ATTENTION: 1337X IS NO LONGER SAFE [Reposted from Reddit]

Madiator2011@lm.madiator.cloud to Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ@lemmy.dbzer0.com – 925 points –
195

Response from the admins

From where I'm sitting it looks like classic overconfidence. I would say keep your eyes open in the future but don't pick up the pitchforks just yet.

Thanks. This community needed your logical input. I've been following this over the past few days and it seems like a blatent Reddit-type pitchfork situation. Based on the mods response and the absolute lack of proof surrounding the mods profiting from the crypto miner (honestly who the actual fuck even came up with this?), I think we need to all take a beat.

Also I don't follow cracked games but this Emperess person seems like a fucking psychopath and the fact that literally anyone here believes a word she says is absolutely astonishing.

I am asking this community to PLEASE STOP REPOSTING THIS. Don't let this community follow the ways of Reddit, please. We are better than that.

I agree, this entire thing looks very blown out of proportion to me. It's not the first time and not the last time there will be malware in a brand new game torrent on 1337x.

This exact situation has happened before with a new game torrent that had malware, torrent eventually got taken down, and nobody raised a huge fuss other than not to download that torrent.

I feel like this community and the reddit one are made up of 14 year olds who figured out how to torrent 2 weeks ago and are freaking out over the prospect that downloading exe files isn't safe....who would have thought!

You can feel their frustration in this post. Being a mod is a thankless job.

So why did he defend the torrent in the comments and said it was not dirty and the uploader is not banned? This defence is laughable.

1 more...

You know it's bad when the almost constantly unhinged 'Empress' is the one speaking sense.

You looked at that screenshot and said, "Ah yes, here's someone speaking sense" ?

Haha, yeah okay perhaps sense isn't the correct word.

I’ll translate: “I find actions of the 1337x admins disappointing. Deleting my torrents causes confusion for the user base, and these actions reflect poorly on your character, suggesting pusillanimity and insufficient discretion when selecting a sexual partner.”

I see Empress is still subtle and classy as always.

That post is a bit older IIRC, couple of months.

Someone posted it because of relevancy i guess. Your point might still stand, i haven't heard anything about him.

Fuck Empress, however she's right on this specific matter.

I guess if you lash out at absolutely everybody, eventually one of them will do something to deserve it.

What's wrong with empress? I really don't follow this stuff much.

That was one of the coolest reads ever! It reminded me of the podcast darknet diaries

This was written before her anti trans rant released with Hogwarts Legacy, too. Although I guess she had said some anti-trans stuff before that.

Wow, thanks for sharing this chunk of internet lore. I never torrented any games so I didn't know there was so much more behind it than torrenting movies.

Thank you for that link. Haven't been pirating for many years now (at least not to even remotely the same degree), so I knew nothing about all of this. But a very interesting read regardless

4 more...

I don’t know why, but I think calling people “pathetic cowardly whores” in this specific situation is hilarious.

What, exactly, does one have to do when moderating a torrent site to earn the title of “whore”?

Well, doing something "wrong" for money is basically the definition of a whore, so yeah it fits in this case if the alligations are correct.

3 more...
3 more...

I wouldn't trust anything from a P2P site that purports to be:

  1. A cracked game / application for desktop and mobile platforms. Maybe it's legit but assume it is malware.
  2. A serial number generator. If you absolutely must run one of these do it from a throwaway VM, or via WINE emulation to mitigate what it might do.
  3. An encrypted archive with a README. It's a scam designed to make people sign up to other scams to release a non-existent password.
  4. A movie / audio with an extension such as .scr, .wma, .com, .exe etc. It's malware.

Movies, audio & books are generally safe providing they use a recognized extension - mp3, mp4, pdf, mkv, aac, flac, epub etc. Stuff that runs under emulation like console games is generally safe. I say "generally" because an exploit could still be crafted to escape a popular media player or emulator and cause actual harm to your computer.

All the ads and 3rd party scripts should be considered malicious too and should be erased with an adblocker, or even better use Tor.

So basically use some common sense and if you really want some game or app, just buy the damned thing or wait for it to go on sale.

