Live data from Hacker News

Infosec company pwned by 4chan user

maia.crimew.gay

161–170 of 234 posts

Re: Infosec company pwned by 4chan user

#161
post #78

Earlier quoted context omitted.

A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?

Because this is a person that doesn't meet the notoriety requirements for Wikipedia, and goes into a level of detail that is also totally unnecessary. It is trivial to connect to different servers via VPN and creating new usernames on Wikipedia takes seconds.

They clearly do meet the notability requirements; the cites on this article are almost as long as the article itself. Notability on Wikipedia is a term of art; it refers ("mostly") to how much of the content of the article can be drawn from (ideally diverse) secondary sources. It's not an achievement award.

Re: Infosec company pwned by 4chan user

#164
post #5

Who makes their Jenkins instance world accessible!

Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…

I like that with Jenkins you can use groovy, which gives you some extra power as far as writing commands is considered. You don't have to do everything via shell. Equivalent shell commands can be a bit messy sometimes.

It was a bit painful to write the same stuff in GitHub actions. Jira's groovy script made loops, storing variables very easy compared to GitHub actions' YAML.

Re: Infosec company pwned by 4chan user

#165
post #78

Earlier quoted context omitted.

A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?

Because this is a person that doesn't meet the notoriety requirements for Wikipedia, and goes into a level of detail that is also totally unnecessary. It is trivial to connect to different servers via VPN and creating new usernames on Wikipedia takes seconds.

> Because this is a person that doesn't meet the notoriety requirements for Wikipedia

Very much does, just because you don't know them doesn't mean they don't.

Re: Infosec company pwned by 4chan user

#166

I suspect this leak was made by the author themselves and submitted to 4chan via Tor or a VPN. I don't have hard evidence to back this up but if you read the Wikipedia article about them, it's pretty easy to put two and two together.

The readme of the leak contains "meow :3", and the author's website is strongly cat-themed. Doesn't prove anything, but an interesting coincidence.

Also this very submission https://crimew.gay/notice/AVWTkvCXna4Pca7OCm

(Unironically keep slaybossing, OP)

Re: Infosec company pwned by 4chan user

#167

Earlier quoted context omitted.

>3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan ahahah 4chan is almost as mainstream as Reddit. ahahahahahahaaaaaaa you really think they would waste time like this for IP addresses to "keep track of"

Several people have been arrested based on 4chan posts recently, after 'threatening' a law enforcement official in florida. So...yes. Yes I do.

The "bait" this comment is referring to is that a Sheriff publicly denounced in a press conference a bunch of neo-nazi messaging spread around his town during a racecar event.

https://www.jta.org/2023/04/27/united-states/a-florida-sheri...

The sheriff's parents' house was swatted. These are the 4chan posts which were included in the various news articles.

https://sports.yahoo.com/4chan-2-men-used-online-170958670.h...

> "It's too bad Mike Chitwood isn’t safe now that I'm planning to kill him. I'm going to shoot Mike Chitwood. I'm going to kill him by shooting him to death."

> "Just shoot Chitwood in the head and he stops being a problem. They have to find a new guy to be the problem. But shooting Chitwood in the head solves an immediate problem permanently. Just shoot Chitwood in the head and murder him."

https://www.clickorlando.com/news/local/2023/04/20/3rd-4chan...

> “I WILL KILL CHITWOOD, MARK MY WORDS.”

Re: Infosec company pwned by 4chan user

#168

Earlier quoted context omitted.

the platonic ideal of what 'hacker' means imo

hactivism means hacking every unsecure jenkins instance for lulz?

No, just the ones where the result is a leak of information on some large government surveillance program, or, say, exposing incompetence of a company that sells security-related products - especially ones focused on "intellectual property".

Not that there's anything wrong with lulz as a motivation from the perspective of old-time hacker ethos.

Re: Infosec company pwned by 4chan user

#169

Back in 90s. I commented to a friend that there sure were a lot of NASA employees on A certain IRC channel. His response was NASA had great computers and no security.

Around here, it was the local college and universities. My friend, in high school at the time, pwned CS departments at both an Ivy and state college, gave out dozens of cracked SunOS accounts to BBSers and script kiddies (the password file was unshadowed...) Tying up all the dialups with IRC and the non-stop downloading of warez eventually brought the attention of sysadmins, but it went on for months.

Re: Infosec company pwned by 4chan user

#170
post #60

Earlier quoted context omitted.

Oh my, assaulted ? By that single blinking icon? I hope you're ok.

Interestingly, had this complaint been about an ad, parent would have been upvoted with hundreds of comments agreeing with them. In other words, what OP is trying to say is that websites should be designed with the users goals in mind, and IMO it's fair to say that this website wasn't designed that way.

Ads are generally not nostalgic references (and when they are, you still know that it's someone ultimately trying to push your emotional buttons to get you to give them money).

https://en.wikipedia.org/wiki/Neko_(software)

Post reply on HN