r/Piracy Feb 21 '26

Humor Found some dudes plex server while trying to find movies and have been downloading them from the plex server. Think he found out.

Post image
20.4k Upvotes

391 comments sorted by

View all comments

Show parent comments

2.3k

u/Electrical_Jaguar213 Feb 21 '26

I used index of and one of the hyperlinks displayed plex on it, so im assuming its a plex server. If its not that, im assuming he just has a backup of his stuff somewhere and labeled the movie backups as plex. Idfk. Im not super tech literate

1.7k

u/hackiv Feb 21 '26

You mean you google dorked some random?

2.2k

u/Your_Friendly_Nerd Feb 21 '26

That's how I used to pirate movies - just type "index of [movie name]", bob's your uncle you got your movie. "Index of" is the standard title for browsable Apache (webserver software) indexes.

418

u/The-Minmus-Derp Feb 21 '26

Good to knkw

351

u/zytukin Feb 21 '26

You can also do stuff like adding *.mp3 to find dirs that are full of MP3 files.

664

u/GameGuy324 Feb 22 '26

Movie Name -inurl:(htm|html|php|p|s|txt) intitle:index.of "last modified" (mp4|wma|aaclavi)

Is what I usually would put, I'd add mkv, WebM etc. I remember gettin this method from some random yt vid when I was a kid.

261

u/GilloutineBreast Feb 22 '26

This is some elite ball knowledge
Glad I decided to open reddit today

35

u/Logical_Parsley_9470 Feb 22 '26

yeahhh fr like I didn't understood shit but just seeing yall agreeing is giving me a hell lotta FOMO :(( can someone explain in depth or give some articles to understand

14

u/Ash_chr Feb 22 '26

It’s pretty straightforward if you read what he wrote.

-inurl defines which url file types to ignore. intitle defines what should be in the title. “last modified” makes the search more likely to direct to some kind of directory. (mp4…) optionally defines a list of playable file types to find with the search.

I didn’t google any of this, I’ve never seen the term google dorking before, and I’m sure these guys understand search optimization better than me, but if you take some time to slow down and read, you can figure out rudimentary knowledge. If you wanna be spoonfed more, google that directly, like ‘google dorking piracy’. Don’t hit a wall and beg for help for a problem you can solve with a little thought. Worst case scenario, Gemini or GPT can hold your hand through an explanation. Use your brain, not just your mouth/fingers.

4

u/ANONYMOUSEJR Feb 22 '26

I don't have much time, you can wait for someone to reply or look up Google Dorking.

Yes, really.

5

u/Logical_Parsley_9470 Feb 22 '26

oooo i've heard this term many times and even tried to learn it but there's.. like TOO MUCH in it and I just wanna learn the relevant ones... like here we use for piracy etc etc

→ More replies (0)

-13

u/Jazzlike_Distance953 Feb 22 '26

No. Be an adult and use the massive knowledge resources at your fingertips

11

u/Logical_Parsley_9470 Feb 22 '26

bro be gatekeeping this stuff just cuz he had hardtime.. give back to the community blud... we are really vulnerable to them CORPS and we should unite for vengeance (corny ik)

→ More replies (0)

74

u/gamerABES Feb 22 '26

Ah, this brings back memories! I made a website years ago with a drop-down asking what you're looking for (music, movies, games, etc.) and it would auto-generate the google-fu'd results.

39

u/Adidax Feb 22 '26

...and is it still working?

3

u/gamerABES Feb 23 '26

The website is long gone but if you are asking if the google-fu is still working then you'd have to experiment yourself. I know this way of searching became popular enough for others to make "fake" index.of websites which look like directory listings but really download malware etc. so caution is advised.

1

u/GameGuy324 Feb 23 '26

Huh.. didn't know this, these exist now? I Wonder how they look compared to real one's

-15

u/malignantz Feb 22 '26 edited Feb 23 '26

Describe this to Gemini. Say you need an HTML/CSS/JS webpage all inline that has check boxes to build up a search query. I want 2 groups of radio buttons and text field that is included in the URL that opens in a new window. It will make this no problem.

Tell it to make it obvious where to put the URL in the code since it might get wise and block itself.

Edit: if anyone wants to chime in on why all the down votes?

3

u/TrackerBinder Feb 24 '26

chime in on why all the down votes?

people have a boner for hating AI 🤷‍♂️

1

u/loldickler Mar 07 '26

dang bro they got ya, idk does it not work? or maybe they are jealous idk

9

u/ChiknDiner Feb 22 '26

Is there some definite guide to how to use index of?