WINE is not safe to run malware in, it's not a secure sandbox. AFAIK, anything expecting it can do anything a Linux binary can. (Also, not an emulator, it's in the original name - WINE Is Not an Emulator)

I know what WINE is and the gist of "Wine is not an emulator". I have used it extensively and for a while it even contained some of my code (not sure if it still does). But it is still emulating but not in the way people think. WINE is not emulating the operating system but it is emulating the interface that an executable interacts with Windows, aka the Win32 APIs and other DLLs.

They even touch on this in their FAQ - *That said, Wine can be thought of as a Windows emulator in much the same way that Windows Vista can be thought of as a Windows XP emulator: both allow you to run the same applications by translating system calls in much the same way. Setting Wine to mimic Windows XP is not much different from setting Vista to launch an application in XP compatibility mode. *

As far as a potentially malicious executable is concerned, you can create a throwaway wine folder to run the thing and delete it as soon as it is done, e.g.

e.g.

export WINEPREFIX=~/tmpwin
winecfg
# disable wininet from libraries tab, remove Z:, unlink all desktop integration folders
wine keygen.exe
# when done...
rm -rf tmpwin

It doesn't matter if keygen.exe is evil because it can write anything it likes to the fake C: and the fake registry and it's blown away. As a precaution disable networking so it can't reach out either. In the extremely unlikely event that keygen.exe had code to detect it was running under WINE, it would still be subject to the permissions of the uid you had run it as, so you could take even more precautions if you felt so inclined. You could even use a dockerized WINE if you felt like it.

On the topic of whether or not it's an emulator, sounds like semantics in the end - fair enough, I disagree but you make a fair point.

That said, in terms of security I think it's very important to point it out that it isn't any more secure than running a random Linux executable. In my view, the original comment is advocating for running unknown executables under wine as a security measure, and the further argument is that it's more secure because most attacks don't target that.

Sounds like if people rely on that for security, malware will just start targeting that after people get used to assuming it's safe.

I doubt many people are ever going to do what I suggested so the effort / payoff for malware writers makes it very unlikely they'd bother. They'll just assume 99.999% of people running the binary are doing so on Windows and code accordingly. Of course anything is theoretically possible.

wine is a windows api implementation, it's specifically NOT an emulator

Read their own FAQ. It's not an emulator in the classic sense of emulating the OS. It is however emulating the API of Windows. I quoted the pertinent line of the FAQ elsewhere and made my point clearer

Not sure what the thumbs down is about. It's right there in their own FAQ.

In fact it ends by saying - "Wine is not just an emulator" is more accurate.

There is a storied history in computing to use tongue in cheek self referential acronyms to denote some humor and finality in distinguishing things that purposely fill a niche in the world of competing, often pricey, commercial software and other hackable reasons.

So I bet you're rubbing wrong those of us who remember that gnu is not unix, and more specifically wine is not an emulator. Because they really aren't.

  1. You could trivially verify an emulated game with a checksum

  2. If a game is released on GOG, there are Checksums that are hidden from the user. GOG games are DRM-free, so there's no reason anyone would modify the installer.

Are cracked games no good anymore? You used to be able to get just about any cracked game back in the day. Sure, some of them might be malware, but it was easy to find one that wasn't.

It's a screenshot of a tweet so you know it's true

It's definitely a real Tweet but I agree, if you visit the site to take a screenshit why not just copy that damn link!

Cool, then what will be the 1337x alternative?

private trackers are the only truly safe option left

Out of the loop, private trackers?

Private sites that people upload torrents to. A lot of them have requirements like “upload at least 1 content that we don’t have” and “must maintain a seed ratio of x”. Most that I’ve seen either have closed registrations, requiring someone to invite you as a referral, or they have interviews to make sure you’re not malicious”.

I’ve always wanted to be in one because every once in a while I can’t find content that’s old/obscure and it’s super annoying and supposedly private trackers have a bunch of old/obscure content as-well as super new stuff like blu ray rips and native stream rips.

A lot of them have requirements like “upload at least 1 content that we don’t have” and “must maintain a seed ratio of x”.

