35 ms·
Infosec company pwned by 4chan user
- dmbche 3y ago"however, they made one of the most comedic mistakes you can still make while setting up jenkins (im actually not sure which misconfiguration leads to this): the build information for each past build contains a link to the git repository, including the bitbucket credentials in the url. genius."
- bheadmaster 3y agoThe most horrible thing Jenkins does to devs is it encourages bad practice. Good practice is so cumbersome to do properly (create a secret, load secret in env through Groovy code, setup git configuration in a shell script) that, unless someone is actively monitoring them, devs are always in a temptation to just put the credentials in the git URL, we'll remove them after testing. Then one out of N times they forget and you get a security hole.
- ilyt 3y agoUh, no, you just pick credentials from list in the repo config. If you wanted to download additional repo in the jenkins script sure, but Jenkins Git plugin just accepts credential (whether its password or pub/priv key pair), just paste URL and select one from the list
- phendrenad2 3y agoIt's 2023, it's far past the time that open-source projects should be made without security being the #1 concern, even above the basic functionality of the app. But Jenkins has been around since 2011, so it's understandable that the security posture is obtuse and tacked-on. It's time for some other CI project to surpass Jenkins. I won't be sorry to see it go. Security should be front and center, the first thing the user sees. The defaults should be secure out of the box, and if the user does something stupid, it should be painfully clear to everyone, even the least technical user who looks at it, that something is wrong. That said, I doubt that what happened here was a Jenkins configuration problem, and instead something to do with the build scripts they're running on Jenkins. You can't solve every class of stupid, sadly.
- onionisafruit 3y ago“one out of N times” where N is < 2
- deng 3y agoNo, the most comedic mistake is to have a public-facing Jenkins running. I mean in general you wouldn't make your CI accessible from the outside, but especially not Jenkins. That software has probably more CVEs every year than all of our other tooling combined.
- supermatt 3y agoGiven the frequency with which I seem to update nokogiri on a rails instance, i assumed libxml2 would hold that award: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=libxml2 https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=libxml2 But sure enough, jenkins FAR outweighs it: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=jenkins https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=jenkins
- deng 3y agoAnd that's just the ones that get reported. Since core Jenkins is pretty bare-bones, most instances also have many plugins installed, and most of those aren't properly reviewed at all.
- jorams 3y agoThe vast majority of those Jenkins CVEs seem to be for a wide variety of plugins, so it seems someone is putting in quite a bit of work to review them.
- deng 3y agoYes, to give credit, they do monitor the most important ones which almost everybody uses and which are usually also maintained by developers from Cloudbees. But there are over 1800 plugins for Jenkins, so at least quantitatively, most of them are not monitored.
- JackSlateur 3y agoThe most comedic mistake is to have a running jenking in 2023
- deleted 3y ago[deleted]
- philipwhiuk 3y agoWho makes their Jenkins instance world accessible!
- albatross13 3y agoAnyone setting up a honey pot. Half of 4chan posts are 3 letter agencies trying to bait people into violence.
- dmbche 3y agoBut what's the trap here? Checking who downloads the file? I don't see how they can get any actionable info out of this
- albatross13 3y ago1. post link to jenkins job in a 4chan thread relating to something nefarious 2. see who clicks it 3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan Something like that.
- unethical_ban 3y agoOr any and every security researcher / infosec company?
- ikiris 3y agoHow to waste your time tracking down 20000 wanna be script kiddies?
- malux85 3y agoNo, but having a list of easy targets to pull from when your performance quotas get low could be useful (I wish I was joking)
- imtringued 3y agoHere is how lawyers in Germany do it. They ask ISPs for the person behind the IPs (cough, cough, carrier grade NAT) and then they send cease and desist letters demanding 800€. If you sign their letter you are considered guilty but avoid further consequences, similar to a plea bargain. It only takes a dozen people having money and fearing court for this to be profitable. The lawyer doesn't want to go to court because that costs money, he just wants you to confess and get paid.
- alexjplant 3y agoThis page reminds me of the old web. I kind of miss it, auto-playing MIDI songs and custom cursors and all. I'll take that over having to wade through Reddit 12 times out of 10.
- walthamstow 3y agoIt's been a long time since I had the sensation of going from a site with a brightly/strongly coloured background to another on white/beige and my eyes not being able to handle it. I really quite enjoyed it.
- Semaphor 3y ago0 times out of ten for me. First I blocked the annoying cat, then I got to the bottom, was assaulted by blinking buttons and decided I didn’t need to know what else they were saying anyway.
- ceejayoz 3y agoYou would not have enjoyed the late 90s.
- Semaphor 3y agoIt was okay back then, I was young and didn’t know you could design websites that are easier on the eyes.