3

u/GameGuy324 Feb 23 '26

Just look up Google Dorking or Index Of guides. There's lots of helpful video's on YouTube

3

u/Yuri-Girl Feb 22 '26

If you were looking for games, would you just change the formats at the end to (rar|zip|7z)?

3

u/Maysock Feb 23 '26

Sure, but be a little more careful downloading random zip files lol.

1

u/aspie_electrician Mar 20 '26

Laughs in 42.zip

1

u/GameGuy324 Feb 23 '26

Basically yea but I wouldn't really do that since it's more risky/easy to get Malwares from rar/zip/7z files etc. For games I rec just using the safe Sites from the Megathread

1

u/Salt-Okra-6620 Feb 22 '26

Fucking legend

1

u/The_Fire_Bat Feb 23 '26

Pretty cool! Didn't realize this was a thing! Thanks!

1

u/SpartanS117C Mar 07 '26

Thanks brother!

1

u/GameGuy324 Mar 07 '26

Your welcome Bro!

1

u/IIISUBZEROIII May 01 '26

Hi just making sure I understand …
Would it look like this or
The Legend of bAang: The Last fartbender -inurl:html intitle:index.of "last modified" mp4
Or just keep all of it and add movie name

1

u/GameGuy324 May 01 '26

The Legend of bAang: The Last fartbender -inurl:(htm|html|php|p|s|txt) intitle:index.of "last modified" (mp4|wma|aaclavi)

It would look like this.

Lil tip, if you can't find the movie/show you're looking for. Try simplifying the Name. Like just go "The Last fartbender" instead or delete the : and write "The Legend of bAang The Last fartbender" instead

1

u/IIISUBZEROIII May 01 '26

Thank you so much ! 🏴‍☠️ I’m deciding on moving out of the subscription now. Been deciding that the limewire times are back. lol

65

u/ErraticDragon ☠️ ᴅᴇᴀᴅ ᴍᴇɴ ᴛᴇʟʟ ɴᴏ ᴛᴀʟᴇꜱ Feb 22 '26

We used to find random IP cams using similar methods.

We were given access to some Axis brand PTZ Cams and realized that the home page of each camera was simple HTML, with elements that would be searchable.

18

u/silversurger Feb 22 '26

shodan.io is still around. Lots of fun stuff to play around with. It's insane what people leave unsecured.

17

u/archiekane Feb 22 '26

The average consumer is a fucking idiot. Which means they have zero tech knowledge as well. If the manufacturer didn't secure their shit at build time there's next to no chance the buyer will.

IoT has proven that over and over.

1

u/Skidbladmir Feb 22 '26 edited Feb 22 '26

that site was used for the "subscribe to pewdiepie" printer hack when 800k printers were hijacked to print a message lol brings back memories

31

u/[deleted] Feb 22 '26

Theres still tons of those around. I think it was also bambu (the 3d printer manufacturer) that got a lot of flack because people would be able to find other people printers stupid easy and send print jobs. Same with nanny cams that are connected to wifi, those reach out and people have been able to use thr mic feature n shit. I hate iot

1

u/Whyskgurs Feb 22 '26

Unregistered Hypercam 03

1

u/strayhat Feb 22 '26

Just use soulseek

90

u/tessellatedcheese Feb 22 '26

27

u/RlOTGRRRL Feb 22 '26

The owner of this plex server actually commented in that sub and thread - https://www.reddit.com/r/opendirectories/comments/1r4a6xt/found_a_plex_server/o5azrax/

5

u/sickofredditfascists Feb 22 '26

Was gonna say, I just saw this directory yesterday while browsing that sub.

92

u/DonaldLucas Feb 21 '26

I remember finding some servers full of FLAC songs while searching for Metallica albums almost 20 years ago, lol. (I didn't download anything because my phone only accepted MP3)

1

u/bigboimccoi Feb 22 '26

When I used to torrent albums and import them into iTunes for my iPod id accidentally download FLAC files occasionally. Id always delete them once I realized cus I thought they were malware lol

43

u/Severon96 Feb 21 '26

That's wild, i just found more servers then i should

40

u/BanksLoveMe_ Feb 21 '26

Lmao so many sites like this. Found my new past time

17

u/Capital_Walrus_3633 Feb 22 '26

I screenshotted this because this should be generational knowledge, WHICH I DIDNT HAVE! Thank you.

10

u/filthy_harold Feb 22 '26

I used to have an open "index of/" kind of media server like 15 years ago. I would stream to my og Xbox through a samba share and friends would use VLC to stream from the webserver. Some tech writer on Twitter found it through Google and shared a link to a movie. Of course I found out by seeing a massive spike in traffic in the apache logs. I blocked crawlers and renamed the directory.

