Live data from Hacker News

Infosec company pwned by 4chan user

maia.crimew.gay

61–70 of 234 posts

Re: Infosec company pwned by 4chan user

#61

This page reminds me of the old web. I kind of miss it, auto-playing MIDI songs and custom cursors and all. I'll take that over having to wade through Reddit 12 times out of 10.

They were born in 1999, so it's more like what a new generation's impression of what the old web was like.

You don't really have to know what specific year they were born in, the refusal to capitalize is a dead giveaway they did not experience that time at all. Anybody of that time period would be embarrassed to do so on a public site.

Kind of funny how we carry these different meanings to mostly meaningless things.

Re: Infosec company pwned by 4chan user

#62
post #52

It's always Jenkins.

Apparently so, considering that this is the same person who got a hold of the No-Fly List a while back, and, you guessed it, they found it through Jenkins somehow.

So ... same attack vector, you implying crimew might be this anonymous 4chinz user? Intriguing...

Re: Infosec company pwned by 4chan user

#63
post #46

I didn't even know that .gay was a top level domain...

Registration was first attempted in 2012. It was denied and appealed several times and finally recognized in 2019. After some Covid-related delays, it was opened to the public in 2020. https://en.m.wikipedia.org/wiki/.gay

Re: Infosec company pwned by 4chan user

#64

This page reminds me of the old web. I kind of miss it, auto-playing MIDI songs and custom cursors and all. I'll take that over having to wade through Reddit 12 times out of 10.

As the creator was born in 1999, it's interesting to me because she's nostalgic for a period she did not fully experience. It's something I did, and it's neat yet strange to see it being done to a part of my past.

This is common among the younger people joining the internet. An the creator of SpaceHey.com was nostalgic for the days of old social media that happened when he was too young to experience it.

Add me if you have a SpaceHey account! https://spacehey.com/josh

Re: Infosec company pwned by 4chan user

#65
post #53

I suspect this leak was made by the author themselves and submitted to 4chan via Tor or a VPN. I don't have hard evidence to back this up but if you read the Wikipedia article about them, it's pretty easy to put two and two together.

Maia is very honest when she hacks a company, unsupported theories don't help anyone.

Maia also has enough going on with lawsuits from being honest in the past. Not taking credit for this one might be for the better...

Re: Infosec company pwned by 4chan user

#66

Who makes their Jenkins instance world accessible!

Anyone setting up a honey pot. Half of 4chan posts are 3 letter agencies trying to bait people into violence.

Or anyone else, such as aviation companies:

https://maia.crimew.gay/posts/how-to-hack-an-airline/

Previously discussed here:

https://news.ycombinator.com/item?id=34446673

Re: Infosec company pwned by 4chan user

#67

This page reminds me of the old web. I kind of miss it, auto-playing MIDI songs and custom cursors and all. I'll take that over having to wade through Reddit 12 times out of 10.

You might have liked Lulzsec's website. They had an auto-playing audio clip of the Love Boat TV theme and an ASCII ship above text lyrics that replaced the word 'love' with 'lulz'. It was refreshingly amusing.

Sadly archive.org doesn't have a copy from its live state—however I saved the home page at the time (MHTML ftw) and here's a video capture of it*: https://streamable.com/zon5wy

* Expires in one day

Edit: for context Lulzsec were a hacking group a decade back responsible for various headline-making leaks and website hacks.

Re: Infosec company pwned by 4chan user

#68

This page reminds me of the old web. I kind of miss it, auto-playing MIDI songs and custom cursors and all. I'll take that over having to wade through Reddit 12 times out of 10.

They were born in 1999, so it's more like what a new generation's impression of what the old web was like.

Was the author the girl that owned the TSA in the past year?

Re: Infosec company pwned by 4chan user

#69

Earlier quoted context omitted.

“Who still uses Jenkins?” I think you may have perhaps misjudged just how entrenched Jenkins is in corp/enterprise.

The older I get, the more systems I learn are only around because they've been around.

A lot of the time when old things are still around, it's not because through all the years nobody has had the idea to replace them, but because the benefit of replacing them hasn't at any point in history outweighed the hassle.

This is true for X11 and this is true for the QWERTY layout. The benefit of switching must outweigh the enormous hassle of doing so. It's easy to find something that's a little bit better, but that's simply not good enough to merit a switch.

Often they're around because when it comes around, they do a such a decent job and it's difficult to actually produce something that has that sort of advantage.

Re: Infosec company pwned by 4chan user

#70

Earlier quoted context omitted.

They were born in 1999, so it's more like what a new generation's impression of what the old web was like.

You don't really have to know what specific year they were born in, the refusal to capitalize is a dead giveaway they did not experience that time at all. Anybody of that time period would be embarrassed to do so on a public site. Kind of funny how we carry these different meanings to mostly meaningless things.

Making advisories hard to read has been a thing since forever. Remember Gobbles?

https://github.com/thinkitdata/GOBBLES/blob/master/advisorie...

Post reply on HN