Live data from Hacker News

4chan Sharty Hack And Janitor Email Leak

knowyourmeme.com

561–570 of 1001 posts

Re: 4chan Sharty Hack And Janitor Email Leak

#561

I did some digging and the hacker posted which exploit he used. Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell ac…

pretty interesting discovery if that was the hack.

do you know what the legal implications are for this?

if the company that owns 4chan finds the identity of the attacker, could they sue him in civil court? or do they send whatever logs they have to the FBI and the FBI would initiate a criminal prosecution? also what is the criminal act here? is it accessing their systems, or is it posting the data that they found "through unauthorised means" on a public channel like twitter? does the "computer fraud and abuse act" apply?

like if you found this exploit, and sent it to the company in good faith (ie a "good hacker"), are you free from prosecution? and what is the grey area, like if you found this exploit and then just sat on it for a while (let's say you didn't report it to the company, but let's also say you didn't abuse it, ie leak private data to twitter)

Re: 4chan Sharty Hack And Janitor Email Leak

#562
post #394
post #238

Earlier quoted context omitted.

it is, and unfortunately from 2016 onwards it kind of outgrew the rest of the site like a tumorous growth until the whole site became markedly more neonazi and less goofy. something to do with donald trump i suspected

I've heard multiple times about a bit of lore that holds that 4chan once tried to brigade Stormfront, causing Stormfront to brigade back, and that was how the cross pollination occurred and started turning 4chan fascist. No idea if this is true but it sounds plausible.

I think the much more likely explanation is that 4chan always existed as a genuine counterculture (which was particularly true in the age prior to the late 2010s, when the internet was like a completely different world to real life), and reflected the rejection and inversion of certain societal mores. The rise of a far right current in 4chan exactly mirrored the kind of progressive fundamentalism that emerged in the dominant culture from around 2013. The outer zeitgeist started to abandon a 30-50-year term of post-racial thought, and immutable characteristics like race and gender started to become meaningful as tangible social capital in a kind of "official" way, as ideas like the progressive stack filtered from online circles and Occupy Wall St, through academia, into the halls of power and governments. The emerging racial consciousness of places like 4chan were a direct (and predictable) reaction to that.

The reason that places like 4chan became a far-right haven and other areas of the internet didn't has nothing to do with whether people tried to raid Stormfront in the 2000s, but is purely a matter of the firm-handedness (or lack thereof) of their respective moderation. Prior to the 2010s, many less-moderated areas of the internet had a variety of political persuasions, but from 2015 to the present day, there is a very strong correlation between the prevailing political leaning of a space and that space's ideological moderation strength.

Re: 4chan Sharty Hack And Janitor Email Leak

#563

Earlier quoted context omitted.

That IS dumb -- everyone knows there are 8 days in a week. Sunday to Sunday -- you can count it on your hands!

Well, the thing is that if it's Sunday you can't know if it's the Sunday at the end of the week or the Sunday at the beginning of the week. Therefore, each Sunday is in two weeks and should be counted twice, 8 + 2 = 10 days in a week. Don't feel bad, a lot of people miss this.

Phewah. I feel like you just upgraded my entire life!

Re: 4chan Sharty Hack And Janitor Email Leak

#565

Earlier quoted context omitted.

It's incredibly easy to just not use those websites. My throat remains surprisingly clear with no effort.

It actually isn't, have you ever tried attending any real life function? An account with Meta is almost a requirement to even get in the door.

Thats insane. I have never been carded for a meta account IRL.

Re: 4chan Sharty Hack And Janitor Email Leak

#566
post #550

I did some digging and the hacker posted which exploit he used. Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell ac…

> could give the attacker shell access. How do these exploits work? Does it open an SSH port somewhere or does it show up as a browser-based terminal?

Usually the attacker, on their own computer, or some other server they have root on, will open a port and expose it to the internet and listen. The exploit payload will then make an outbound connection to that port. Once it's connected, the exploit will give the attacker's computer shell access. Search terms include 'reverse shell'.

It takes the normal client/server architecture and turns it inside out. If you remember FTP and active vs passive, it works like active mode FTP.

That's just one way to do it. If the attacker wants to actually listen on an open port on a compromised server that's behind a firewall, look up 'NAT traversal' for like half a dozen ways to do it.

One interesting method to get a shell that I read about is (ab)using ICMP echo requests. ICMP echo requests can contain arbitrary bytes as a payload. So the exploit will poll the attacker's IP address with ICMP echo requests. The exploit will have data payloads that have the shell's output. The attacker's server will respond with ICMP echo requests that have whatever the attacker wants to type into the shell. It's kinda janky but it works. Lots of firewalls might block outbound UDP/TCP connections from internal servers that don't need to make outbound connections, or might whitelist the addresses they're allowed to connect to. But they won't block ICMP, either because it's considered harmless or they forgot or they didn't know it needs to be blocked separately with other rules.

The point is there's any number of ways to do it, each more clever than the last.

Re: 4chan Sharty Hack And Janitor Email Leak

#568
post #147

Earlier quoted context omitted.

For users who aren't familiar with 4chan - this post describes only one board - /pol/, where you can find hateful posts about every race and religion. 4chan have 30+ boards in total

This is /pol/ focused, yes, but the other boards aren't separate worlds. It's all part of what many call the "alt-right pipeline" and it's subtle and insidious. For example, many (particularly women) have consumed Candace Owens's content about the Blake Lively / Justin Baldoni saga, just like many followed certain creators with the Amber Heard trial. Both of thse fall squarely on the alt-right pipeline. So you may st…

>Candace Owens's content about the Blake Lively / Justin Baldoni saga, just like many followed certain creators with the Amber Heard trial.

No offense, but this just sounds like gossip

Re: 4chan Sharty Hack And Janitor Email Leak

#569
post #238

Earlier quoted context omitted.

it is, and unfortunately from 2016 onwards it kind of outgrew the rest of the site like a tumorous growth until the whole site became markedly more neonazi and less goofy. something to do with donald trump i suspected

the fash trend on /pol/ died somewhere around 2018 and has shifted significantly radleft in the years since. This is misunderstood by outsiders largely because /pol/ users don't actually hold these opinions, they just will represent whatever is the edgiest opinion at any given time. And despite things like shooting pharma executives in broad daylight being mainstream now, /pol/lacks rightly recognize that this is sti…

I'm too red pilled off of post-irony to accept that argument anymore.

Their internal narrative and outward justification for their transitory position is irrelevant.

Re: 4chan Sharty Hack And Janitor Email Leak

#570
post #550

I did some digging and the hacker posted which exploit he used. Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell ac…

> could give the attacker shell access. How do these exploits work? Does it open an SSH port somewhere or does it show up as a browser-based terminal?

A shell's stdin and stdout can be redirected to a tcp socket which connects to the attacker. Here are some examples: https://www.invicti.com/learn/reverse-shell/
Post reply on HN