Live data from Hacker News

Infosec company pwned by 4chan user

maia.crimew.gay

221–230 of 234 posts

Re: Infosec company pwned by 4chan user

#221
post #195
post #144

Earlier quoted context omitted.

And that's just the ones that get reported. Since core Jenkins is pretty bare-bones, most instances also have many plugins installed, and most of those aren't properly reviewed at all.

The vast majority of those Jenkins CVEs seem to be for a wide variety of plugins, so it seems someone is putting in quite a bit of work to review them.

Yes, to give credit, they do monitor the most important ones which almost everybody uses and which are usually also maintained by developers from Cloudbees. But there are over 1800 plugins for Jenkins, so at least quantitatively, most of them are not monitored.

Re: Infosec company pwned by 4chan user

#222
post #206

Earlier quoted context omitted.

..written in Java. In case anyone needs reminding, Java developers, on purpose, put a line in a logging library that can fetch and execute code when given a url string for a log statement. Nobody should be touching anything Java in 2023.

Yes, we all sat down and unanimously agreed that we should perform JNDI lookups to execute arbitrary code stored in an LDAP directory. No regrets.

Java, Not Even Once.

Re: Infosec company pwned by 4chan user

#223
post #78

Earlier quoted context omitted.

A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?

To be fair, if I was writing my own Wikipedia page, I would do the same.

Especially as a hacker

Re: Infosec company pwned by 4chan user

#224

Earlier quoted context omitted.

Because at the end of the day, the problem with ads isn't that they're annoying, or get in the way, or are garish, or whatever else. The problem with ads is that they are ads. They're an overt attempt to hijack your attention implant ideas in your head, ideas that are antithetical to your own wellbeing. A little cat chasing my cursor is just plain fun. No malice involved.

> A little cat chasing my cursor is just plain fun. No malice involved. There’s a browser setting, "prefers reduced motion" for accessibility reason. And yes, I have that enabled.

https://crimew.gay/notice/AVXaTbTamC92MLk1ei

the cat following the cursor should now apparently be properly disabled with the reduced motion acessibility setting

Re: Infosec company pwned by 4chan user

#225
post #206

Earlier quoted context omitted.

Yes, we all sat down and unanimously agreed that we should perform JNDI lookups to execute arbitrary code stored in an LDAP directory. No regrets.

You joke, but that code made it through rounds of reviews, and nobody saw anything wrong with having a logging library able to make network requests in the first place. I honestly don't even blame the developers of Log4J that much, because after all its open source, and nobody is paying them to use it despite the idiocy surrounding shit like that. I do however blame the developers that use Java, see things like this…

Since developers can just decide to rewrite a code base because Java is not a shiny new language.

Re: Infosec company pwned by 4chan user

#226
post #5

Who makes their Jenkins instance world accessible!

Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…

github has had service issues at least for the last 3 days.

Fun times.

Re: Infosec company pwned by 4chan user

#227
post #137

Earlier quoted context omitted.

No, the most comedic mistake is to have a public-facing Jenkins running. I mean in general you wouldn't make your CI accessible from the outside, but especially not Jenkins. That software has probably more CVEs every year than all of our other tooling combined.

The most comedic mistake is to have a running jenking in 2023

[deleted]

Re: Infosec company pwned by 4chan user

#228

Earlier quoted context omitted.

>3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan ahahah 4chan is almost as mainstream as Reddit. ahahahahahahaaaaaaa you really think they would waste time like this for IP addresses to "keep track of"

Several people have been arrested based on 4chan posts recently, after 'threatening' a law enforcement official in florida. So...yes. Yes I do.

Because threatening a law enforcement officer is actually illegal. and your scare quotes don't make it less of a crime.

Re: Infosec company pwned by 4chan user

#229

Earlier quoted context omitted.

hactivism means hacking every unsecure jenkins instance for lulz?

Might be worth doing some reading about hackers and their attitude towards "IP" and whether it can really be "theft".

http://phrack.org/issues/7/3.html ?

Re: Infosec company pwned by 4chan user

#230
post #137

Earlier quoted context omitted.

No, the most comedic mistake is to have a public-facing Jenkins running. I mean in general you wouldn't make your CI accessible from the outside, but especially not Jenkins. That software has probably more CVEs every year than all of our other tooling combined.

The most comedic mistake is to have a running jenking in 2023

What's the most comparable alternative to use for self-hosted CI in 2023? Curious.
Post reply on HN