Can this (.class) file be downloaded?

Discuss the many weaknesses of browser security and ways to mitigate the threat

Can this (.class) file be downloaded?

Post by tomthecool on Fri Feb 13, 2009 1:21 pm
([msg=17824]see Can this (.class) file be downloaded?[/msg])

Ok, here's the situation: In my free periods at school, we sometimes play this awesome two player game: http://www.sciencenewsforkids.org/pages ... /slime.asp

..But today, the admins decided to block the site, since they have nothing better to do. So I decided to try and get the file, to play it offline.
I know how to download, for example, .swf files from websites - but this game is a .class file and there seems to be some sort of protection against people downloading it (I think?)

This is the relevant HTML code of the page:
Code: Select all
<applet code="Slime.class" codebase ="applet" width="800" height="400">


So I've tried going to the URL http://www.sciencenewsforkids.org/pages ... lime.class but... well, look for yourself what happens!

My question for you: Is it actually possible for me to download this game? If so, how? Thanks in advance for any responses!
tomthecool
New User
New User
 
Posts: 17
Joined: Sun Feb 08, 2009 5:05 pm
Blog: View Blog (0)


Re: Can this (.class) file be downloaded?

Post by aNewHobby4me on Fri Feb 13, 2009 1:56 pm
([msg=17826]see Re: Can this (.class) file be downloaded?[/msg])

tomthecool wrote: ...
My question for you: Is it actually possible for me to download this game? If so, how? Thanks in advance for any responses!



Why not ask Eric Peterson for a copy? Worst that can happen is that he says 'no'.
"To understand recursion you must first understand recursion."
aNewHobby4me
Poster
Poster
 
Posts: 187
Joined: Thu Jan 08, 2009 5:44 pm
Blog: View Blog (0)


Re: Can this (.class) file be downloaded?

Post by tomthecool on Fri Feb 13, 2009 3:01 pm
([msg=17829]see Re: Can this (.class) file be downloaded?[/msg])

aNewHobby4me wrote:
tomthecool wrote: ...
My question for you: Is it actually possible for me to download this game? If so, how? Thanks in advance for any responses!



Why not ask Eric Peterson for a copy? Worst that can happen is that he says 'no'.

Although I'd be happy to do that (I don't want to feel like I'm "stealing" the game, or anything - we just want to be able to play it at school!), I can't see any way of getting in contact with him :(
tomthecool
New User
New User
 
Posts: 17
Joined: Sun Feb 08, 2009 5:05 pm
Blog: View Blog (0)


Re: Can this (.class) file be downloaded?

Post by mutants_r_us_guild on Fri Feb 13, 2009 6:57 pm
([msg=17835]see Re: Can this (.class) file be downloaded?[/msg])

Hmmm.. I can't really see a way to download it .. maybe its protected in .htaccess.
However, I did find an XSS vuln.
http://www.sciencenewsforkids.org/pages ... 3E&x=0&y=0

^if the above needs removing..by all means..remove it. Doesn't seem harmful enough to worry about though.^
Image
Image
Image
User avatar
mutants_r_us_guild
Poster
Poster
 
Posts: 246
Joined: Fri May 30, 2008 7:56 pm
Blog: View Blog (0)


Re: Can this (.class) file be downloaded?

Post by xcurious on Fri Feb 13, 2009 7:12 pm
([msg=17838]see Re: Can this (.class) file be downloaded?[/msg])

lol
- Apologies to all who I have flamed in the past. Thanks mods for unbanning me.


ckw100 wrote:so i have been pacticeing my batch file hacking for networks
xcurious
Experienced User
Experienced User
 
Posts: 79
Joined: Sun Sep 21, 2008 3:49 pm
Blog: View Blog (0)


Re: Can this (.class) file be downloaded?

Post by starwiz on Sat Feb 14, 2009 10:08 pm
([msg=17911]see Re: Can this (.class) file be downloaded?[/msg])

Have you tried www.file2hd.com ?
starwiz
New User
New User
 
Posts: 3
Joined: Mon Jan 19, 2009 11:37 pm
Blog: View Blog (0)


Re: Can this (.class) file be downloaded?

Post by tomthecool on Sun Feb 15, 2009 11:21 am
([msg=17946]see Re: Can this (.class) file be downloaded?[/msg])

starwiz wrote:Have you tried http://www.file2hd.com ?

I didn't know about this, so thanks for suggesting it!
However, it does not seem to find the file either :(
tomthecool
New User
New User
 
Posts: 17
Joined: Sun Feb 08, 2009 5:05 pm
Blog: View Blog (0)


Re: Can this (.class) file be downloaded?

Post by cen on Sat Feb 21, 2009 2:30 am
([msg=18336]see Re: Can this (.class) file be downloaded?[/msg])

A while ago, I got tired of playing with issues like this and designed my own program to steal these types of files.