I can attest to seeding requirements, but I've seen lots of private trackers, and only very few have rules like "upload at least 1 piece of content that we don't have." I would say those ones are in the minority, and most are happy to accept people who only download as long as they keep seeding and keep their ratios up.

I’ve always wanted to be in one because every once in a while I can’t find content that’s old/obscure and it’s super annoying and supposedly private trackers have a bunch of old/obscure content as-well as super new stuff like blu ray rips and native stream rips.

Depends on the tracker. Cinemageddon literally only traffics in B-movies and so the worse and more obscure the film is, the more likely it is you will find numerous copies on CG.

Can you please explain the difference between seeders and leechers?

Givers and takers. Seeders have the complete file and leechers are currently downloading the file.

The way torrenting works, you're getting different parts of a file from different people, while at the same time you're also sharing the little parts you've received so far with other recent downloaders.

Seeders are people that already have the full file and are spreading (seeds) for other users to download through the same torrent.

Leechers are those that are currently downloading the file but still have not finished.

The term "Leecher" is also used to call those that delete the torrent as soon as it finishes dowaloading. It's good practice to seed it (upload), at the very least, for the same amount you downloaded.

So everyone is a leecher until the file is downloaded and you tou only become a seeder by allowing the upload to finish? Is that correct? Sorry, just got done driving 17hrs so my mind is a little mush.

Mostly you've got the right idea. Important to note that seeding is not only done after you have 100% of the file downloaded (the whole time you're downloading you are also uploading back the files you already have up to that point) but private trackers mostly make the assumption that anyone in the peer swarm that isn't at 100% yet is leeching until proven otherwise.

Oh okay. Thank you so much for taking the time to explain.

EDIT: I think it is amazing that I have 10 upvotes, and -1 downvotes, resulting in 11 upvotes.

invite only torrent sites.

reddit used to have its own private tracker, baconBits, spawned on christmas day 2009. It shut down May of last year.

there's plenty of others, though.

The benefit of private trackers is that since they're invite-only, you don't really run the risk of running into copyright cops who want to send you cease and desist notices. They generally tend to go for the easy fish at the public trackers like 1337x and torrentgalaxy. There is a sort of "circle of trust" on private trackers and it can be really easy to get your account banned if someone you invite got banned. They take the circle of trust pretty seriously on a lot of them. (That sounds more scary than it is, I've never seen it in practice, but the general rule is "don't invite people who will cause trouble, because you'll be accountable for their behavior since you invited them.")

Also, many private trackers have an upper limit on users, and stop accepting new users when they hit that limit. Keeping user bases small also keeps you more "under the radar."

Finally, private trackers are also a source of many scene groups releases, so if you get on certain trackers, you'll have faster access to certain releases.

I hate being that bitch but I gotta clear up:

“The benefit of private trackers” is what this poster meant.

Thanks, I put this comment up half asleep before work earlier. Corrections edited in.

I see your edit—I use Memmy and I used to be able to see separate downvotes and upvotes, but I cannot anymore. I miss that! Maybe it’s a setting somewhere. I didn’t downnvote ya and I’m sure everyone else didn’t because your comment was helpful and we could understand in context what ya meant ;3

I hope your helpful butt is already on all of the private trackers you desire to be on! I’m on a couple I love, but there’s always the white whales of trackers I can’t be assed to work my way up to hahaha

Invite only torrent sites.

Retention and availability of seeders is higher.

You have to seed each torrent for a certain period of time at minimum (usually a week or so) and maintain a good overall upload/download ratio total (1.0 +)

🌍👨‍🚀🔫👨‍🚀

Always has been

I subscribed to a usenet service. Still figuring out how to use it 🤔

Look for releases on the sites of the groups / ppl releasing them. Most offer trackers they seed to.

Other than that and private trackers, I like torrends.to to meta search for torrents, but there proceed with caution.

Oh didn't know there was another meta search site like torrentz2. Thank you for the info!

thepiratebay.org what else would it be? #sweden

Hmm I've heard that site nowadays is just the shadow of it's former self.

1 more...

For those asking “private trackers what’s that?”

