Live data from Hacker News

4chan Intrusion Postmorterm

blog.4chan.org

31–40 of 45 posts

Re: 4chan Intrusion Postmorterm

#31

Earlier quoted context omitted.

chippy1337's comment is marked as dead, but here it is for posterity: Rumor is it was an SQL Injection in the "days" parameter of the stats system. Details here -> http://pastebin.com/Fq96ndB6 -----

Ah, chippy1337. Haven't seen that name in a while. Is "he" the original?

[deleted]

Re: 4chan Intrusion Postmorterm

#32

This makes an excellent testimonial for Stripe. Consider the ROI just realised.

4chan gets a lot of of traffic and is well-known so I think anything they use gets a boost in popularity :)

Eh, Stripe has way larger/more high profile customers than us, but yes we've been very happy with them.

Re: 4chan Intrusion Postmorterm

#33
post #20

They should spend time to refactor their code, it's a mess: http://pastebin.com/a45dp3Q1 With that source is much harder to make a security analysis and is easier to create side effects leading to security holes

Per meowface's comment, this code is ~4 years old. It's in a much better place now, but there's still a lot of room for improvement.

The vulnerability wasn't in the main application. I'll write more about it on my personal blog in the coming days (http://chrishateswriting.com).

Re: 4chan Intrusion Postmorterm

#34
post #26
post #16

Earlier quoted context omitted.

http://archive.today/UJAXS

This is the first .newlongwordtld domain I've seen that isn't a spam site squatting on a popular domain equivalent. A new era has begun

Yeah, only because .is domains were being compromised and a new TLD was chosen as an easy alternative.

Re: 4chan Intrusion Postmorterm

#36

Earlier quoted context omitted.

I think that the userbase is rather fickle and it depends on who you piss off. Each board has its own culture so, for example, if you piss off /b/ then you might get an angry mob that gives you grief but I doubt that would happen if you pissed off /g/ or /tg/.

In this case the user who gained access to the database was seen as doing it for a reasonably "noble" reason, relatively speaking (to find information about another user whom some disliked), so from what I can see there hasn't been much backlash against him even though his full name was posted in a few places. It was kind of a self-hack.

Please don't miscontrue the person's intentions as noble, or even put that word in the same paragraph as 4chan. It was misogynistic, sexist harrassment.

Re: 4chan Intrusion Postmorterm

#37
post #33
post #20

They should spend time to refactor their code, it's a mess: http://pastebin.com/a45dp3Q1 With that source is much harder to make a security analysis and is easier to create side effects leading to security holes

Per meowface's comment, this code is ~4 years old. It's in a much better place now, but there's still a lot of room for improvement. The vulnerability wasn't in the main application. I'll write more about it on my personal blog in the coming days ( http://chrishateswriting.com ).

Have you ever thought about re-writing 4chan and making it open source? I think a large portion of the community would be willing to contribute.

Re: 4chan Intrusion Postmorterm

#38

Earlier quoted context omitted.

I think that the userbase is rather fickle and it depends on who you piss off. Each board has its own culture so, for example, if you piss off /b/ then you might get an angry mob that gives you grief but I doubt that would happen if you pissed off /g/ or /tg/.

In this case the user who gained access to the database was seen as doing it for a reasonably "noble" reason, relatively speaking (to find information about another user whom some disliked), so from what I can see there hasn't been much backlash against him even though his full name was posted in a few places. It was kind of a self-hack.

The way I heard it originally the dude broke in while trying to stalk his ex-gf, which is consistent with the report.

Re: 4chan Intrusion Postmorterm

#39
post #36

Earlier quoted context omitted.

In this case the user who gained access to the database was seen as doing it for a reasonably "noble" reason, relatively speaking (to find information about another user whom some disliked), so from what I can see there hasn't been much backlash against him even though his full name was posted in a few places. It was kind of a self-hack.

Please don't miscontrue the person's intentions as noble, or even put that word in the same paragraph as 4chan. It was misogynistic, sexist harrassment.

[deleted]

Re: 4chan Intrusion Postmorterm

#40
post #37
post #33

Earlier quoted context omitted.

Per meowface's comment, this code is ~4 years old. It's in a much better place now, but there's still a lot of room for improvement. The vulnerability wasn't in the main application. I'll write more about it on my personal blog in the coming days ( http://chrishateswriting.com ).

Have you ever thought about re-writing 4chan and making it open source? I think a large portion of the community would be willing to contribute.

IIRC they had open source code called Futabally, but as time went on they closed the sources to protect their interests. Projects like it exist, such as Kusaba X.
Post reply on HN