How efficient are paywalls? A quick check on an online newspaper paywall in Belgium:


The scenario

  1. Someone posts an interesting article link
  2. You click the link...

The question

Are all paywalls equal or are some more equal?

Let's investigate

Let's check out , a quality Belgian newspaper, as our target.

When looking at the source code, it seems all artcile content is present in the browser, but a Javscript is triggering a layer that prevents reading the content.

Paywall -VS- Article content

So, lets use Curl to fetch the article html and thus ignore javascripts to active the paywall.

Curl the article and store it

Using DOMxpath queries we can get the relevant article titles, images and paragraphs.

Extract article content using DOMXpath Query


And we have a working POC:

The answer

Most paywalls are effective. Some can be evaded easily.

All other Belgian online newspapers did a much better job at protecting their precious content, even newspapers from the same media group (DPG).

Let's report this to, maybe I can get a Bug Bounty reward or at least a Responsible Disclosure?

TLDR: No. joined the Bug Bounty platform. In the project details you'll find:

Can we create a Chrome Plugin to open a blocked article with one click?

Lets create a simple Chrome browser plugin to open a page with a blocked article in the Paywall Evader website.

And we have a winner.

