Live data from Hacker News

Infosec company pwned by 4chan user

maia.crimew.gay

111–120 of 234 posts

Re: Infosec company pwned by 4chan user

#111

Earlier quoted context omitted.

“Who still uses Jenkins?” I think you may have perhaps misjudged just how entrenched Jenkins is in corp/enterprise.

The older I get, the more systems I learn are only around because they've been around.

Yes? do you know the cost of moving big systems?

Re: Infosec company pwned by 4chan user

#112
post #88

I had to check the article to understand how it is notable for a 4chan user to also be a business owner. They're using "owned" in leet speak sense, infiltrated security.

yeah should probably be edited to "pwned" just to make it clear, even though "owned" is the original term for, well, getting owned/rekt/"hacked"/etc.

I too thought it would be about a company who was a sole proprietor of an infosec corp lol

Re: Infosec company pwned by 4chan user

#113

Earlier quoted context omitted.

Is there an F/OSS alternative to Jenkins that I’m not aware of?

- Woodpecker CI: https://woodpecker-ci.org/ - Drone CI: https://www.drone.io/ - Buildbot: https://buildbot.net/ - Gitea Actions: https://docs.gitea.io/en-us/usage/actions/overview/ - Fogejo Actions: https://forgejo.org/2023-02-27-forgejo-actions/ - GitLab Runners: https://gitlab.com/gitlab-org/gitlab-runner You could also use Ansible playbooks/roles to run your build, although that's going to be a bit more manual: ht…

How did Apache Maven make it onto this list? Seems like Maven is a build tool that one would invoke _from_ Jenkins or Drone.

Re: Infosec company pwned by 4chan user

#114
post #8

Earlier quoted context omitted.

But what's the trap here? Checking who downloads the file? I don't see how they can get any actionable info out of this

1. post link to jenkins job in a 4chan thread relating to something nefarious 2. see who clicks it 3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan Something like that.

>3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan

ahahah 4chan is almost as mainstream as Reddit. ahahahahahahaaaaaaa you really think they would waste time like this for IP addresses to "keep track of"

Re: Infosec company pwned by 4chan user

#115

> which makes it all so much more ironic how completely they have been hacked. Nope, not really. It just takes one mistake and you're pwned. Imagine giving the intern a small project, you're losing your head due to your main project, no time to supervise. Boom. /e: Or imagine an update in one of your libs/apps. In order to not to be hacked you need to make everything right. In order to hack you just need to find one…

I guess they meant paradoxical. Being a security company they are juicy target for an attacker's rep, meaning they are in the situation where they are both more protected than usual but also more at risk. That's the arm's race paradox I guess.

Re: Infosec company pwned by 4chan user

#117
post #78

Earlier quoted context omitted.

Appears to be self-authored.

A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?

To be fair, if I was writing my own Wikipedia page, I would do the same.

Re: Infosec company pwned by 4chan user

#118
post #96

Earlier quoted context omitted.

The correct spelling in that case is pwned isn’t it? I got it from context, but those always felt like subtly different words to me.

I've seen owned plenty of times. "Owned a box" like that

yeah, "owned" came far before "pwned". Wiktionary cites this usenet post from 1996 https://groups.google.com/g/alt.sysadmin.recovery/c/IsdIZqfW... .. can't find an "earliest source" for "pwned" tho

Re: Infosec company pwned by 4chan user

#119

Earlier quoted context omitted.

- Woodpecker CI: https://woodpecker-ci.org/ - Drone CI: https://www.drone.io/ - Buildbot: https://buildbot.net/ - Gitea Actions: https://docs.gitea.io/en-us/usage/actions/overview/ - Fogejo Actions: https://forgejo.org/2023-02-27-forgejo-actions/ - GitLab Runners: https://gitlab.com/gitlab-org/gitlab-runner You could also use Ansible playbooks/roles to run your build, although that's going to be a bit more manual: ht…

How did Apache Maven make it onto this list? Seems like Maven is a build tool that one would invoke _from_ Jenkins or Drone.

That is correct, I removed it from the comment. It's more of an alternative to Apache Ant/make/whatever really.

Re: Infosec company pwned by 4chan user

#120
post #88

I had to check the article to understand how it is notable for a 4chan user to also be a business owner. They're using "owned" in leet speak sense, infiltrated security.

Man I was wondering the exactly same thing! I’m not a native speaker so that might be why

Native speaker, and title confused me even being familiar with the whole owned/pwned thing. I clicked on the article simply because I was curious why being a 4chan-using sole proprietor would be at all interesting.
Post reply on HN