- cushpush 3y agoOh man, never visit Tumblr
- Semaphor 3y agoThat’s actually not as bad, as it’s usually just some big meme gifs that I can disable with my animation blocker extension.
- pc86 3y ago
- generalizations 3y agoFound this on the same blog. Wild read. Apparently they found a copy of the nofly list from 2019. https://maia.crimew.gay/posts/how-to-hack-an-airline/ https://maia.crimew.gay/posts/how-to-hack-an-airline/
- bo0tzz 3y agoDiscussed here previously: https://news.ycombinator.com/item?id=34446673 https://news.ycombinator.com/item?id=34446673
- yccs27 3y agoShe has a pretty comprehensive wikipedia entry: https://en.wikipedia.org/wiki/Maia_arson_crimew https://en.wikipedia.org/wiki/Maia_arson_crimew
- sdfghswe 3y ago[flagged]
- deleted 3y ago[deleted]
- brodouevencode 3y agoAppears to be self-authored.
- westmeal 3y agocrimew is 1337
- cornhole34 3y agoOptimEyes.ai wins Global Infosec Award 2022 OptimEyes.ai data leak - 2023 smh
- testplzignore 3y agoAren't these industry awards essentially participation trophies for whoever is willing to pay? Like the notorious "Who's Who Among American High School Students" in the US.
- insanitybit 3y agoYes. I started a security company and received tons of award emails and conference invites that were all bullshit.
- treeman79 3y agoBack in 90s. I commented to a friend that there sure were a lot of NASA employees on A certain IRC channel. His response was NASA had great computers and no security.
- sybercecurity 3y agoHeck, I've heard stories that several big agencies only started deploying firewalls at their network perimeter in the late 90's. I guess one of the saving graces was that a lot of stuff like personnel records were hard to reach or still only on paper.
- stonogo 3y agoPerimeter security with firewalls didn't really come into vogue until the mid 1990s (post-Cheswick and Bellovin), so that seems like a pretty speedy adoption for a big agency.
- qingcharles 3y agoIn the 90s I would be hard-pressed to name any of my techie chums who didn't have a shell account on a NASA box, through legal or illegal means. NASA also had some great cables and satellite runs between their facilities and other partners overseas that allowed for moving warez and porn very quickly across the Atlantic when the commercial connection between the UK and USA was something like 2Mbps for the entire country.
- icedchai 3y agoAround here, it was the local college and universities. My friend, in high school at the time, pwned CS departments at both an Ivy and state college, gave out dozens of cracked SunOS accounts to BBSers and script kiddies (the password file was unshadowed...) Tying up all the dialups with IRC and the non-stop downloading of warez eventually brought the attention of sysadmins, but it went on for months.
- doodlesdev 3y agoIt's always Jenkins.
- voynich 3y agoApparently so, considering that this is the same person who got a hold of the No-Fly List a while back, and, you guessed it, they found it through Jenkins somehow.
- isoprophlex 3y agoSo ... same attack vector, you implying crimew might be this anonymous 4chinz user? Intriguing...
- Lammy 3y agoSimpsons did it: https://en.wikipedia.org/wiki/HBGary#WikiLeaks,_Bank_of_America,_Hunton_&_Williams,_and_Anonymous https://en.wikipedia.org/wiki/HBGary#WikiLeaks,_Bank_of_Amer...
- richbell 3y agoDramatic recounting of this: https://youtu.be/uFw66YyHD6E https://youtu.be/uFw66YyHD6E
- Dwedit 3y agoI didn't even know that .gay was a top level domain...
- sp332 3y agoRegistration was first attempted in 2012. It was denied and appealed several times and finally recognized in 2019. After some Covid-related delays, it was opened to the public in 2020. https://en.m.wikipedia.org/wiki/.gay https://en.m.wikipedia.org/wiki/.gay
- odiroot 3y agoTime to register gaymusical.gay!
- schwartzworld 3y ago"Not as long as some musicals" - The Banner
- dijksterhuis 3y ago“The Audience Applauded” Great episode.
- thinkling 3y agohttps://enola.gay https://enola.gay (safe for work)
- robotnikman 3y agoA fitting domain for the famous B-29
- c7DJTLrn 3y agoI suspect this leak was made by the author themselves and submitted to 4chan via Tor or a VPN. I don't have hard evidence to back this up but if you read the Wikipedia article about them, it's pretty easy to put two and two together.
- reocha 3y agoMaia is very honest when she hacks a company, unsupported theories don't help anyone.
- cedws 3y agoMaybe because previous hacks have been of varying legality. The entrypoint for the airline hack was also Jenkins.
- SuperShibe 3y agoMaia also has enough going on with lawsuits from being honest in the past. Not taking credit for this one might be for the better...
