Live data from Hacker News

4chan Sharty Hack And Janitor Email Leak

knowyourmeme.com

491–500 of 1001 posts

Re: 4chan Sharty Hack And Janitor Email Leak

#491

The take on 4chan on here is super intriguing. I always felt that the current social media/doomscroll/memesharing landscape which has become so common worldwide is indiscernable and in some ways worse than 4chan. It feels like 4chan left it's homepage and went worldwide sometime in the early 2010s when iPhone-style phone use became more commonplace. I remember that 4chan users had more honor than users on the interne…

[dead]

Re: 4chan Sharty Hack And Janitor Email Leak

#492

I see a lot of hate for 4chan here. Why? I’ve never used it, know it by reputation, but not sure why there’s so much hate for it.

I hope this isn't too contentious but I'll try to cover most things. I've posted this a few times, but I checked out 4Chan about twice in the early days and saw CSAM both times and it gave me personally a visceral hatred of the site. I've heard it got better/that's not representative but it's a hard thing to shake. The origin of the site is also supposedly Moot getting kicked off SomethingAwful for posting 'lolicon'…

I don't know what CSAM is and after reading the rest of your post I don't want to Google it

Re: 4chan Sharty Hack And Janitor Email Leak

#493

I did some digging and the hacker posted which exploit he used. Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell ac…

This is an old well known exploit.

Don't run versions of ghostscript from 2012?

Re: 4chan Sharty Hack And Janitor Email Leak

#494

Earlier quoted context omitted.

I hope this isn't too contentious but I'll try to cover most things. I've posted this a few times, but I checked out 4Chan about twice in the early days and saw CSAM both times and it gave me personally a visceral hatred of the site. I've heard it got better/that's not representative but it's a hard thing to shake. The origin of the site is also supposedly Moot getting kicked off SomethingAwful for posting 'lolicon'…

I don't know what CSAM is and after reading the rest of your post I don't want to Google it

"Child Sexual Abuse Material"

Re: 4chan Sharty Hack And Janitor Email Leak

#495
post #17

Jannies had it coming tbh. They were certainly tightening the rope when it came to free speech in the last few years

Always curious to know what kind of speech this kind of complaint refers to.

If you post "What are your favorite snacks at the movie theater?" you can get a 3 day ban from /ck/ which is too short to appeal. I posted a thread on the Television and Movie board asking what people thought of Matt Walsh's movie What is a Woman and got a 3 day ban which was too short to appeal for posting off topic

Re: 4chan Sharty Hack And Janitor Email Leak

#496

Rip 4chan. For all the bad it did, 4chan also made at least one real contribution to science [1], specifically to the study of superpermutations (aka the Haruhi problem), which was cited by genuine academics. We should try to remember it by that. [1] https://www.theverge.com/2018/10/24/18019464/4chan-anon-anim...

I think this is more of a temporary concussion, it'll be back up by the weekend.

Re: 4chan Sharty Hack And Janitor Email Leak

#497
post #81

Earlier quoted context omitted.

Sure, if you slap Basic Auth with "admin:admin" on phpMyAdmin in 2025, you're asking for it. But a Basic Auth password with 256 bits of entropy is just as resistant to brute force as AES-256 (assuming the implementation is sound and TLS is used). It's not the protocol that's insecure, it's usually how it's deployed.

Only if it's only accessible via proper TLS (otherwise it's easy to read the user/pass with MITM as basic auth doesn't encrypt the user/pass). If there is no throttling/rate-limiting/banning then this setup allows for a lot of attempts, wether brute-force or dictionary.

As long as "a lot of attempts" take longer than the time it'll take the sun to expand and envelop the earth, that's not really a problem.

Every form of authentication is either subject to "a lot of attempts" or trivial DoS (for when you rate limit the login API so now admins can't log in either). The principles behind modern authentication are mostly "how do we make verification require even more attempts if the attacker doesn't know the password".

Re: 4chan Sharty Hack And Janitor Email Leak

#498

Posted link is a tad vulgar and scarce on information. A bit of a collection forming on The Sun's live blog post: Thousands of 4Chan users report issues accessing controversial website - https://www.thesun.co.uk/tech/34472708/4chan-down-updates-co...

Why would you use the Sun as a source for anything

Re: 4chan Sharty Hack And Janitor Email Leak

#499

Earlier quoted context omitted.

Like it or not, 4chan was a major hub of Internet culture. Especially early on some of the best stuff on the internet happened on 4chan (and a good chunk of the worst, of course)

Small pedantic correction: “major hub of Internet culture” is “major subculture in English-speaking segment of Internet” (American segment?). In many other languages it was irrelevant.

[deleted]

Re: 4chan Sharty Hack And Janitor Email Leak

#500

Earlier quoted context omitted.

I would be 0% surprised to see Stephen Miller's information in this leak.

If you're looking for malign influence on 4chan - look outside the US. Anyone on /pol/ and /k/ after Oct 7th understands clearly who has been influencing if not controlling the site.

I think it's the other way around; keen observers have noticed a 4chan influence on the US Government's policies.
Post reply on HN