Live data from Hacker News

Infosec company pwned by 4chan user

maia.crimew.gay

21–30 of 234 posts

Re: Infosec company pwned by 4chan user

#21
post #5

Earlier quoted context omitted.

Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…

“Who still uses Jenkins?” I think you may have perhaps misjudged just how entrenched Jenkins is in corp/enterprise.

The older I get, the more systems I learn are only around because they've been around.

Re: Infosec company pwned by 4chan user

#22
post #8

Earlier quoted context omitted.

But what's the trap here? Checking who downloads the file? I don't see how they can get any actionable info out of this

1. post link to jenkins job in a 4chan thread relating to something nefarious 2. see who clicks it 3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan Something like that.

How to waste your time tracking down 20000 wanna be script kiddies?

Re: Infosec company pwned by 4chan user

#23
post #5

Earlier quoted context omitted.

Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…

jenkins is old and crusty, but it works and works well. if the UI for a build tool looks too fancy, my faith in it drops to 0 almost immediately.

It doesn’t work well. It’s the JIRA of CI/CD: it is entrenched and does multiple things but doesn’t do any one thing well, and the people that decide what to buy aren’t the people who are forced to use it so they don’t care about its quality so much

Re: Infosec company pwned by 4chan user

#24

This page reminds me of the old web. I kind of miss it, auto-playing MIDI songs and custom cursors and all. I'll take that over having to wade through Reddit 12 times out of 10.

It's been a long time since I had the sensation of going from a site with a brightly/strongly coloured background to another on white/beige and my eyes not being able to handle it. I really quite enjoyed it.

Re: Infosec company pwned by 4chan user

#25

This page reminds me of the old web. I kind of miss it, auto-playing MIDI songs and custom cursors and all. I'll take that over having to wade through Reddit 12 times out of 10.

0 times out of ten for me. First I blocked the annoying cat, then I got to the bottom, was assaulted by blinking buttons and decided I didn’t need to know what else they were saying anyway.

Re: Infosec company pwned by 4chan user

#26
post #5

Earlier quoted context omitted.

Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…

jenkins is old and crusty, but it works and works well. if the UI for a build tool looks too fancy, my faith in it drops to 0 almost immediately.

[deleted]

Re: Infosec company pwned by 4chan user

#27

Back in 90s. I commented to a friend that there sure were a lot of NASA employees on A certain IRC channel. His response was NASA had great computers and no security.

Heck, I've heard stories that several big agencies only started deploying firewalls at their network perimeter in the late 90's. I guess one of the saving graces was that a lot of stuff like personnel records were hard to reach or still only on paper.

Re: Infosec company pwned by 4chan user

#28
post #5

Earlier quoted context omitted.

Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…

People doing embedded testing use Jenkins still. Not that I would, but some people do.

Embedded people are pretty pragmatic and tend not to chase fads for the sake of change or resume engineering. If it works, it's good enough for them.

Switching away from Jenkins would cost effort and offer no competitive advantage to your end product, so then why do it?

Re: Infosec company pwned by 4chan user

#29
post #15

Found this on the same blog. Wild read. Apparently they found a copy of the nofly list from 2019. https://maia.crimew.gay/posts/how-to-hack-an-airline/

She has a pretty comprehensive wikipedia entry: https://en.wikipedia.org/wiki/Maia_arson_crimew

[flagged]

Re: Infosec company pwned by 4chan user

#30
post #5

Who makes their Jenkins instance world accessible!

Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…

What is a better alternative, if you want to self-host?
Post reply on HN