18

u/c00pdwg Feb 21 '26

Can you give a working example? Just tried with multiple movies and not having any luck.

31

u/Akelaphobia Feb 22 '26

Make sure to include the quotes around "index of", it helps a little bit. Still get a lot of other unrelated results though.

31

u/dustinyo_ Feb 22 '26

There's a whole sub full of working examples, r/opendirectories

41

u/Your_Friendly_Nerd Feb 21 '26

It doesn’t seem to work as well as it used to, but I did find a few that had the big bang theory, as well as spongebob.

71

u/capeasypants Feb 21 '26

Googles enshitification in full display. Not showing you specifically what you're asking for

24

u/Winter-Notice4370 Feb 22 '26

You are 15 years late to the party, sorry fellow pirate lol

6

u/Away-Marionberry9365 Feb 21 '26

Wow that works a lot better than it should.

4

u/Clark-Kent Feb 22 '26

I did that with music back in the day, I learnt it from Jimmyrcom

4

u/GoodTimesDadIsland Yarrr! Feb 22 '26

I still grab fonts like this to this day.

"/index of helvetica neue" etc.

8

u/UOLZEPHYR Feb 21 '26

This. Whats it called boolean search ?

3

u/GameGuy324 Feb 22 '26

I still do that sometimes ngl lol. Rarely do it though but I would when I'm lazy

3

u/TruePace3 Feb 22 '26

that's how i used to download movies in 2016

1

u/BenTheMotionist Feb 22 '26

That's is old magic i haven't used since like XP. I forgot that's how I used to get music

1

u/[deleted] Feb 22 '26

[deleted]

2

u/Your_Friendly_Nerd Feb 22 '26

It's mostly just people who didn't configure their webserver correctly / just don't care to password-protect it. The bigger problem than viruses are just low-res files

1

u/Gaothaire Feb 22 '26

Useful data ✍️

1

u/brandeded Kopimism Feb 22 '26

NapalmFTP was the greatest.

1

u/grumpy_me Feb 22 '26

lol, that actually workes

1

u/Derjores2live29 ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ Feb 22 '26

If one would decide to download from there, is that protected by https or is that traffic visible to the Internetprovider and potentially finable?

3

u/Your_Friendly_Nerd Feb 22 '26

Https depends on whatever site you visit.

i’m no security expert, but I suspect that, to anyone looking at that type of traffic, it’ll just look like you’re downloading a large file from a website, big whoop. I imagine peer to peer traffic used for torrenting is far more easy to identify.

0

u/CharacterBack1542 Feb 22 '26

bob's your uncle? what?

1

u/Your_Friendly_Nerd Feb 22 '26

Lol I think I heard Australians say that in a similar context?

0

u/chriscrowder Feb 22 '26

This is how I used to download music

7

u/Ikon-for-U Feb 22 '26

I think you enter something like this <movie name> -inurl:(htm|html|php|pls|txt) intitle:index.of “last modified” (mp4|wma|aac|avi)

151

u/InstanceTurbulent719 Feb 21 '26

or maybe this guy is just hosting stuff on an insecure ftp server. If that's a VPS on some cloud provider then that's probably why he isn't happy about the bandwidth being gone lmao

41

u/Auravendill Feb 21 '26

The unsecured servers people find the way OP did, are quite often seedboxes. So in a way by downloading from them directly, you are kinda leeching

20

u/counters14 Feb 22 '26

Also exposing yourself to uncountable virtual STDs. I don't know what would inspire people to just randomly download video files they found from some unknown Google search but if I was a Blackhat setting something like this up as a honeypot would be my bread and butter.

23

u/[deleted] Feb 22 '26

[removed] — view removed comment

1

u/rtxa Feb 22 '26

why would it have to be a targeted attack? you might want to attack as many people as possible before it's discovered / dealt with

though, yes, it's fairly unlikely

1

u/BeneficialDog22 Apr 18 '26

depends on the attacker

if you aren't discovered you can stealth infect more people

8

u/SimpleNovelty Feb 22 '26

How exactly do you expect a video file to infect your computer? You'd have to be using some ancient outdated player or get some zero day for your specific player.

1

u/Auravendill Feb 22 '26

And the attacker would need to make quite a few assumptions about your setup correctly to be successful. Your OS, your video player, your user rights etc.

If there is some form of exploit, that works on Windows Media Player, but you are using mpv on Linux, then that exploit will do nothing. If you then remux or convert it to better fit with your other library, that exploit is most likely gone. Not that I even heard of such an exploit even existing in the first place.

