Live data from Hacker News

4chan Sharty Hack And Janitor Email Leak

knowyourmeme.com

471–480 of 1001 posts

Re: 4chan Sharty Hack And Janitor Email Leak

#471
post #430

Earlier quoted context omitted.

> I feel too many people conflate /pol/ with the whole website. Because it is the 2nd most active category, and the racist/alt-right beliefs have spread to the other boards because the head admin fires anyone that tries to moderate it. https://www.vice.com/en/article/the-man-who-helped-turn-4cha... On top of that, they actively delete and ban posts that go against alt-right. I discussed it somewhat recently here: htt…

I like /pol/ and although I'm not really interested in defending it (I 100% understand why people don't like it) I will give my opinion of it because I think most people don't get it and take the board wayy too seriously. /pol/ isn't trying to be like the millions of other politic discussion forums online. It's literally intended to be politically outrageous so when people like yourself complain that it's full of out…

"you're typically missing the point."

You too buddy

Re: 4chan Sharty Hack And Janitor Email Leak

#472

Wow doxing the Jannies! I mean, wow, they’re doxing people that helped keep a legacy internet place alive and compliant with the law. Who would do that?

Whoever's trying their hardest to shut down the rest of the free internet as well. I do think these actions we've seen in the last 5 years are co-ordinated. Will post sources soon

Re: 4chan Sharty Hack And Janitor Email Leak

#473

Earlier quoted context omitted.

It's incredibly easy to just not use those websites. My throat remains surprisingly clear with no effort.

It actually isn't, have you ever tried attending any real life function? An account with Meta is almost a requirement to even get in the door.

Uh, yes? What kind of functions are you trying to attend? If you go to C3 and show people your Facebook account, you will rightfully be mocked (unless it's an admin account you're not supposed to have).

Re: 4chan Sharty Hack And Janitor Email Leak

#474
post #244

Earlier quoted context omitted.

/g/ genuinely was one of the worst boards on the website, but there were a handful of lurkers who made good posts in some of the general threads. the site as a whole was still was a diverse place up until yesterday, with only a few boards being unusably bad, and it was getting increasingly better. it's a bit sad really. zero-barrier to entry, no login gates, no accounts, and traffic was so high that it moved really f…

ive always wondered, is there a way to use technology on a board style wesbite to enforce a higher quality culture? i toyed with the idea of requiring an org email similar to Blind except it could be a school email too, the hope being that after verification you are fully anon still just now with write privileges and that it would somehow lead to better quality discussions and engagements

Time limit for a reply. If you could only reply once in a 20 minutes, that wouldn't hinder most thoughtful users, but for user that are quick to draw a reply it's a detterenr.

Re: 4chan Sharty Hack And Janitor Email Leak

#475

I did some digging and the hacker posted which exploit he used. Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell ac…

Reminds me of how people were crashing the PSP's XMB with BMP and TIFF files twenty years ago. I was just a kid, and began "pirating" every one of my classmates' consoles (some in exchange for a small amount of money). Good times.

Re: 4chan Sharty Hack And Janitor Email Leak

#476

I did some digging and the hacker posted which exploit he used. Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell ac…

This is such a common hole. One of my early hacks was a forum that allowed you to upload a pfp but didn't check it was actually an image. Just upload an ASP file which is coded to provide an explorer-like interface. Found the administrator password in a text file. It was "internet" just like that. RDP was open. This was a hosting provider for 4000+ companies. Sent them an email. No thank you for that one. Always chec…

Uploading ASP as an image and having it execute server side is one thing.

But in this case, it's subtly different.

This issue relies more on a quirk of how PDF and PostScript relate (PDF is built on a subset of postscript).

Imagine you had an image format which was just C which when compiled and ran produced the width, height, and then stream of RGB values to form an image. And you formalised this such that it had to have a specific structure so that if someone wanted to, they didn't have to write a C compiler, they could just pull out the key bits from this file which looks like ordinary C and produce the same result.

Now imagine that your website supports uploading such image files, and you need to render them to produce a thumbnail, but instead of using a minimal implementation of the standard which doesn't need to compile the code, you go ahead and just run gcc on it and run the output.

That's kind of more or less what happened here.

It's worth noting here that it's not really common knowledge that PDF is basically just a subset of postscript. So it's actually a bit less surprising that these guys fell for this, as it's as if C had become some weird language nobody talks about, and GCC became known as "that tool to wrangle that image format" rather than a general purpose C compiler.

The attackers in this case relied on some ghostscript exploits, that's true, but if you never ran the resulting C-image-format binaries, you could still get pwned through GCC exploits.

Re: 4chan Sharty Hack And Janitor Email Leak

#477
post #430

Earlier quoted context omitted.

I like /pol/ and although I'm not really interested in defending it (I 100% understand why people don't like it) I will give my opinion of it because I think most people don't get it and take the board wayy too seriously. /pol/ isn't trying to be like the millions of other politic discussion forums online. It's literally intended to be politically outrageous so when people like yourself complain that it's full of out…

> I will give my opinion of it because I think most people don't get it and take the board wayy too seriously. I don't take the board seriously. The posts I made that got deleted for being "off topic" were mocking the alt-right and I just wanted to get a reaction out of people rather than trying to sway anyone. I know I'm not going to convince anyone and I'm not trying to get anyone elected. So when I see my posts ge…

[dead]

Re: 4chan Sharty Hack And Janitor Email Leak

#478

Earlier quoted context omitted.

> bodybuilding.com Obligatory post about the dumbest argument to ever be had online [0]. It’s so good, the Wikipedia entry [1] has a section devoted to it. [0]: https://web.archive.org/web/20240123134202/https://forum.bod... [1]: https://en.wikipedia.org/wiki/Bodybuilding.com

> In 2015, Vice News contacted mathematician Joanna Nelson for a resolution, and she said that TheJosh would have to schedule his workouts in two-week chunks, claiming a week is seven days from Monday to Sunday. Why was a mathematician necessary for this assertion?

Because if you ask an economist you'll get two answers, neither of which will be helpful.

Re: 4chan Sharty Hack And Janitor Email Leak

#479

I feel too many people conflate /pol/ with the whole website. I enjoyed browsing through sfw boards like /tg/ (tabletop media), /ck/ (cooking) and /fit/ (fitness). I had long discussions about the SW sequels on /tv/ back in 2015-19. The readership was surprisingly diverse and the anonymity lead users to provide more focused replies. With bodybuilding.com gone, the blue boards felt like the last bastion of the old int…

It's interesting to note the popularity of the website, and the massive traffic it handled, despite the lack of everything we assume necessary for a modern (social media) website - no modern web frameworks - no microservices/kubernetes clusters - no algorithmic curation/moderation/recommendation algoritmhs One wonders just how much of the modern engineering developed in the past decades, that cost a fortune to develo…

I worked for a major internet company until 2020. HN would be aghast how much "if we failed to provide this service a good chunk of the internet would either go down or sites wouldn't function properly and the stock market probably would dip" stuff runs on redundant pairs of LAMP stacks and other unsophisticated old stuff HN would turn up its nose at.

Re: 4chan Sharty Hack And Janitor Email Leak

#480
post #337

Earlier quoted context omitted.

Note, some of these are associated with the far right. > fren later came to prominence on sites such as 4chan and the subreddit /r/frenworld as a dog whistle used by far-right white nationalists and fascists to refer to each other https://en.m.wiktionary.org/wiki/fren

Why does that matter?

So you can have a clue who you're talking to.
Post reply on HN