Live data from Hacker News

Infosec company pwned by 4chan user

maia.crimew.gay

71–80 of 234 posts

Re: Infosec company pwned by 4chan user

#71

This page reminds me of the old web. I kind of miss it, auto-playing MIDI songs and custom cursors and all. I'll take that over having to wade through Reddit 12 times out of 10.

As the creator was born in 1999, it's interesting to me because she's nostalgic for a period she did not fully experience. It's something I did, and it's neat yet strange to see it being done to a part of my past.

>It's something I did, and it's neat yet strange to see it being done to a part of my past.

Agree. I read recently that digital cameras have been taking off among younger people in the way vinyl took off among millennials. I'm excited to see how people that grew up with excessive, toxic social media manage to find better solutions for dealing with the internet

Re: Infosec company pwned by 4chan user

#73
post #5

Earlier quoted context omitted.

Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…

Is there an F/OSS alternative to Jenkins that I’m not aware of?

- Woodpecker CI: https://woodpecker-ci.org/

- Drone CI: https://www.drone.io/

- Buildbot: https://buildbot.net/

- Gitea Actions: https://docs.gitea.io/en-us/usage/actions/overview/

- Fogejo Actions: https://forgejo.org/2023-02-27-forgejo-actions/

- GitLab Runners: https://gitlab.com/gitlab-org/gitlab-runner

You could also use Ansible playbooks/roles to run your build, although that's going to be a bit more manual: https://www.ansible.com/

Not necessarily endorsing any of the alternatives, just pointing them out.

Re: Infosec company pwned by 4chan user

#74
post #53

I suspect this leak was made by the author themselves and submitted to 4chan via Tor or a VPN. I don't have hard evidence to back this up but if you read the Wikipedia article about them, it's pretty easy to put two and two together.

Maia is very honest when she hacks a company, unsupported theories don't help anyone.

Their antics have been of questionable legality, and I would assume they'd try to avoid drawing too much attention, given that this is the 3rd US-based company they're trying to hack, and the US just might ask for an extradition.

Further, the conclusion about Jenkins being the attack vector is drawn without much thought or explanation, and it is also interesting that they've used the same attack vector elsewhere.

Re: Infosec company pwned by 4chan user

#75
post #5

Earlier quoted context omitted.

Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…

What is a better alternative, if you want to self-host?

You can self-host:

- Woodpecker CI: https://woodpecker-ci.org/

- Buildbot: https://buildbot.net/

- GitLab Runners: https://docs.gitlab.com/runner/

- Gitea Actions: https://docs.gitea.io/en-us/usage/actions/overview/

- Forgejo Actions: https://forgejo.org/2023-02-27-forgejo-actions/

- Drone CI: https://www.drone.io/

- CircleCI (not free nor open-source, but self-hosted): https://circleci.com/pricing/server/

- GitHub Runners (same deal as CircleCI): https://docs.github.com/en/actions/hosting-your-own-runners/...

Re: Infosec company pwned by 4chan user

#77
post #60

Earlier quoted context omitted.

0 times out of ten for me. First I blocked the annoying cat, then I got to the bottom, was assaulted by blinking buttons and decided I didn’t need to know what else they were saying anyway.

Oh my, assaulted ? By that single blinking icon? I hope you're ok.

Interestingly, had this complaint been about an ad, parent would have been upvoted with hundreds of comments agreeing with them.

In other words, what OP is trying to say is that websites should be designed with the users goals in mind, and IMO it's fair to say that this website wasn't designed that way.

Re: Infosec company pwned by 4chan user

#78
post #15

Earlier quoted context omitted.

She has a pretty comprehensive wikipedia entry: https://en.wikipedia.org/wiki/Maia_arson_crimew

Appears to be self-authored.

A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?

Re: Infosec company pwned by 4chan user

#79
post #15

Earlier quoted context omitted.

She has a pretty comprehensive wikipedia entry: https://en.wikipedia.org/wiki/Maia_arson_crimew

Appears to be self-authored.

Easy to check on wikipedia, looks like it was created by the user Ezlev [0], who does not appear to be crimew's wikipedia acocunt, and updated by several other users over the last couple years.

[0] https://en.wikipedia.org/wiki/User:Ezlev

Re: Infosec company pwned by 4chan user

#80
post #8

Earlier quoted context omitted.

But what's the trap here? Checking who downloads the file? I don't see how they can get any actionable info out of this

1. post link to jenkins job in a 4chan thread relating to something nefarious 2. see who clicks it 3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan Something like that.

Or any and every security researcher / infosec company?
Post reply on HN