Live data from Hacker News

Infosec company pwned by 4chan user

maia.crimew.gay

151–160 of 234 posts

Re: Infosec company pwned by 4chan user

#151
post #145
post #78

Earlier quoted context omitted.

A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?

I don't think it's a stretch to assume that infosec experts/hackers have ways to falsify their online identities.

Funny to think about: "writing your own Wikipedia page without it getting taken down for Original Research" is a fun first hobby project to certain kinds of network-security people, as much as as "making your Github activity graph solid green" is a fun first hobby project to bot programmers.

Re: Infosec company pwned by 4chan user

#152
post #2

"however, they made one of the most comedic mistakes you can still make while setting up jenkins (im actually not sure which misconfiguration leads to this): the build information for each past build contains a link to the git repository, including the bitbucket credentials in the url. genius."

[deleted]

Re: Infosec company pwned by 4chan user

#153

Back in 90s. I commented to a friend that there sure were a lot of NASA employees on A certain IRC channel. His response was NASA had great computers and no security.

In the 90s I would be hard-pressed to name any of my techie chums who didn't have a shell account on a NASA box, through legal or illegal means. NASA also had some great cables and satellite runs between their facilities and other partners overseas that allowed for moving warez and porn very quickly across the Atlantic when the commercial connection between the UK and USA was something like 2Mbps for the entire country.

Re: Infosec company pwned by 4chan user

#154

I suspect this leak was made by the author themselves and submitted to 4chan via Tor or a VPN. I don't have hard evidence to back this up but if you read the Wikipedia article about them, it's pretty easy to put two and two together.

4chan blocks Tor and VPNs

You can pay for 4chan and bypass the blocks: https://www.4channel.org/pass

Costs $20 per year and can be paid with various cryptocurrencies. Since 4chan keeps IP logs, this seems like a good deal for someone leaking company source code.

Re: Infosec company pwned by 4chan user

#155
post #60

Earlier quoted context omitted.

Oh my, assaulted ? By that single blinking icon? I hope you're ok.

Yet everyone on HN complains about ads Yes I blocked it with ublock

Because at the end of the day, the problem with ads isn't that they're annoying, or get in the way, or are garish, or whatever else. The problem with ads is that they are ads. They're an overt attempt to hijack your attention implant ideas in your head, ideas that are antithetical to your own wellbeing.

A little cat chasing my cursor is just plain fun. No malice involved.

Re: Infosec company pwned by 4chan user

#156

Earlier quoted context omitted.

the platonic ideal of what 'hacker' means imo

hactivism means hacking every unsecure jenkins instance for lulz?

Might be worth doing some reading about hackers and their attitude towards "IP" and whether it can really be "theft".

Re: Infosec company pwned by 4chan user

#157

Earlier quoted context omitted.

They were born in 1999, so it's more like what a new generation's impression of what the old web was like.

FYI, the author uses it/she pronouns.

So it uses it/she pronouns? Usually the object pronoun is second; does that mean that it wants people to call she "it" unless they're doing something to she? That's off the chain, and sounds like meta-trolling.

Re: Infosec company pwned by 4chan user

#159
post #137

Earlier quoted context omitted.

No, the most comedic mistake is to have a public-facing Jenkins running. I mean in general you wouldn't make your CI accessible from the outside, but especially not Jenkins. That software has probably more CVEs every year than all of our other tooling combined.

The most comedic mistake is to have a running jenking in 2023

The vast majority of gigs/jobs I've had which involved touching Jenkins were for the purpose of migrating elsewhere - Gitlab, GitHub Actions, Drone, Harness...

Re: Infosec company pwned by 4chan user

#160
post #78

Earlier quoted context omitted.

Appears to be self-authored.

A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?

Because this is a person that doesn't meet the notoriety requirements for Wikipedia, and goes into a level of detail that is also totally unnecessary. It is trivial to connect to different servers via VPN and creating new usernames on Wikipedia takes seconds.
Post reply on HN