/r/trackers (on the bad site I know) has a lot of info

For those who may be interested in getting into private trackers, you should start with Myanonamouse.net in my opinion. They do an interview on the irc which is easy and you can join that way https://www.myanonamouse.net/inviteapp.php

It is a tracker for ebooks/audiobooks/comics that is easy to maintain a ratio on (via their generous bonus point system) as long as you are a decent seeder.

Once you’re on the site for a few months you can access the invite forum which can get you access to other private trackers. Think of it like a ladder.

Torrentleech (a general private tracker) occasionally has open signups throughout the year.

I’m on multiple private trackers, and they all hosted the infected version (they’ve been taken down now). Private doesn’t make it safe, especially when people are using automated tools to be the first to upload a torrent.

I didn’t say anything about that and don’t disagree but private trackers definitely have less of it due to their content having more scrutiny and standards.

Nothing is perfect. My comment only strived to let people know about private trackers as I saw multiple people ask about it.

The best way to get invites is to make friends with as many people on irc as possible

Thanks. Looks like the registration window is closed. I’ll check back soon!

12 more...

I know this is probably obvious to many people, but if a charitable soul could explain to me what a miner is and why the admins are involved in it, it would be very much appreciated. Also, explain like I am 5 if possible

A cryptocurrency miner. It uses your computer to generate currency, which costs you resources (electricity, compute power, etc.).

Was anyone under the impression that everything on the site was free of malware? Has such a torrent site ever existed?

The problem isn't that there is malware on the site, it's linked to admins as distributors.

Who would have though pirates would try and pirate hardware? Guess there is no honour amongst pirates.

I couldn't care less if someone made a clone of my CPU to use for themselves. This isn't the same as pirating

There are plenty of good torrent sites with upload verification. They are rarely public though.

What evidence has been found that links the crypto-mining wallets with the 1337X admins?

Literally nothing. This entire thing is one of the stupidest controversies that I've ever seen. One idiot made a wild accusation about the 1337 mods based on no evidence and apparently that was good enough for this community....we are better than this people, grow up.

See my reply to Whiskey Pickle for the evidence.

I read through the wayback link you had, but it really just sounds like admin are busy with their other lives and getting frustrated with new users spamming "trojan found" which is an extremely common thing to see from new users and they don't have time to verify everything out there. Even saying it has "unpacker.exe" wouldn't mean anything as the release was packed. Unless the wallet address can actually be tied to admin/mods, then that's just heresay.

That VitaminX user sounds shady as all hell, but that doesn't mean admin are doing backhanded deals with some users.

There is literally no public torrent tracker out there that has no issues...

At the risk of asking an incredibly stupid question, but if I only ever torrent video/audio, scan everything I download with defender, and only ever use a recently updated version of vlc, what's the risk?

I remember getting viruses in ye olden days, but afaik the main problem is malware now.

Risk is practically nothing in your case, because you're being careful, and know what you're doing. You won't run a binary when you were expecting the Barbie movie, for example.

If you were downloading binaries, then your risk is significant, but even then, unless you're downloading new releases immediately, it's likely that your antivirus will catch the new popular ransomware after a few days, when a few thousands of people have become infected. Governments won't employ valuable zero-days on any rando who just wants to see their new isekai episode.

If you're using Windows, just make sure file extensions are visible and that your file isn't named Movie.mp4.exe

This is about a game, which is a .exe. In your case, it's probably not an issue, but games will be. Pdfs also had an issue for a while, but I think that's solved. As far as I'm aware, there aren't any video/audio codec or VLC issues to be worried about though, so you should be good.

Movies and audio are very rarely infected, almost never. That depends on bugged software, so that you can be relatively safe of.

Executables... well... no anti virus can protect you in reality from dumb double-clicks. This is because viruses are trained against anti virus software until they can't be recognized. There are mathematically an infinite number of patterns to run a program to trick all kinds of anti viruses. So in reality you can't be safe. Once that's done by an expert virus creator, the best you have to protect you is a behavioral detection of viruses, which may or may not work.

So, don't rely on anti viruses. They barely protect you from script kiddies and legacy viruses.

why do you have to pirate VLC, just go to the website and download (or even compile from source)

He doesn’t pirate VLC, he pirates the audio/video he plays with it and asks if there is any danger in that.

