5 ms·
4chan Intrusion Postmorterm
- voltagex_ 12y agoCan't read it here, could someone post the text?
- Buge 12y agoConcerning a recent intrusion Last week we were made aware of a software vulnerability that allowed an intruder access to administrative functions and information from one of our databases. The intruder later stated their motive was to expose the posting habits of a specific user they disliked. After careful review, we believe the intrusion was limited to imageboard moderation panels, our reports queue, and some tables in our backend database. Due to the way the intruder extracted information from the database, we have detailed logs of what was accessed. The logs indicate that primarily moderator account names and credentials were targeted. Three 4chan Pass users had their Pass credentials accessed, and were notified and offered refunds and lifetime Passes shortly after the discovery. As a reminder, all payment information is processed securely by Stripe—we never see nor store any of it, and thus no payment information was compromised. We patched the vulnerability quickly after it came to our attention, and have spent—and will continue to spend—dozens of hours poring over our software and systems to help mitigate and prevent future intrusions. We’re sorry it happened, and will do our best to ensure it doesn’t happen again. —moot
- id 12y agoGoogle Cache: https://webcache.googleusercontent.com/search?q=cache:-lA9eoO3XFAJ:blog.4chan.org/post/84289353232/concerning-a-recent-intrusion https://webcache.googleusercontent.com/search?q=cache:-lA9eo...
- alloyed 12y agoI suspect a lot of people will be unable to read it if they use HTTPS everywhere: the 4chan blog does not support https and the EFF is currently in a ruleset freeze so they cannot reflect that until the next stable version is out.
- ZoF 12y agoTumblr only recently added SSL support, which is likely the reason Moot hasn't implemented it yet. That said, I(unfortunately) doubt that HTTPS-everywhere is being utilized by that many people.
- hrrsn 12y agoThat's only for the dashboard. Blogs are still cleartext. It's possible to do SSL for *.tumblr.com domains but not (easily) for custom ones.
- willvarfar 12y agoA lot of corporate firewalls block access to 4chan etc.
- nwh 12y agohttp://archive.today/UJAXS http://archive.today/UJAXS
- corobo 12y agoThis is the first .newlongwordtld domain I've seen that isn't a spam site squatting on a popular domain equivalent. A new era has begun
- nwh 12y agoYeah, only because .is domains were being compromised and a new TLD was chosen as an easy alternative.
- voltagex_ 12y ago>.is domains were being compromised Can you elaborate?
- nwh 12y agohttp://blog.archive.today/post/82775187091/curious-why-the-move-in-domain-names-from-archive-is http://blog.archive.today/post/82775187091/curious-why-the-m...
- voltagex_ 12y ago> Content Blocked (content_filter_denied) > Content Category: "Proxy Avoidance" Another day, another block at $employer. Curiously, web.archive.org is allowed. Thanks for the link.
- deleted 12y ago[deleted]
- vex 12y agoWay to not give any details about the vulnerability...
- robobro 12y agoThis article's pretty much useless.
- chippy1337 12y agoRumor is it was an SQL Injection in the "days" parameter of the stats system. Details here -> http://pastebin.com/Fq96ndB6 http://pastebin.com/Fq96ndB6
- hayksaakian 12y agochippy1337's comment is marked as dead, but here it is for posterity: Rumor is it was an SQL Injection in the "days" parameter of the stats system. Details here -> http://pastebin.com/Fq96ndB6 http://pastebin.com/Fq96ndB6 -----
- meowface 12y agoAh, chippy1337. Haven't seen that name in a while. Is "he" the original?
- deleted 12y ago[deleted]
- drum 12y agoMoot mentions refunds for targeted users. I was unaware 4chan offered something purchasable. Anybody know what he's referring to?
- tga_d 12y ago4chan passes, they allow you to post without entering in captcha, and to avoid IP block bans. Otherwise the experience is identical.
- Aoyagi 12y agohttps://www.4chan.org/pass https://www.4chan.org/pass
- grrowl 12y ago4chan Pass, which enables you to bypass the annoying CAPTCHA (and is a kind of CAPTCHA in itself, since a computer can't own a credit card); much like Reddit Gold
- jokoon 12y agoyeah, 4chan pass is the main reason I don't use this website. really clunky
- tobyjsullivan 12y agoThis makes an excellent testimonial for Stripe. Consider the ROI just realised.
- linuxydave 12y ago4chan gets a lot of of traffic and is well-known so I think anything they use gets a boost in popularity :)
- moot 12y agoEh, Stripe has way larger/more high profile customers than us, but yes we've been very happy with them.
- linuxydave 12y agoWhile that is true I think you might have more impact than you realise :)
- izietto 12y agoThey should spend time to refactor their code, it's a mess: http://pastebin.com/a45dp3Q1 http://pastebin.com/a45dp3Q1 With that source is much harder to make a security analysis and is easier to create side effects leading to security holes
- meowface 12y agoThat code was leaked in 2010 and is quite out of date. Since then they've updated their codebase quite a bit.
- moot 12y agoPer meowface's comment, this code is ~4 years old. It's in a much better place now, but there's still a lot of room for improvement. The vulnerability wasn't in the main application. I'll write more about it on my personal blog in the coming days (http://chrishateswriting.com http://chrishateswriting.com).
- hsx 12y agoHave you ever thought about re-writing 4chan and making it open source? I think a large portion of the community would be willing to contribute.
- thrillgore 12y agoIIRC they had open source code called Futabally, but as time went on they closed the sources to protect their interests. Projects like it exist, such as Kusaba X.
- rodgerd 12y agoI find myself wondering who in their right mind pokes 4chan with a stick. It is not an angry mob I would care to have ambling in my general direction.
- linuxydave 12y agoI think that the userbase is rather fickle and it depends on who you piss off. Each board has its own culture so, for example, if you piss off /b/ then you might get an angry mob that gives you grief but I doubt that would happen if you pissed off /g/ or /tg/.
- meowface 12y agoIn this case the user who gained access to the database was seen as doing it for a reasonably "noble" reason, relatively speaking (to find information about another user whom some disliked), so from what I can see there hasn't been much backlash against him even though his full name was posted in a few places. It was kind of a self-hack.
- nilved 12y agoPlease don't miscontrue the person's intentions as noble, or even put that word in the same paragraph as 4chan. It was misogynistic, sexist harrassment.
- deleted 12y ago[deleted]
- meowface 12y agoI did say "relatively speaking." I wasn't making a judgment as to whether it was moral or immoral, just that 4chan as a whole mostly saw it as reasonable, which is why most of them found the intrusion humorous instead of an affront. This is in stark contrast to when UG Nazi hacked 4chan a while ago by hijacking Cloudflare's CEO's Gmail and pointing 4chan.org's A record at their own server.
- 12y ago
- Igglyboo 12y agoWow, now that is a response. Full disclosure of what happened and a nice payout to victims who weren't even harmed that much.