, 2011, 07:36:56 pm »
I wonder if it's possible similar scrapers exist for private notes.

A chilling thought.

Pi

  • POOR IMPULSE CONTROL
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 614
  • E-points: +40/-10
  • <blink>yes hello</blink>
    • View Profile
    • Clan Spum userpage
Re: FurAffinity's data scraping
« Reply #3 on: May 14, 2011, 07:41:37 pm »
Well, it's public knowledge that the admins have a "dump all of the notes for a specific user" button. A scraper wouldn't be too far beyond belief.
"we did farts.  now we do sperm.  we are cutting edge." — Theo DeRaadt

GreenReaper

  • transphobic shitheel raccoon puppetmaster
  • **
  • Posts: 124
  • E-points: +12/-23
  • Rambling norn
    • View Profile
    • GreenReaper Studios
Re: FurAffinity's data scraping
« Reply #4 on: May 14, 2011, 08:33:04 pm »
It's sad that they're gone, but a fox on a trampoline is a great metaphor for those Inkbunny journals.

Pi

  • POOR IMPULSE CONTROL
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 614
  • E-points: +40/-10
  • <blink>yes hello</blink>
    • View Profile
    • Clan Spum userpage
Re: FurAffinity's data scraping
« Reply #5 on: May 14, 2011, 08:46:55 pm »
FALeaks suggests that these were built with Dragoneer's complicity. No surprise there.

I really like how they can make this disappear more quickly than, say, a security hole.
"we did farts.  now we do sperm.  we are cutting edge." — Theo DeRaadt

Freehaven

  • LOLS AND DONGS WHOLESALE
  • ***
  • Posts: 323
  • E-points: +12/-28
    • View Profile
Re: FurAffinity's data scraping
« Reply #6 on: May 15, 2011, 05:05:32 am »
Wow, talk about paranoia.

Jim Demintia

  • Postcount ate Whippany, NJ
  • ****
  • Posts: 628
  • E-points: +24/-6
  • Deflator Mouse
    • View Profile
Re: FurAffinity's data scraping
« Reply #7 on: May 15, 2011, 08:43:06 am »
On what planet, when asked (or not) to build something like this, do you make it publicly accessible? Not even a basic auth shared password, good grief.
Can it be this sad design
Could be the very same
A wooly man without a face
And a beast without a name

Eevee

  • VAPOREONWARE
  • Cabalistic Fuckhead
  • *
  • Posts: 48
  • E-points: +8/-0
    • View Profile
Re: FurAffinity's data scraping
« Reply #8 on: May 16, 2011, 07:23:06 am »
This isn't exactly a huge privacy invasion; FA journals are public and numbered consecutively from 1, so it's not too difficult to snag them all in order and then search them yourself.  yak just happens to have access to a shortcut.

Jim Demintia

  • Postcount ate Whippany, NJ
  • ****
  • Posts: 628
  • E-points: +24/-6
  • Deflator Mouse
    • View Profile
Re: FurAffinity's data scraping
« Reply #9 on: May 16, 2011, 07:45:01 am »
I was thinking more that it was just there for some random person on Lulz to see that it existed. In other words, if you build something like this, you really don't want anyone to know about it. Yet he just left it sitting there. They really don't seem to understand how "big" FA is, in that they treat it like a hobby or a toy project. You can't just throw whatever up on the public Internet and not expect this to happen.
Can it be this sad design
Could be the very same
A wooly man without a face
And a beast without a name

loki

  • **
  • Posts: 125
  • E-points: +2/-2
    • View Profile
Re: FurAffinity's data scraping
« Reply #10 on: May 16, 2011, 02:37:01 pm »
Stay classy, FA.  8) I'm waiting for them to use this as the excuse as to why the site is slow. "Sorry guys it's because we're paranoid as hell and wrote a scrapper to follow you mentioning anything we don't like!" - if they're willing to do this, how much do you want to be they also wrote a scrapper for user's notes? I wouldn't trust FA for any sort of personal info considering the fact that they really don't care and have no financial interest in protecting anything you may keep there. :I

Clayton

  • STOP POSTING
  • *
  • Posts: 35
  • E-points: +0/-35
    • View Profile
Re: FurAffinity's data scraping
« Reply #11 on: May 16, 2011, 10:07:52 pm »
if they're willing to do this, how much do you want to be they also wrote a scrapper for user's notes?
I was about to ask this too. It's extremely paranoid and definitely something they didn't want out.. 'cause they redirected it to Youtube. :\