Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


is this guy abusing Cloudflare or not?
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

is this guy abusing Cloudflare or not?

TangeTange Member

Hi everyone

i found a porn site using Cloudflare to stream their videos, i know CF has service like Cloudflare stream or Cloudflare R2 can do this job, but after checking their price, i am not sure whether this free pron site can handle the bill or not, the URL is missav dot com, similarweb shows it has 200 Million visits per month, which is huge traffic

any idea?

Comments

  • jahrincjahrinc Member

    They convert the videos into a playlist (HLS), and the fragments are "jpeg" so that CloudFlare caches it, but more so that it doesn't detect it as videos.

    This is very common in movie sites, thats why they load instantly.

  • host_chost_c Member, Patron Provider

    And now everyone is checking it out and bookmarking it.

    LOL :D :D :D

    Nice Marketing Strategy, :+1:

    @Calin

    Is this also hosted with you? :)

    Thanked by 1Frameworks
  • CalinCalin Member, Patron Provider

    @host_c said: Is this also hosted with you?

    >

    Most probality :lol:

    Thanked by 2bikrama Frameworks
  • host_chost_c Member, Patron Provider

    @Calin said: Most probality :lol:

    :D :D :D

    Figured.... :+1:

    Thanked by 1Frameworks
  • JasonMJasonM Member

    @Tange said: missav dot com

    thanks. I never knew this site. will check it out tonight!! o:)

  • TangeTange Member

    @jahrinc said:
    They convert the videos into a playlist (HLS), and the fragments are "jpeg" so that CloudFlare caches it, but more so that it doesn't detect it as videos.

    This is very common in movie sites, thats why they load instantly.

    Thanks for the reply,

    i think CF knows exactly what they are doing, their system may not detect it as videos, but they can see the huge traffic, i had program use a few hundred TBs a month, then i get an email from their sales man.

    it's wired that CF let these guys doing this, consider CF has their own streaming service, i really don't get it.

  • yoursunnyyoursunny Member, IPv6 Advocate

    @JasonM said:

    @Tange said: missav dot com

    thanks. I never knew this site. will check it out tonight!! o:)

    Are the pants wet/ripped?

  • host_chost_c Member, Patron Provider

    @yoursunny said: Are the pants wet/ripped?

    Hmmmm, why on earth would you want to know :D :D :D

  • @host_c said:

    @yoursunny said: Are the pants wet/ripped?

    Hmmmm, why on earth would you want to know :D :D :D

    Way to know quality of content without visiting :D

    Thanked by 1host_c
  • host_chost_c Member, Patron Provider

    @malignify said: Way to know quality of content without visiting :D

    ha ha ha, lol, without visiting, naaaaa

    I bet my 2 cents that everyone that read this post checked out the site, it is about curiosity, part of human nature. :D :D

  • JabJabJabJab Member

    @host_c said: I bet my 2 cents that everyone that read this post checked out the site, it is about curiosity, part of human nature.

    You lost your 2 cents now, I did not.

  • @jahrinc said: HLS
    it's wired that CF let these guys doing this, consider CF has their own streaming service, i really don't get it.

    CF seems to be very inconsistent in who they contact for "technical meetings" (aka sales)...

    Frankly, it makes then very more and more unattractive from a business point of view, because you have no clear idea what will trigger their "sales", what their forced price will be (and lets not kid around, its forced price).

    I assume that they look at the profile of the client and try to figure who has more money? I personally always hated that "enterprise" tier on pro-products because its that whole trap. Get you into the system, too much trouble to move and BLAM....

    @JabJab said:

    @host_c said: I bet my 2 cents that everyone that read this post checked out the site, it is about curiosity, part of human nature.

    You lost your 2 cents now, I did not.

    Fyi: Its just a Japanese porn site, what is frankly more interesting is the amount of movies they seem to have at 150.000+. Love to know where they got the space to host so much data.

    @jahrinc said:
    They convert the videos into a playlist (HLS), and the fragments are "jpeg" so that CloudFlare caches it, but more so that it doesn't detect it as videos.

    This is very common in movie sites, thats why they load instantly.

