Earlier quoted context omitted.
A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?
I don't think it's a stretch to assume that infosec experts/hackers have ways to falsify their online identities.
Infosec company pwned by 4chan user
151–160 of 234 posts
Re: Infosec company pwned by 4chan user
#152"however, they made one of the most comedic mistakes you can still make while setting up jenkins (im actually not sure which misconfiguration leads to this): the build information for each past build contains a link to the git repository, including the bitbucket credentials in the url. genius."
Re: Infosec company pwned by 4chan user
#153Back in 90s. I commented to a friend that there sure were a lot of NASA employees on A certain IRC channel. His response was NASA had great computers and no security.
Re: Infosec company pwned by 4chan user
#154I suspect this leak was made by the author themselves and submitted to 4chan via Tor or a VPN. I don't have hard evidence to back this up but if you read the Wikipedia article about them, it's pretty easy to put two and two together.
4chan blocks Tor and VPNs
Costs $20 per year and can be paid with various cryptocurrencies. Since 4chan keeps IP logs, this seems like a good deal for someone leaking company source code.
Re: Infosec company pwned by 4chan user
#155Earlier quoted context omitted.
Oh my, assaulted ? By that single blinking icon? I hope you're ok.
Yet everyone on HN complains about ads Yes I blocked it with ublock
A little cat chasing my cursor is just plain fun. No malice involved.
Re: Infosec company pwned by 4chan user
#156Re: Infosec company pwned by 4chan user
#157Earlier quoted context omitted.
They were born in 1999, so it's more like what a new generation's impression of what the old web was like.
FYI, the author uses it/she pronouns.
Re: Infosec company pwned by 4chan user
#158Re: Infosec company pwned by 4chan user
#159Earlier quoted context omitted.
No, the most comedic mistake is to have a public-facing Jenkins running. I mean in general you wouldn't make your CI accessible from the outside, but especially not Jenkins. That software has probably more CVEs every year than all of our other tooling combined.
The most comedic mistake is to have a running jenking in 2023
Re: Infosec company pwned by 4chan user
#160Earlier quoted context omitted.
Appears to be self-authored.
A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?