Not what they're asking, read closely. They're curious about the risk from using pirated audio or video material (not executables). VLC is only mentioned as their player of choice, so it's easy to assume they've already got it installed.

God people come on!! This is not the first time this happening , 1337X is still a very reliable and trusted source for torrents , don't make up things. If you are so worried about security pay for the damn game. Its free and you are still asking the mods to be vigilant 24/7 for every single torrent upload it come on people that's impossible. I bet many of you here complaining about 1337x wouldn't last a day being a moderator in this site.

Isn't this ignoring the whole thing in the link about negative responses being removed?

Sure you can't have mods being vigilant 24/7, but the link seems to be arguing they're being vigilant in keeping the bad link up.

Tbf, people comment on almost any software with "keygen flagged as Trojan! Avoid!!1!" There are a lot of folk who aren't as on the ball with this stuff that don't know how anti-virus works or what a false positive is. It does get annoying dealing with those folk.

They're not really backing their claim up though in regards to "related to admins" and "admins are deleting other people's warnings".
And as far as I know the torrent has been pulled even.

Uploads are disabled for new accounts, how can it be so hard?

Uploads are disabled for new accounts

This is simple to bypass. Accounts must be 30 days old to upload?

Create an account or 3 each day.

Post using the newly mature accounts till they get banned and move on to the next one.

how can it be so hard?

A simple solution to a complex problem is usually wrong.

Does this mean we should remove it from the megathread?

Meh this is one instance that just keeps getting reposted every couple days. Pirating executable files has always been a risk and brought with it issues like this. There is little risk with music, tv, and movies.

All the more reason to have a list of safe(est) sites. I can't always afford games and when I do I prioritize multiplayer ones so I can play with friends. If I really enjoy a single player game I'll go back and dish out for it of course but there are way too many bad, halfbaked, cashgrab landmines that will outright rob me and others if we're not careful. Games are the biggest industry right now which means it's ripe for bad actors.

I still think it's weird that the admins are doing this...

The admins have nothing to do with this. The comments left on the torrent were from the uploaded and a single mod.

No. 1337x isn't any more or less dangerous than any other torrent site (except rarbg, rip). Can we all stop this nonsense?

I have seen multiple posts about the situation by now with various claims but no one seems to have actually looked into it so I have questions! Is it true that moderators defended the upload and silenced criticism, is it true that the crypto address in question can be linked to the sites admins and is it true that the same malware is all over the internet in countless releases? Not all of those are from this particular pist but if someone here knows the answers I would be happy to read them!

There is a discord group in the official 1337x subreddit, the user was just a vip user, not a staff/moderator and he deleted comments after posting a malware in order to keep the release alive. Maybe he was trusted before posting it, and 1337x staff are a few people (lately even less) so he wasn't blocked quickly. Nothing more. I hope 1337x will make an announcement. The user who posted malware was under a blue nikname:

  • Black - admin
  • Green - moderator
  • Blue - vip
  • Yellow - uploader
  • Red - trial uploader
  • Grey - user

There wasn't any member of the staff that was helping the vip user to delete comments. He was just deleting comments under its own post by himself.

There is no official 1337x subreddit or discord group. Go to the 1337x official chat room (link on the front page of 1337x.to) and ask about a discord group or sub reddit and they will tell you its fake.

Thanks! I don't know why a VIP would have this kind of power but that's exactly the kind of explanation I was looking for because (as usual) a lot of people claim all kind of shit whenever they get a chance and it can be hard to understand what actually happened, glad it's not as bad as it seemed at first glance! :)

But that doesn't make it better. It makes it worse. So there is a VIP who uploads a miner. First the mods defend the VIP and the upload but later have to admit that it's a miner. Then mods can't do anything because the admin, the only one who could ban the VIP and uploader is AWOL since who knows; a long time. So effectively the topic is correct, the site is not safe. Uploaders can do what they want and cannot get punished because the few mods left can't do anything and the admin is missing.

So the VIP can't even be banned by a mod? That's a fucked up system and I can only woder why it worked at all for such a long time!