- supriyo-biswas 3y agoTheir antics have been of questionable legality, and I would assume they'd try to avoid drawing too much attention, given that this is the 3rd US-based company they're trying to hack, and the US just might ask for an extradition. Further, the conclusion about Jenkins being the attack vector is drawn without much thought or explanation, and it is also interesting that they've used the same attack vector elsewhere.
- deleted 3y ago[deleted]
- cool_dude85 3y agoIt says in the wiki entry that Switzerland does not extradite citizens unless they consent to it. She is probably already not able to leave Switzerland due to her US indictment.
- hiidrew 3y agothis is the same person that found the no fly list from an airline lol https://maia.crimew.gay/posts/how-to-hack-an-airline/ https://maia.crimew.gay/posts/how-to-hack-an-airline/
- rurban 3y ago[flagged]
- kruuuder 3y agohttps://en.wikipedia.org/wiki/Deadnaming https://en.wikipedia.org/wiki/Deadnaming
- neurobama 3y ago[flagged]
- EdwardDiego 3y agoIs it deadnaming? Given that she and her supporters have used Tillie in the very recent past, a feminine name, I doubt it.
- bagels 3y agoI had to check the article to understand how it is notable for a 4chan user to also be a business owner. They're using "owned" in leet speak sense, infiltrated security.
- Swizec 3y agoThe correct spelling in that case is pwned isn’t it? I got it from context, but those always felt like subtly different words to me.
- RamblingCTO 3y agoI've seen owned plenty of times. "Owned a box" like that
- amatecha 3y agoyeah, "owned" came far before "pwned". Wiktionary cites this usenet post from 1996 https://groups.google.com/g/alt.sysadmin.recovery/c/IsdIZqfW_sM/m/9UTRiIoSy74J https://groups.google.com/g/alt.sysadmin.recovery/c/IsdIZqfW... .. can't find an "earliest source" for "pwned" tho
- Izkata 3y ago"pwned" is from a late-90s StarCraft custom map where the map creator typo'd "owned" as "pwned" in a message that popped up when one player beat another.
- bombcar 3y agopwn is a typo'd version of own, but since it's unambiguous it would have been better here
- sobkas 3y ago> The correct spelling in that case is pwned isn’t it? I got it from context, but those always felt like subtly different words to me. For me owned was as in "CIA owned Crypto AG" not "netrunner owned the Chrome" not that Chrome
- RamblingCTO 3y ago> which makes it all so much more ironic how completely they have been hacked. Nope, not really. It just takes one mistake and you're pwned. Imagine giving the intern a small project, you're losing your head due to your main project, no time to supervise. Boom. /e: Or imagine an update in one of your libs/apps. In order to not to be hacked you need to make everything right. In order to hack you just need to find one mistake. Well, kinda, but you know what I mean
- Leo_Germond 3y agoI guess they meant paradoxical. Being a security company they are juicy target for an attacker's rep, meaning they are in the situation where they are both more protected than usual but also more at risk. That's the arm's race paradox I guess.
- _23sd 3y agoIt only takes one mistake, but this was a pretty easy one to prevent. At a mature company with a decent security program, creating an internet facing Jenkins instance wouldn't have been approved by IT, doesn't matter if it was an intern with an overworked manager trying to set it up. So it is pretty bad that a security company failed at something as basic as minimizing their attack surface (and possibly not sufficient segmentation between the dev environment and customer data, but the post is not very detailed on that part). Not surprising, though.
- aigoochamna 3y ago[flagged]
- becquerel 3y agothe platonic ideal of what 'hacker' means imo
- 2OEH8eoCRo0 3y agohactivism means hacking every unsecure jenkins instance for lulz?
- Bonus20230510 3y agoMight be worth doing some reading about hackers and their attitude towards "IP" and whether it can really be "theft".
- aigoochamna 3y agohttp://phrack.org/issues/7/3.html http://phrack.org/issues/7/3.html ?
- int_19h 3y agoNo, just the ones where the result is a leak of information on some large government surveillance program, or, say, exposing incompetence of a company that sells security-related products - especially ones focused on "intellectual property". Not that there's anything wrong with lulz as a motivation from the perspective of old-time hacker ethos.
- 2OEH8eoCRo0 3y ago[flagged]
- rejectfinite 3y ago>if you enjoyed this or any of my other work feel free to support me on my ko-fi. this is my only real source of income so anything goes a long way, and monthly contributions help tremendously with budgeting wow she seems smart. I hope ko-fi is enough
- _8j50 3y agoTheme aside I really like this site's design.
- 404mm 3y agoI always tell myself, if I ever start any kind of business, I’ll make sure to host my website as static content on a read only file system. And customer data will be handled by 3rd party
- onionisafruit 3y agoNo third parties for my customer data. I will write it on flash paper and burn it all every Friday.