this post was submitted on 01 Sep 2025
52 points (89.4% liked)

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ

64213 readers
475 users here now

⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don't request invites, trade, sell, or self-promote

3. Don't request or link to specific pirated titles, including DMs

4. Don't submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder

📜 c/Piracy Wiki (Community Edition):

🏴‍☠️ Other communities

FUCK ADOBE!

Torrenting/P2P:

Gaming:


💰 Please help cover server costs.

Ko-Fi Liberapay
Ko-fi Liberapay

founded 2 years ago
MODERATORS
 

This is such a great music service but I'm wondering who is behind it and why they provide it? It must be costing them something to host the site. Interesting that Cloudflare stats show its biggest user base is India.

top 22 comments
sorted by: hot top controversial new old
[–] SaltySalamander@fedia.io 41 points 2 weeks ago (1 children)
[–] 10x10@lemmy.dbzer0.com 6 points 2 weeks ago

If I was I'd be earning a lot more than I do at the moment.

[–] SanctimoniousApe@lemmings.world 24 points 2 weeks ago (1 children)

First rule of Fight Club...

[–] 10x10@lemmy.dbzer0.com 5 points 2 weeks ago

Fair enough. Thought that after I posted.

[–] LiamTheBox@lemmy.ml 9 points 2 weeks ago (1 children)

Seems to be open and allow community apps to work with the site.

https://dab.yeet.su/download

I wonder if FMHY is aware of it.

[–] 10x10@lemmy.dbzer0.com 3 points 1 week ago

Its on fmhy site here https://fmhy.net/audio Has invite link to Discord and Telegram

[–] Coopr8@kbin.earth 6 points 2 weeks ago (2 children)

My bigger question is how secure is it? Looks like low trust score new Russian website, what's the chance of malware or other attacks?

[–] BlueRingedOctopus@lemmy.dbzer0.com 7 points 2 weeks ago (2 children)

It gives you literal FLAC files, how are they gonna be malicious!?

People need to stop over analyzing things, its just a qobuz ripper, people who want to help the community provide them with Qobuz tokens that don't expire as often as Deezer, now they just rip from Qobuz on your request, as simple as that. Firehawk is also building a similar site from scratch.

[–] chirping@infosec.pub 1 points 2 days ago

Well it's both possible, and has been done. both with mp3s and FLAC, not too long ago. It's not the format itself, but rather the applications parsing the files that are the target.

CVE-2023-37327: A remote code execution vulnerability in GStreamer’s FLAC file parser caused by an integer overflow. Carefully crafted FLAC files could exploit this flaw to run arbitrary code on the target system

https://nvd.nist.gov/vuln/detail/CVE-2023-37327#%3A%7E%3Atext=GStreamer+FLAC%2Ccode+on

[–] Coopr8@kbin.earth 6 points 2 weeks ago (1 children)

I mean, a website where you make requests to download many files are pretty ripe for a bate and switch scenario. That said, I'm looking for more cybersecuroty savvy folks than myself to chime in with the all-clear after doing some actual checks and analysis.

[–] ArcaneSlime@lemmy.dbzer0.com 4 points 1 week ago* (last edited 1 week ago) (1 children)

bate and switch

Is that when you use your left hand?

[–] Coopr8@kbin.earth 2 points 1 week ago (1 children)

Lol, yep, then do a malicious redirection attack after getting a large user base which forces a drive-by-download of a malware package alongside the requested FLAC file.

[–] ArcaneSlime@lemmy.dbzer0.com 1 points 1 week ago (1 children)

(The joke was: you mean "bait and switch." "Bate" is short for "masturbate.")

[–] Coopr8@kbin.earth 1 points 1 week ago

Yes, I know, thats why I lol'ed

[–] 10x10@lemmy.dbzer0.com 4 points 1 week ago* (last edited 1 week ago)

Im not aware its possible to put malware in a flac file and its still playable. There are a few examples from 2007-2008 but they were to do with flac media players. Microsoft showed you could corrupt the meta data but its then unplayable. I think BlueRingedOctopus comment has the right idea.

[–] drspod@lemmy.ml 3 points 2 weeks ago
[–] Kissaki@lemmy.dbzer0.com 2 points 1 week ago (1 children)

It must be costing them

From their Terms:

DAB Music Player does not host any copyrighted content. Our Service acts as a search and streaming interface that connects to publicly available APIs. We do not store or distribute copyrighted material.

When you open the Webbrowser Developer Tools, Network tab, you can see where it streams from.

When I check on a song, it streams it from a CDN of qobuz (qobuz.com).

[–] 10x10@lemmy.dbzer0.com 1 points 1 week ago

I was thinking of the cost of hosting the site rather than paying for the media. Thanks thoigh for the comment about checking the stream source.

[–] 10x10@lemmy.dbzer0.com 2 points 1 week ago

Looking through the discord group it looks pretty straight up. Part of the project is an android music player.

[–] elucubra@sopuli.xyz 2 points 1 week ago

I have the same questions about Stremio.

[–] stupid_asshole69@hexbear.net 2 points 2 weeks ago (1 children)

No keep going I just need one more square to turn “non-western hosting”, “free”, “mysterious”, “only used by Indians” into a malware bingo!

[–] arararagi@ani.social 8 points 2 weeks ago

To be fair, only non western hosting is copyright resistant.