📜 ⬆️ ⬇️

Do you protect files on the People.Disk?

It is believed that it is impossible to download a file from the People.Disk without knowing the link to this file.
At least I got the impression.


Recently I received two links to files of the form:
narod.ru/disk/11243067000/...r.rar
narod.ru/disk/11370765000/car1.rar
and asked to download files.

When it came to downloading files, two unpleasant facts were discovered.
1. Downloading from People.Disk only one file at a time is possible (limiting using cookies)
2. The first link was shortened by the “caring” forum and it has now sunk into oblivion.
If you go to narod.ru/disk/11243067000/...r.rar , Yandex redirects the user to error 404: narod.yandex.ru/404u.yhtml
404
')
Frustrated, I decided to download at least one file, with a surviving link, and found an interesting point.

If you go to the link narod.ru/disk/11243067000/...r.rar during the download of another file, Yandex shows not a 404 error, but reports that "It is impossible to download several files at the same time." And displays the full name of the file, which I was going to download. In this case, "! Neck_handler.rar". Later it turned out that during the download of the file, Yandex doesn’t really matter what the user writes in the address bar after the last slash.
! 404

Now, if you replace “... r.rar” with “! Neck_handler.rar” in the link, you’ll get narod.ru/disk/11243067000/!neck_handler.rar and you can safely download the file from Folk.Disk.

This focus works with any file on Narod.Disk. It is enough just to replace the number “11243067000" with another one and
substitute the file name after the last slash.
Thus, anyone can access almost any file on the People.Disk.
(except for password-protected files)

Do you protect files on the People.Disk?

PS Authorship is not mine - a friend who does not have a residence permit on Habré.

Source: https://habr.com/ru/post/66161/


All Articles