MediaDefender Anti-Piracy Tools Leaked

Written by Ernesto on September 20, 2007 

The MediaDefender-Defenders have released the source code for the “trapping” and decoy software that MediaDefender uses to spread fake files on P2P networks.

Similar to the previously released e-mails, tracking database and phone call this leak is also spread by the group that goes by the name “MediaDefender-Defenders“. In the .nfo that was posted with the torrent we read:

The source is complete for their operations regarding Kazaa, bittorrent, gnutella etc. This system is now released for the public in order to identify the decoys they set up. A special thanks to the MD employee that gave this to us.

It appears that this leak was not collected from the e-mails. The MD-Defenders themselves claim that a MD employee handed over the files to them, but this hasn’t be verified by other sources at this point.

This leak contains a wealth of information and seriously harm MediaDefender’s future operations. BitTorrent tracker owners and other admins who are involved in managing P2P networks can utilize the leaked information to brace themselves against companies like MediaDefender, who try to pollute their networks with fake files.

From the leak it seems that MediaDefender is active on virtually every P2P network, including Usenet.

Not surprisingly, most applications are dedicated to BitTorrent, which is probably their main target because of its popularity. Application names BTPoster, BTSeedInflator, BTDecoyClient and BTInterdictor make it quite obvious what they are supposed to do.

At this point it is still unclear who the MediaDefender-Defenders are and how they got their hands on all this information. MediaDefender has announced that the FBI will be investigating the source of the leaks.

To be continued?

Update: A list of leaked utilities is now available:

AresDataCollector, AresLauncher, AresProtector, AresSupernode, AresUDPDataCollector, AutoUpdater, AutoUpdaterSource, BTClient, BTDataCollector, BTDecoyClient, BTInflationDest, BTInterdictor, BTIPGatherer, BTPoster, BTRemover, BTScraper, BTScraperDLL, BTSearcher, BTSeedInflator, BTTorrentGenerator, BTTorrentSource, BTTracker, BTTrackerChecker, CVS, DCMaster, DCScanner, DCSupply, DistributedKazaaCollector, DllLoader, ED2KSupplyProcessor, EdonkeyIpBanner, FastTrackGift, FastTrackGiftDecoyer, GnutellaDecoyer, GnutellaFileDownloader, GnutellaProtector, GnutellaSupply, KademliaProtector, KazaaDBManager, KazaaLauncher, KazaaSupplyProcessor, KazaaSupplyTaker, KazaaSwarmerDest, KazaaSwarmerDistributedSource, KazaaSwarmerDownloader, KazaaSwarmerSource, MediaMaker, MediaSwarmerDest, MediaSwarmerSource, MetaMachine, MetaMachineHashSetCollector, MetaMachineSpoofer, MI-GnutellaSupply, MovieMaker, NameServer, NetworkMonitor, OverNetLauncher, OvernetProtector, OvernetSpoofer, P2PFileIndexer, PioletDC, PioletPoisoner, PioletSpoofer, SamplePlugIn, SLSKSpooferDLL, SoulSeekClient, StatusDest, StatusSource, SupernodeCollector, SupernodeController, SupernodeDistributer, SupplyProcessor, TKCom, TKFileTransfer, TKLauncher, TKProjectManager, TKSyncher, UsenetPoster, UsenetSearcher, WatchDogControllerDestination, WatchDogControllerSource, WinMxDC, WinMxLauncher, WinMxProtector, wma generator

Previously: Talk Like a Pirate Day 2007 is Here

Next: Speed Up Your Torrents With Ono

125 Responses (Add yours or TrackBack)

Pages: « 1 2 3 [4] 5 » Show All

76 Sep 21, 2007 at 09:56 by SP

How to block MD

“MediaDefender is a kind of the criminal organization which acts by the support and money of international media companies.

For your protection:
1) Download

http://thepiratebay.org/tor/3812404/MediaDefender_IPs_blocklist_for_PeerGuardian

2) Unpack.
3) Add this list to your Peer Guardian 2 program.”

77 Sep 21, 2007 at 11:58 by Octavio

No! I’m Octavio

78 Sep 21, 2007 at 12:18 by neugier

little snipplet - I find it funny that the “CEO” of MD lives with a roommate :)
Source from MDD

Quote:
On Apr 30, 2007, at 9:50 PM, Jay Mairs wrote:

Randy had a few things he wanted on the web page.

His roommate thought the selection and deletion in the lists (library, queue, favorites,history) was confusing.