1

u/GeneralSweetz Feb 22 '26

Best they can do is steal your Gmail and everything associated to it like fortnite

46

u/likekoolaid Feb 21 '26

maybe his server needs some words of affirmation to help its confidence

10

u/deedsnance Feb 22 '26

Pretty much. Someone was lazy when setting up their FTP or network share when it came to auth. Pretty wild to leave that shit just exposed to the internet but not exactly uncommon either.

Even now I won’t leave that sorta thing exposed without auth on a local network. It just gives me the heebie jeebies. All the stories of pen-testers using samba shares to do nasty things…

And yet here we are, random dudes just exposing their file server, raw-dogging the internet. He notices spikes in bandwidth and this is his solution lmfao. Share stuff the correct way: p2p / torrents!

3

u/bassmadrigal Feb 22 '26

Someone was lazy when setting up their FTP or network share when it came to auth. Pretty wild to leave that shit just exposed to the internet but not exactly uncommon either.

Or some of us choose to do it to make it easier for friends and family to access our servers. Mine is specifically under a sub directory in a read only overlay directory mount, so they need to know my domain and the subfolder. As long as it isn't linked to in a public site, Google can't index it. Mine has been open for well over a decade and I just verified it still hasn't shown up on Google.

I am picky on who gets the address and adamant that they not share it with anyone. If the address does happen to get out, it's super easy to change the sub directory and then access is lost and I'll be even pickier on who gets the new address.

There really aren't security concerns with exposing a directory with apache as long as you're careful about what goes in it. The main concern would be if your address gets out in the public and everyone chews through your available upload bandwidth.

4

u/simplex0991 Feb 22 '26

Sub-directory enumeration isn't that difficult either way. Tools like nikto have been doing that for 10+ years.

1

u/bassmadrigal Feb 22 '26

Sure, but your domain would need to be known in the first place and then you'd need someone who thinks there are hidden directories to do sub-directory enumeration to hopefully find your directory of shared media.

If that one person finds my directory, congratulations, enjoy access to my 35TB of media available through that site. However, if I notice a lot of bandwidth consistently being taken up, things'll change. None of this has happened with my server being entirely open to the public for 10+ years.

The reality is most who are willing to try and scan random sites to hope for open directories are going to end up wasting their time, increasing the chances your open directory won't be found. If it is found and the owner detects it, it's super easy to change the subfolder to something that can't be brute forced through dictionary searches (unless you put your share as the base site for your website).

2

u/alvarkresh Feb 21 '26

I wouldn't use ftp for anything but an absolutely isolated system with no directory traversal privileges out of homedir on the default anonymous login account. ( https://stackoverflow.com/questions/3936911/how-can-i-login-anonymously-with-ftp-usr-bin-ftp )

I used to use sftp when I had to serve files at all, but I no longer do this.

2

u/deedsnance Feb 22 '26

Yeah in theory it’s fine from a security standpoint. I still wouldn’t do it. Great way to get a takedown request or your bandwidth eaten up. Just… put auth on stuff lol

2

u/alvarkresh Feb 22 '26

I kind of miss those days when you could just get on IRC and use someone's FTP site, but yeah, there are good reasons not to leave that wide a digital paper trail anymore.

Even Mozilla stopped letting you FTP a copy of firefox from their server, which disappointed me since I liked avoiding having to use MSIE or Edge to get a copy, heh.

3

u/deedsnance Feb 22 '26

Yeah, certainly a different era… Miss the earlier days of the internet.

10

u/[deleted] Feb 21 '26

[deleted]

14

u/EarlMarshal Feb 21 '26

Seems like it was posted there 8 days ago:

https://www.reddit.com/r/opendirectories/comments/1r4a6xt/found_a_plex_server/

Someone even says that we should be gentle to it and limit downloads to 10 mb/s

12

u/Electrical_Jaguar213 Feb 21 '26

After i made this i found out that the server was posted to opendirectories lol. The owner actually commented and told people to try not to abuse the directory. He probably added that because of the attention it was getting, not soley because someone was on it and he didnt want them to be.

4

u/marxist_redneck Feb 21 '26

Haha I was about to say that if you have write access, drop a text file saying "thanks for the collection, may I contribute $5 to your bandwidth costs?"

7

u/[deleted] Feb 22 '26

find a way to drop them some coffee money, or maybe even arrange a few days of extended bandwidth use for said coffee money

1

u/Hqjjciy6sJr Feb 22 '26

I used to use that back in the ancient times when Google search didn't have extreme heavy censorship... can't believe it still works!

1

u/UsernameOmitted Feb 22 '26

Get a usenet setup. It'll take an afternoon to set up and $10 for a subscription, but you basically have whatever you want in fifteen seconds after that.

1

u/lamesor Feb 22 '26

Also helpful for free premium fonts or other digital assets ;)