Live data from Hacker News

4chan Intrusion Postmorterm

blog.4chan.org

21–30 of 45 posts

Re: 4chan Intrusion Postmorterm

#21
post #20

They should spend time to refactor their code, it's a mess: http://pastebin.com/a45dp3Q1 With that source is much harder to make a security analysis and is easier to create side effects leading to security holes

That code was leaked in 2010 and is quite out of date. Since then they've updated their codebase quite a bit.

Re: 4chan Intrusion Postmorterm

#22
post #6

Way to not give any details about the vulnerability...

chippy1337's comment is marked as dead, but here it is for posterity: Rumor is it was an SQL Injection in the "days" parameter of the stats system. Details here -> http://pastebin.com/Fq96ndB6 -----

Ah, chippy1337. Haven't seen that name in a while.

Is "he" the original?

Re: 4chan Intrusion Postmorterm

#25
post #23

I find myself wondering who in their right mind pokes 4chan with a stick. It is not an angry mob I would care to have ambling in my general direction.

I think that the userbase is rather fickle and it depends on who you piss off. Each board has its own culture so, for example, if you piss off /b/ then you might get an angry mob that gives you grief but I doubt that would happen if you pissed off /g/ or /tg/.

Re: 4chan Intrusion Postmorterm

#27
post #8
post #7

Earlier quoted context omitted.

I suspect a lot of people will be unable to read it if they use HTTPS everywhere: the 4chan blog does not support https and the EFF is currently in a ruleset freeze so they cannot reflect that until the next stable version is out.

Tumblr only recently added SSL support, which is likely the reason Moot hasn't implemented it yet. That said, I(unfortunately) doubt that HTTPS-everywhere is being utilized by that many people.

That's only for the dashboard. Blogs are still cleartext. It's possible to do SSL for *.tumblr.com domains but not (easily) for custom ones.

Re: 4chan Intrusion Postmorterm

#28
post #19
post #15

Earlier quoted context omitted.

4chan Pass, which enables you to bypass the annoying CAPTCHA (and is a kind of CAPTCHA in itself, since a computer can't own a credit card); much like Reddit Gold

Is a credit card like a captcha? A computers may not be able to own credit cards, but they can use cards owned by someone else.

Most of the spam on 4chan isn't that serious to be worth using fraudulent cards.

Re: 4chan Intrusion Postmorterm

#29
post #23

I find myself wondering who in their right mind pokes 4chan with a stick. It is not an angry mob I would care to have ambling in my general direction.

I think that the userbase is rather fickle and it depends on who you piss off. Each board has its own culture so, for example, if you piss off /b/ then you might get an angry mob that gives you grief but I doubt that would happen if you pissed off /g/ or /tg/.

In this case the user who gained access to the database was seen as doing it for a reasonably "noble" reason, relatively speaking (to find information about another user whom some disliked), so from what I can see there hasn't been much backlash against him even though his full name was posted in a few places. It was kind of a self-hack.
Post reply on HN