Live data from Hacker News

4chan Sharty Hack And Janitor Email Leak

knowyourmeme.com

541–550 of 1001 posts

Re: 4chan Sharty Hack And Janitor Email Leak

#541

Earlier quoted context omitted.

This is such a common hole. One of my early hacks was a forum that allowed you to upload a pfp but didn't check it was actually an image. Just upload an ASP file which is coded to provide an explorer-like interface. Found the administrator password in a text file. It was "internet" just like that. RDP was open. This was a hosting provider for 4000+ companies. Sent them an email. No thank you for that one. Always chec…

Uploading ASP as an image and having it execute server side is one thing. But in this case, it's subtly different. This issue relies more on a quirk of how PDF and PostScript relate (PDF is built on a subset of postscript). Imagine you had an image format which was just C which when compiled and ran produced the width, height, and then stream of RGB values to form an image. And you formalised this such that it had to…

> it's not really common knowledge that PDF is basically just a subset of postscript.

Because that's not actually true? Check out the table in the PDF specification, Appendix A, p985, listing all the PDF operators and their totally different PostScript equivalents, when there are any: https://opensource.adobe.com/dc-acrobat-sdk-docs/pdfstandard...

The PDF imaging model is mostly borrowed from PostScript, though PDF's imaging model also supports partial transparency. The actual files themselves are totally different.

In this case, no PDF files were involved at all, but a PostScript file renamed to .pdf, which was used to exploit an old insecure GhostScript's PostScript execution engine (PostScript is a programming language, unlike PDF) or maybe parser:

> According to S0I1337, it was done by exploiting a vulnerability on 4chan's outdated GhostScript version from 2012 by uploading a malformed PostScript file renamed to PDF to gain arbitrary code execution as 4chan didn't check if files with PDF extensions were actually PDF files -- https://wiki.soyjak.st/Great_Cuckset, see also the image in A_D_E_P_T's comment https://news.ycombinator.com/item?id=43699395

Re: 4chan Sharty Hack And Janitor Email Leak

#542
post #245

Earlier quoted context omitted.

this might be conspirational thinking, but i don't think it's an accident that the site came out like this. yes, there's moderation, but the moderators are explicitly told to go easy on moderating racism[1]. it feels like once that kind of stuff isn't punished, it starts to snowball a change in the attitudes of the site as a whole. that's not to say stringent moderation doesn't make a site less welcoming, though. it'…

> it feels like once that kind of stuff isn't punished, it starts to snowball a change in the attitudes of the site as a whole. Considering the site has been around for over 20 years and people still call out and flame racism, I think this is an uncharitable and unfounded cynicism. I'm not sure declarative claims of 3rd order effects in a system so chaotic are capable of being accurate.

Multiple white supremacist mass shooters have been 4chan users.

4chan cheered on the Buffalo shooter who was live updating a 4chan thread during his murder spree: https://www.thetrace.org/newsletter/4chan-moderation-buffalo...

The christchurch shooter was a 4chan regular https://theconversation.com/christchurch-terrorist-discussed...

The whole "boogaloo" white nationalist/supremacist movement started on 4chan:

https://www.splcenter.org/resources/reports/mcinnes-molyneux...

Stop whitewashing 4chan's history.

Re: 4chan Sharty Hack And Janitor Email Leak

#543

Earlier quoted context omitted.

> I feel too many people conflate /pol/ with the whole website. Because it is the 2nd most active category, and the racist/alt-right beliefs have spread to the other boards because the head admin fires anyone that tries to moderate it. https://www.vice.com/en/article/the-man-who-helped-turn-4cha... On top of that, they actively delete and ban posts that go against alt-right. I discussed it somewhat recently here: htt…

All of this sentiment is many years out of date. "Alt-right" hasn't been a term of self-identification for almost a decade, and hasn't been used as an identifier by pretty much anyone for at least half of that. /pol/ is not the epicentre of the radical online right and has not been for years - it's a backwater in that regard now. The most notable radicalisation happening on /pol/ nowadays, in my opinion, is a kind of…

I don't think it is out of date at all.

Anti-jewish content was there 10 years ago as well. The board is full of white supremacist posts when I checked yesterday with lots of threads complaining about non-white races. There's absolutely no indication that it has been overtaken by developing countries.

Just because they changed their name to "groyper" doesn't mean they aren't alt-right anymore.

As for support for authoritarian regimes like russia, it is obvious that they are running propaganda on the website and want to sow division in the US by encouraging fringe groups like these.