79 Sep 21, 2007 at 13:16 by h33t

according to BISS, the mediadefender ip’s gleamed from the emails are for a long time already included in the bluetack blocklists also used by peerguardian. there is no new ip information in the emails that was not already known

so no need to rush to add ip’s to your blocklists, they are already there

there are new attacks coming out of mediadefender space using new ip’s which mediadefender-defender are publishing here:

http://mediadefender-defenders.com/ips.txt

add these ranges to your blocklists

80 Sep 21, 2007 at 14:11 by Lepaca Kliffoth

Has the mailtard committed suicide yet?

81 Sep 21, 2007 at 16:02 by Randy Saaf

http://bayimg.com/iaHeKAABC

THIS IS FUCKED

-RANDY SAAF

82 Sep 21, 2007 at 18:17 by An0nym0us

Its not appart of this topic really but… just a heads up

Warning to all fellow P2P members and and guests… the site FunFile.org is a MediaDefender run site and should be avoided at all costs.

83 Sep 21, 2007 at 18:35 by Omega50

Mediadefender crying because their information is being passed around? Their reps being trashed?
Stiff shit dudes, you do that everyday to P2P sites and users. Sympathy level running @ 0% and falling. If you guys can’t stand the heat, get out of the fucking kitchen!

84 Sep 21, 2007 at 21:39 by h33t

[quote comment="170116"]Its not appart of this topic really but… just a heads up

Warning to all fellow P2P members and and guests… the site FunFile.org is a MediaDefender run site and should be avoided at all costs.[/quote]

good to know. h33t was spammed with 20+ FunFile.org torrents and each has a lengthy description inviting people to download the latest and greatest from FunFile.org

they did not get past the torrent moderators because the uploads were missing any description other than the advert for FunFile.org

i can only speak for Europe and what is interesting legally is that entrapment is an illegal activity in ALL European countries. let me rephrase that for our American friends, in Europe entrapment is a criminal activity. a policeman in possession of a bag of crack trying to sell it to a customer is guilt of the crime of possession with intent to supply, for crack in Europe that is a life sentence

organised extortion of the type perpetrated by the agents of the **AA is a ditch they have thrown themselves into. on the basis of their record, European judicial systems will never permit these mobsters to gain a foothold in their systems

85 Sep 21, 2007 at 22:10 by V for Vigilante

MediaDefender asstunnels are about to do the perp walk for the botnet software.

Photo here

86 Sep 21, 2007 at 22:11 by V for Vigilante

http://i10.tinypic.com/4uu6nhf.jpg

87 Sep 22, 2007 at 08:56 by Rajeiwo.|_ { { |_

I don’t know if anyone else posted this, but apparently Mediadefender-defenders.com was hit by a Denial of Service attack. Apparently those idiots at MD think that crashing their website will make everything better. They just don’t learn.

By the way I find it hard to read the posts and article with this dark wallpaper, is there a reason for this?

88 Sep 22, 2007 at 16:35 by Jimbo

Jay,

Please confirm that the following are your current home and cell number:

Home 310.802.3208

Cell: 310.408.9722

A

These asstunnels still have their numbers active…I called from a pay phone……BTW I had a hard time finding one!

I would NOT call from your home or cell phone, I AM SURE THE FBI is NOW watching and listening!!!! Remember the Bush phone tap laws in the US… Homeland security BS.

Long Live MD-D

89 Sep 23, 2007 at 04:37 by Justin

[quote comment="169182"]It’s a shame that personal info like social security numbers made it out along with great stuff like this.[/quote]

It’s a shame people are sending completely confidential data via email which is anything but a secure medium.

90 Sep 24, 2007 at 03:11 by Opie Taylor

I listened to the conversation, and all i can say is these guys have no idea of what is happening, how it happened, and how to deal with it.

To hear the attorney getting edgy about security because of their dealings with the defender boys is quite funny.I can hardly wait until the software they were going to use is reverse engineered so it all heads back to attack defender.

91 Sep 28, 2007 at 17:28 by Mr. Select

I love sharing
It will never die!
We the people will unite and become even stronger! Long live p2p!
vivi la revolution!

92 Oct 03, 2007 at 03:12 by Anonymous

[quote comment="170116"]Its not appart of this topic really but… just a heads up

Warning to all fellow P2P members and and guests… the site FunFile.org is a MediaDefender run site and should be avoided at all costs.[/quote]

heh, care to share where you got this information?

Pages: « 1 2 3 [4] 5 » Show All

Add your response

It takes approximately 1 minute for your comment to appear on TorrentFreak after it's posted.