Secure token issueHello everyone!
I'm trying to catch rtmpe streams from the site mybeststream.xyz So far, I haven't got problems to capture streams from this platform. But since a few days, something has changed (I guess they must have added some token) Here is an example: Code:
rtmpdump -v -r "rtmpe://l.mybeststream.xyz/r/" -a "r/" -y "dolcehdw619" -W "http://mybeststream.xyz/MjJiYmQ3MjI0ZWVkZTYzZmNlYTkzM2M0OTcyZjVhMGZlMzAzN2/jwplayer.flash.swf" live=1 -p "http://mybeststream.xyz/gen_s.php?id=27281&width=710&height=440" Once this stream worked nicely. Now, instead, I systematically get the error message "RTMP_ReadPacket, failed to read RTMP packet header" (typical error due to secure tokens) Likewise, all the other streams from this platform don't work anymore for the same issue. Any help (you can send me a pm, if you like) would be appreciated. Thanks in advance! P.S: notice that the SWF path changes dynamically. So if you need to analyze the swf file, I have uploaded it here: http://speedy.sh/sw8RR/jwplayer.flash.swf |
Re: Secure token issueHahah I like to see the people crying now trying to fuck my servers bandwidth for restream or KODI :cool:
Good luck trying to rip my streams now. ;) |
Re: Secure token issueQuote:
|
Re: Secure token issue![]() Code:
rtmpdump -r "rtmpe://l.mybeststream.xyz/r/" -a "r/" -f "WIN 18,0,0,232" -W "http://mybeststream.xyz/YjdlYTI1ZjM5ZGRiYThhNmQ1NzRkM2IzNDQxY2UxNDZlY2Q2NW/jwplayer.flash.swf" -p "http://mybeststream.xyz/gen_s.php?id=27281&width=710&height=440" -y "dolcehdw619" -T "ovcast_live_streaming" | "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" - |
Re: Secure token issueQuote:
![]() |
Re: Secure token issueQuote:
|
Re: Secure token issueQuote:
and again good job! |
Re: Secure token issueQuote:
|
Re: Secure token issueQuote:
What are you using there to find it if you dont mind me asking? |
Re: Secure token issueQuote:
if you look the flash within you'll see that the token is computed so: private var _typeOfServerAccepted:String = "937a417fd8b8aaa672743035cd18f1d9b31c82f628c1600f" ; _typeOfServer = TEA.decrypt(_typeOfServerAccepted,"0x0000"); "937a417fd8b8aaa672743035cd18f1d9b31c82f628c16 00f" as securetoken "0x0000" as key. not 100% sure how denobis found the 937a417xxx part. |
Re: Secure token issueQuote:
|
Re: Secure token issueOk time to fix this, and seal the player, wait there :) ah and remember, ovcast_live_streaming token was dumb for a reason! ;)
|
Re: Secure token issueQuote:
Thanks for your help and suggestions! |
Re: Secure token issueQuote:
|
Re: Secure token issueOk, since TEA encryption is a pretty old standard, and if i start using AES with a dynamic key based on UTC on server and on player, are you sure that you can find it?
Quote:
|
Re: Secure token issueQuote:
|
Re: Secure token issueHi,
datas you can find in AS part of the file. Code:
private var _typeOfServer:String; |
Re: Secure token issueHmm hmm, yeah yeah...
Try now. ;) PS: Next time if someone crack it, the code will be obfuscated, and i'll put some entropy among the generation process. |
Re: Secure token issueHi,
your streams are no more working now and player in browser loads endless. :) Other streams of deltatv are working.I get this... (can't post all values correctly and in one line in code tags below) Code:
?‹e w?g3G“?§™s; Code:
PLEASE, **** MY BIG HEAD ****, I TOLD YOU I'M BETTER THAN YOU! greetz |
Re: Secure token issueQuote:
|
Re: Secure token issueLOL Nice message man, you really think you're clever, it will be cracked. just wait. :D
|
Re: Secure token issueCode:
token=c.r.e.a.t.e.S.t.r.e.a.m |
Re: Secure token issueQuote:
|
Re: Secure token issueOnly way is by memory searching, but well, this way i will need too fuscate all secureToken strings, realloc the position, and make my cronjob to 1 hour by hour generate a new token, i would like to see someone updating it every hour :cool:
|
Re: Secure token issueQuote:
|
Re: Secure token issueNo you will not, because i will code an HTTPProvider generating each second a new token and send it by HTTPS to the player, unless you will update it by hand you will do shit about it.
|
Re: Secure token issueQuote:
I think you completely misunderstood my real intentions, as I did not want to play a nasty trick nor I invited you to a war of mice and cats. Who cares of f***ing your servers bandwidth, I just asked for help to play on VLC a rtmp stream freely found on the web. What's wrong with it? Do you think that people watching your streams on your website, instead of using VLC, spare your servers bandwidth instead? Besides, I feel really surprised and disappointed by your arrogance (also proven by the rude words you put in your swf code), which doesn't fit to the professional role of someone who provide an internet service. Your obsession for obfuscating and re-directing all the time seems more like an escape, rather than as an attempt to protect the content of what you host. If you really care about what your website hosts, you'd better simplify things instead of complicating them with pseudo-urls and pseudo-keys. Otherwise even legitimate copyrighters will find it extremely difficult to report possible violations because they won't be able to trace the real source of your hosted streams. P.S.: being too arrogant and sadist with rtmp dumpers does not help, because the people who want to view a free stream on VLC can be your potential clients too. I hope you'll be seriously thinking about that, because your way of behaving is the worst promotion you can offer for your service. |
Re: Secure token issueQuote:
Im not a bad person, trust me, and believe im very very professional in what I do, and those messages in the source code of the player, well, if they don't want to see them, just keep the eyes way of it. |
Re: Secure token issueQuote:
Your streams are a) freely available on the internet b) you CHOOSE to do so with servers you HAVE to pay for. If people can play them in VLC, they will. i will help with that because that is what is asked of in this thread. If you want real protection get AES-128 via m3u8. rtmp is not secure unless you are Hulu. |
Re: Secure token issueHi,
Ok I see your channels are working if I disable ASD Blocker. :) One reason why people don't wanna watch your channels on your website is that you use a lot commercial stuff on the player screen itself and the user has to click them away which popups another sites so nobody want this but you do force people to do that if they wanna watch directly on your site.Maybe a little less of that ADS would be better for your site to get also a better reputation.At the end you shouldn't wonder if people don't wanna watch your channels on your site and try to pipe them on home PC player.I am just talking about normal channel watcher only not about any steal / re-streaming etc. About token... Code:
https://mybeststream.xyz/key.php?bandwidth=1.7976931348623157E308 |
Re: Secure token issuethis cunts server needs a ddos, then we shall see who makes money,
hwahwahwa |
Re: Secure token issueCan someone please help to decrypt this link? I think this is using AES on M3U8.
http://72.21.81.253/80112A1/50770rse...cedd34a7c58fec Thank you. |
Re: Secure token issueQuote:
Maybe... |
All times are GMT -6. The time now is 10:11 AM. |