Re: 4chan Sharty Hack And Janitor Email Leak

#544
post #337

Earlier quoted context omitted.

Wiktionary has a surprisingly robust list https://en.wiktionary.org/wiki/Category:English_4chan_slang

Note, some of these are associated with the far right. > fren later came to prominence on sites such as 4chan and the subreddit /r/frenworld as a dog whistle used by far-right white nationalists and fascists to refer to each other https://en.m.wiktionary.org/wiki/fren

Should be noted that they have a history of trying to co-opt neutral terms and symbols. Like the frog and the ok gesture.

Re: 4chan Sharty Hack And Janitor Email Leak

#545
post #541

Earlier quoted context omitted.

Uploading ASP as an image and having it execute server side is one thing. But in this case, it's subtly different. This issue relies more on a quirk of how PDF and PostScript relate (PDF is built on a subset of postscript). Imagine you had an image format which was just C which when compiled and ran produced the width, height, and then stream of RGB values to form an image. And you formalised this such that it had to…

> it's not really common knowledge that PDF is basically just a subset of postscript. Because that's not actually true? Check out the table in the PDF specification, Appendix A, p985, listing all the PDF operators and their totally different PostScript equivalents, when there are any: https://opensource.adobe.com/dc-acrobat-sdk-docs/pdfstandard... The PDF imaging model is mostly borrowed from PostScript, though PDF's…

Key word: "basically"

Read section 2.4 of the PDF you linked for a bit of additional information on this "bsaically".

GhostScript is a postscript interpreter which can handle PDF files by applying the relatively simple transformations described in that section of the PDF. Whether they embedded the ghostscript exploit within the PDF, or didn't, it's not particularly important for making my point.

Re: 4chan Sharty Hack And Janitor Email Leak

#546

If you lamented the disappearance of the "old internet", well, this was a part of it, and now it may be gone too. The title is also a fair bit understated. They're leaking the moderators home addresses and work contact info (for admins, who are(were?) paid moderators)

4chan is not "old internet". Not even close. It's predated by a bunch of forums (including 2channel) on the Internet, some anonymous.

As far as image boards go, 4chan is the first successful (and longest surviving) English-speaking 2chan clone.

2chan is a japanese site.

Re: 4chan Sharty Hack And Janitor Email Leak

#547
post #3

Earlier quoted context omitted.

Do you think that 4chan is going to disappear forever for this? Just wait a bit and it will be back. Also where did you see that they are leaking home addresses and work contact info? I think they just leaked the emails (I don't understand why home addresses and work contact info should be present in the 4chan database, everyone moderating the site for free).

I'm not up to speed - but isn't that a free-speech absolutist site?

4chan has global rules and board-specific rules.

Racism, hate speech in general, as well as anything illegal, will quickly result in deletion and IP ban.

The site will also, as it's obvious, cooperate with authorities, when it comes to crimes.

4chan is far from being a free-speech absolutist site.

Re: 4chan Sharty Hack And Janitor Email Leak

#548
post #415

I did some digging and the hacker posted which exploit he used. Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell ac…

Got a source? Not doubting, just curious.

Source: https://www.soyjak.st/soy/thread/10615723.html#:~:text=What%...

Kiwifarms is also discussing, links to code and griefing - https://kiwifarms (NSFW/NSFL) .st/threads/soyjak-party-the-sharty.145349/page-1468#post-21102686

Re: 4chan Sharty Hack And Janitor Email Leak

#549

I feel too many people conflate /pol/ with the whole website. I enjoyed browsing through sfw boards like /tg/ (tabletop media), /ck/ (cooking) and /fit/ (fitness). I had long discussions about the SW sequels on /tv/ back in 2015-19. The readership was surprisingly diverse and the anonymity lead users to provide more focused replies. With bodybuilding.com gone, the blue boards felt like the last bastion of the old int…

> bodybuilding.com Obligatory post about the dumbest argument to ever be had online [0]. It’s so good, the Wikipedia entry [1] has a section devoted to it. [0]: https://web.archive.org/web/20240123134202/https://forum.bod... [1]: https://en.wikipedia.org/wiki/Bodybuilding.com

I need to thank you for the web archive post. The argument was amusing as it was dumb.

Re: 4chan Sharty Hack And Janitor Email Leak

#550

I did some digging and the hacker posted which exploit he used. Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell ac…

> could give the attacker shell access.

How do these exploits work? Does it open an SSH port somewhere or does it show up as a browser-based terminal?

Post reply on HN