That's at least what the mods claim in defense that the uploader is not banned. But don't forget, the same mods also said that the upload is "not dirty" until they had to admit it had a miner included.

I honestly don't get why this behaviour gets defended here. Only because Empress was quoted? And that quote hasn't anything to do with this incident.

I'm very doubtful too. Crypto mining isn't profitable on computers nowadays. You would need millions of infections to even generate a dollar a day. It doesn't make any sense that someone would work on such malware

With enough machines (especially powerful gaming rigs) you could probably still make a really decent amount and since the malware is detected by common antivirus tools and even Windows Defender as far as I can tell it's most likely old and just used again by someone but you always have to be careful with all claims in the cracking scene and considering how long that site has been reliable I definitely have my doubts!

Even if 100% of all pirates on earth downloaded it, it would still earn shit

It's one torrent that's not safe. That doesn't make the entirety of the website unsafe!

If the admins endorse malware, it's best to assume the entire site is compromised.

Before even worrying about the content of individual torrents people should worry about the sites themselves being full of ads, spyware and other garbage that generates revenue for shady people. There's a reason beyond just privacy that people use rss and magnet links. In an ideal scenario you never go to an actual torrent website.

Public trackers have never been safe. Why not find a better tracker for your games or just buy it. Assume anything you have to install is infected

What's the alternative?

I use torrentgalaxy.to now. Or some search engine like solidtorrents.to, this one's neat since it does not have any ads.

There are few. For most of stuff there's fitgirl and for things that are outdated or not available there (like empress) there's dodi.

What else is there for movies and TV tho? 1337x and pirate bay are all I really know, and they're both pretty dubious.

I miss Demonoid so much 😭

I use yts.mx for movies and they have a site for tv shows too, i think its ytstv.mx

In the middle of this controversy there is just one thing I don't really understand: why haven't they banned the offending account?

From what I read, the admin of the site is long gone and they don't have the power to ban uploaders.

Buddy it’s been posted here a dozen times since BG3 release

The difference this time is that Empress was angy wangy and had to cry.

In reality it was indeed a few bad releases of a popular game on a popular site... 1337x constantly had these. Just like Pirate Bay had them. I never go there expecting safety in the first place.

Was tempted to download it last night.

what do I do if I have downloaded and installed the infected game?

If possible, turn networking off!

Dealing with viruses:

  • Get a linux iso and scan potential threats with ClamAV/TK.

  • Fresh install (If you are paranoid.)

  • Manually find and remove dangerous software. (VirusTotal may help.)

i was never really convinced of that site anyway. the agressive ad monetization made me feel like they were just in it for the cash.

Who the hell sees ads? If you choose to let your browser run them, well, what do you want?

i have all of the top 3 most popular adblockers and i still get redirected to scam porn websites.

Three ad blockers? One of them is fake and serving you ads. Or is allowing ads through because they are getting kickbacks. Or one of your other add-ons is serving that crap. Purge all that shit and start over.

Just use uBlock Origin and the site wont show any ads unless you have adware on your computer

The world hasn't changed, theres just less in it.

I got baldurs gate from igg-games, does anyone know if I'm safe? I'm asking for advice dunno why I'm getting down voted xD

Igg has a shit reputation for adding malware to their torrents. I think it’s hit and miss, but better to avoid them than risk it.

Just get it from fitgirl. Can't confirm for this game as I actually bought it, but I never had issues before.

Igg-games is a very bad site to download anything from. There has been known malware in the past and the owners of the site are garbage.

Rule of the Internet do not trust anyone and it’s always wise to scan anything you download from Internet.

Lmfaoo fuckin love empress so much.

i mean shes a terrible person but she is pretty comical. Also her being told in a dream that she has to crack games is pretty funny lmao

The woman cracked Denuvo, keep in mind. Multiple groups have declared this feat impossible.

When your dream tells you to do something impossible, and you proceed to do that thing successfully, then maybe the dream wasn't so crazy after all.

1 more...
1 more...

She's one of the strangest, most insane individuals I've ever seen on the internet, which is only compounded by the fact that she's insanely good at what she does. I love her too.

The Scene needs more women content creators as well.

2 more...