It's far from finished, but I've used it many times.

I haven't released it, but I'll silently make it available for a little while if you want.

You can download it off my site here:

http://cen.x10hosting.com/URLThief.rar

Copy the link to the .class file:

http://www.sciencenewsforkids.org/pages ... lime.class

Now, run URLThief, if you copied the link to your clipboard first then it will already be in the text box when the program opens. Click on Download.

If memory serves, it will download the file to the same location of the URLThief executable, unless you specified a different download path under Options.

I didn't actually test the Slime.class file, but it DID download it for me - Give it a try...

Cheers, and enjoy the program! The link won't remain active long...
Last edited by cen on Sat Feb 21, 2009 11:33 pm, edited 1 time in total.
User avatar
cen
Experienced User
Experienced User
 
Posts: 77
Joined: Mon Jun 30, 2008 1:06 pm
Blog: View Blog (0)


Re: Can this (.class) file be downloaded?

Post by IncandescentLight on Sat Feb 21, 2009 3:26 am
([msg=18338]see Re: Can this (.class) file be downloaded?[/msg])

You should inform them about their vulnerability. Then he'll probably give you the game free.
Speak softly and carry a big stick -Theodore Roosevelt

http://www.rhetoricalcatch.blogspot.com
User avatar
IncandescentLight
Poster
Poster
 
Posts: 217
Joined: Sun Apr 27, 2008 3:16 am
Blog: View Blog (0)


Re: Can this (.class) file be downloaded?

Post by cen on Sat Feb 21, 2009 11:59 pm
([msg=18380]see Re: Can this (.class) file be downloaded?[/msg])

You should inform them about their vulnerability. Then he'll probably give you the game free.


It isn't a vulnerability...

He has already given the game to everyone for free. He did this by making it available and completely unprotected, your computer likely already downloads it when you play it. Open the page and perform a search for Slime.class on your own computer and you'll likely find it - although it may even be renamed to something else and sitting in your temporary internet files folder.

The fact that the browser isn't downloading it by default is likely a simple MIME issue or something like that.

Point being, the file is already being provided unprotected on the internet.

My program performs NO magic, this is NOT A HACK - It simply removes ANY restrictions on downloading a URL from the program used to connect to the URL. If you have READ access to the file, then you can download it by providing the URL. As another example, this program WILL download PHP files - BUT ONLY AFTER the server has compiled the finished view of the script. Therefore, it's still performing the same as it normally would - I would NOT get the actual PHP script, just the output it produces.

REPEAT - THIS IS NOT A HACK - What you CANNOT do is modify the game or claim it as your own... ;-)

-- Mon Feb 21, 2009 11:59 pm --
Time passes.... passes.... A few PM's are sent - And more time passes... Oooh - Look at that???
-- Mon Feb 23, 2009 5:35 pm --

PM from tomthecool:
Using your program, all I get is the .class file which actually just contains HTML code for the web page saying "this file does not exist".

Are you sure it actually worked for you? Could you not just send me the file if it did, since nothing at all seems to be going right for me?


Wow, you're right - I never looked at the file myself, just attempted a download of it.

I can tell you this - In order to run your game you need either a Java engine to run the .class file or you need an additional web page that loads the .class file for you (an example of this is the link to the game). I have NO IDEA why the .class file contains HTML. The .class file IS the game.

I've never seen this before - My guess is that it's something server side - I briefly followed the code and am quite stumped, they either implemented some weird trick or there's some type of security being implemented here that I've never seen. I'm an excellent programmer, but I never use java, I hate it actually, but have used it to some extent in college - I would recommend getting someone REALLY competent with Java to assist you at this point. My program acted the same way with this game as it does with a .php script -Why it produced HTML code is beyond me though - It's likely the same reason why when you try to go the that URL it re-directs you back to the page again - Like I said, some kind of server side security... It's probably the way the java class was programmed - I think the game itself is detecting that it isn't being accessed properly and re-directs???

BTW, given this new info - I'm gonna have to take back what I said - I SERIOUSLY doubt it's legal to have the game anymore...

Sorry for your luck, like I said contact a Java programmer for further (and more accurate) information... You DO NOT have access to the file, it's been hidden somehow - and therefore NOT free for home use.

However, this has CERTAINLY intrigued my 'as of yet' useless notions of Java... I still hate the way the libraries work, yet somehow hate the whole project a little less now... ;)

Sorry I couldn't help more - But good luck!
User avatar
cen
Experienced User
Experienced User
 
Posts: 77
Joined: Mon Jun 30, 2008 1:06 pm
Blog: View Blog (0)


Next

Return to Web

Who is online

Users browsing this forum: No registered users and 0 guests