    Never hear of this before, thanks for the info. Frankly, makes no sense that CF does not instant ban sites like that. We are talking probably insane amount of bandwidth usage.

    I wonder if they use multi-domains to hide the traffic over a ton of proxies. Need to go check again, for ... research reasons. That is what i am telling the wife :p

  • jahrincjahrinc Member

    @Benjiro29 said: I wonder if they use multi-domains to hide the traffic over a ton of proxies

    Yeah, they have rotating domains, they just get cheap $1 domains, setup free account on CF and integrate in their system to rotate them, easy.

  • @jahrinc said:
    Yeah, they have rotating domains, they just get cheap $1 domains, setup free account on CF and integrate in their system to rotate them, easy.

    That is normally my idea but they are not doing that.

    Its basically the url with main domain / some kind of movie id / size / images.jpg
    Looking a bit deeper, and that traces back to surrit.oss-eu-central-1.aliyuncs.com
    And that goes to ... alibabacloud and basic bucket response from the API...

    For the covers they are using a different domain but also alibabacloud

    I assume the operator is Chinese?

  • jahrincjahrinc Member

    @Benjiro29 said: That is normally my idea but they are not doing that

    I'm referring to the movie sites I've seen :)

  • TangeTange Member

    @Benjiro29 said:

    at least in the past 2 month, they didn't route any domains on CF

    150.000 movies in like say 1200kbps bit rate, you gonna need around 200-300 TB space, HDD is enough because CDN handle the traffic, so it is not expensive, but like you said, they use Alibaba Cloud Object Storage Service (OSS) to store the file, that gonna cost some money

    and yes, they are Chinese, however i think they are from taiwan, not the mainland

  • LeviLevi Member

    @Tange said:

    @Benjiro29 said:

    at least in the past 2 month, they didn't route any domains on CF

    150.000 movies in like say 1200kbps bit rate, you gonna need around 200-300 TB space, HDD is enough because CDN handle the traffic, so it is not expensive, but like you said, they use Alibaba Cloud Object Storage Service (OSS) to store the file, that gonna cost some money

    and yes, they are Chinese, however i think they are from taiwan, not the mainland

    According to wikipedia, Taiwan belongs to China. They are chinese, nothing wrong with that.

  • DazzleDazzle Member

    Cloudflare is very prone to abuse. There is a method out there to abuse their referral program for the paid 1.1.1.1 VPN. It still works today, and they just don't bother with it.

  • UchihaUchiha Member

    @Tange said: missav dot com

    Thanks, a great resource for my study material folder!

    Thanked by 1emgh
  • SirNeoSirNeo Member

    So how do you know that the movies are actually thousands of jpeg images? For the normal user the movies on the site look like movies so any hint for me to figure that the movies are actually images? This is a very interesting topic

  • emghemgh Member
    edited June 29

    @SirNeo said:
    So how do you know that the movies are actually thousands of jpeg images? For the normal user the movies on the site look like movies so any hint for me to figure that the movies are actually images? This is a very interesting topic

    Check network requests maybe

    Thanked by 1totally_not_banned
  • tenjitenji Member

    @SirNeo said:
    So how do you know that the movies are actually thousands of jpeg images? For the normal user the movies on the site look like movies so any hint for me to figure that the movies are actually images? This is a very interesting topic

    Not image actually. A mpeg ts file(s). Just use mediainfo on the file to detect it. ≈≈Edit : [ I'll put some examples later, still on my phone atm ]

    As I understand it, the video split into multiple mpeg ts files which then included into .m3u8 file.
    So instead, like in mp3 player which the playlist contain multiple mp3 files, this work like the playlist contain correct sequence of those mpeg ts stream (multiple mpeg ts file) to play by the video player.

    This thing defined by name as HLS. See their explanation on wikipedia as 'HTTP Live Streaming'.
    In this particular abuse case, the file itself can be named anything as long it was a correct mpeg ts format. Each file size also small ranging from few KB to few MB. As seen by provider (Cloudflare in this case) it just normal file http(s) GET requests.

Sign In or Register to comment.