xlak / hapara-delete

How to disable Hapara and other school spyware
22 stars 5 forks source link

Can you help find one that works on Securely? #1

Open GhostieKoto opened 1 year ago

GhostieKoto commented 1 year ago

Thanks

xlak commented 1 year ago

There is already a section on Securly. Are none of the bypass methods working for you?

GhostieKoto commented 1 year ago

none of them do, no

xlak commented 1 year ago

Securly has both a Chromebook extension and a network-wide filter. Which one of them are you trying to bypass?

If it's the extension, you can use the Alphabetic exploit to hide tabs from it. (It's not supposed to completely disable the extension.) If the Chaos exploit is running but not disabling the extension, please send the extension ID here so I can add it to the list of IDs to target.

If it's the network-wide filter, you will need to find a proxy site or a VPN that isn't blocked. You can join the Titanium Network discord to find new proxy URLs. The Alphabetic exploit should also work to bypass it if the extension is active at the same time.

GhostieKoto commented 1 year ago

The Chromebook extension.

Are you able to upload to the chrome web store?

Message ID: @.***>

xlak commented 1 year ago

Unfortunately not at the moment. There's a fee to do that.

If your school's IT admins were actually silly enough to leave untrusted extensions enabled, there are plenty of existing Chrome extensions that let you bypass extension-based filters. One of these is Leaf Browser.

Would you mind giving some more details about how exactly the bypass methods aren't working? I would like to get Chaos and Alphabetic working for as many people as possible.

GhostieKoto commented 1 year ago

Yeah, they found those. They just recently got rid of the last one I could find, called FHS rocks.

I was gonna upload to the chrome web store, but then saw the fee :/

Do you know any other proxy sites then?

Message ID: @.***>

xlak commented 1 year ago

Try the proxy sites listed in this repo. If they don't work then join the Titanium Network discord to get new proxy sites.

GhostieKoto commented 1 year ago

is there a javascript bookmarklet that can delete an extension by ID or something?

xlak commented 1 year ago

That's what LTBEEF and Ingot do, but they're patched in version 106 of Chrome OS.

I probably should have asked way sooner, but are you using a Chromebook or another type of laptop? The Chaos exploit only works on Chrome OS.

GhostieKoto commented 1 year ago

Chromebook (version 107

Message ID: @.***>

xlak commented 1 year ago

I need some more information on what step you get stuck on with each bypass method. Please include screenshots if applicable.

GhostieKoto commented 1 year ago

Screenshot 2022-12-09 8 55 49 AM Screenshot 2022-12-09 8 52 55 AM Screenshot 2022-12-09 8 52 50 AM Screenshot 2022-12-09 8 51 22 AM Screenshot 2022-12-09 8 50 29 AM

There you go

Our administrator recently banned all extensions and made it so you have to request the extensions instead of downloading them. What do I do? Do you think it would affect him much if I spammed him with requests? Or would that just make him stop doing requests and stop extensions altogether? Then again, if he makes it so you can't get extensions, maybe then the students and teachers would say something about it, but I doubt it. any ideas on how to make his life miserable? (Not by hurting him, but by using tech to annoy the fvck out of him, until he gives us our internet rights back)

xlak commented 1 year ago

Wow, everything's extremely locked down. I'm currently analyzing the Securly source code to make the Alphabetic exploit be able to bypass it, but any additional details you can give will help tremendously. Does the Alphabetic exploit fail right after you click the bookmark or at a later step?

GhostieKoto commented 1 year ago

The nebula proxy doesn't work too well, mostly because it mostly returns 504 and 401 (insufficient perms (401) or cannot connect (504))

How will rotating the screen affect him? (they don't watch our screens) I'm thinking of spamming requests If I go on blocked proxy websites, will that do the same or does it have to be from multiple ip addresses? What will ChromeVox do against him? and what will disabling touchpads do against him?

Do you think you could send me the Securely source code?

I know that Securely can't touch files, so that's one way to play games. I know a few game website if you want them. I'm actively looking, so if you wanna recruit me I'd be happy to send you anything I find.

As of right now, I have quite a few gaming websites, and like, 2 proxy websites

Hapara.cf tan-misty-reindeer.cyclic.app

Those are the only 2 I have that work

xlak commented 1 year ago

Your sysadmin having to fix messed up chromebooks with flipped screens or the touchpads not working will leave less time to focus on blocking things. Turning on ChromeVox on the lock screen will make it even more annoying to deal with.

What websites are broken on the Nebula proxy? I can work on fixing them.

I can make a private repo with the Securly source code (so it doesn't get taken down due to copyright.)

Feel free to open pull requests on this repo to add any info you find.

xlak commented 1 year ago

Here is an existing repo with the source code for Securly

GhostieKoto commented 1 year ago

I have good news and bad news...

Good news, I don't have to request extensions anymore

Bad news, they're now blocking a lot more websites, including ones that I use for coding, such as cyclic.app, I'm assuming because we have too much freedom (programming proxies)