this post was submitted on 01 Sep 2025
52 points (89.4% liked)
Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ
64213 readers
1588 users here now
⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.
Rules • Full Version
1. Posts must be related to the discussion of digital piracy
2. Don't request invites, trade, sell, or self-promote
3. Don't request or link to specific pirated titles, including DMs
4. Don't submit low-quality posts, be entitled, or harass others
Loot, Pillage, & Plunder
📜 c/Piracy Wiki (Community Edition):
🏴☠️ Other communities
FUCK ADOBE!
Torrenting/P2P:
- !seedboxes@lemmy.dbzer0.com
- !trackers@lemmy.dbzer0.com
- !qbittorrent@lemmy.dbzer0.com
- !libretorrent@lemmy.dbzer0.com
- !soulseek@lemmy.dbzer0.com
Gaming:
- !steamdeckpirates@lemmy.dbzer0.com
- !newyuzupiracy@lemmy.dbzer0.com
- !switchpirates@lemmy.dbzer0.com
- !3dspiracy@lemmy.dbzer0.com
- !retropirates@lemmy.dbzer0.com
💰 Please help cover server costs.
![]() |
![]() |
---|---|
Ko-fi | Liberapay |
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
My bigger question is how secure is it? Looks like low trust score new Russian website, what's the chance of malware or other attacks?
It gives you literal FLAC files, how are they gonna be malicious!?
People need to stop over analyzing things, its just a qobuz ripper, people who want to help the community provide them with Qobuz tokens that don't expire as often as Deezer, now they just rip from Qobuz on your request, as simple as that. Firehawk is also building a similar site from scratch.
Well it's both possible, and has been done. both with mp3s and FLAC, not too long ago. It's not the format itself, but rather the applications parsing the files that are the target.
https://nvd.nist.gov/vuln/detail/CVE-2023-37327#%3A%7E%3Atext=GStreamer+FLAC%2Ccode+on
I mean, a website where you make requests to download many files are pretty ripe for a bate and switch scenario. That said, I'm looking for more cybersecuroty savvy folks than myself to chime in with the all-clear after doing some actual checks and analysis.
Is that when you use your left hand?
Lol, yep, then do a malicious redirection attack after getting a large user base which forces a drive-by-download of a malware package alongside the requested FLAC file.
(The joke was: you mean "bait and switch." "Bate" is short for "masturbate.")
Yes, I know, thats why I lol'ed
Im not aware its possible to put malware in a flac file and its still playable. There are a few examples from 2007-2008 but they were to do with flac media players. Microsoft showed you could corrupt the meta data but its then unplayable. I think BlueRingedOctopus comment has the right idea.