I did some digging and the hacker posted which exploit he used. Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell ac…
Periodic reminder that a PDF is a turing-complete script that generates a document and should be treated as foreign code
4chan Sharty Hack And Janitor Email Leak
901–910 of 1001 posts
Re: 4chan Sharty Hack And Janitor Email Leak
#902Earlier quoted context omitted.
Nearly every website developer servicing small business builds a WordPress site and sets it up on a hosting company's cPanel install with phpmyadmin running by default.
Which are far far outnumbered by people setting up squarespace sites, or shopify sites or facebook pages or twitter profiles these days. It was definitely true at one point that small scale indie web devs and small business contractors outnumbered big tech in both headcount and servers. I don't think that's been true for a while now.
WordPress powers 43% of websites today. Shopify, Wix, and Squarespace together only account for 11%.
https://w3techs.com/technologies/overview/content_management
Re: 4chan Sharty Hack And Janitor Email Leak
#903Earlier quoted context omitted.
My main problem with 4chan is how they talk, like the language they use. They really don't care about anyone's feelings and show a lack of empathy. Unfortunately this has been spreading to other social media as well. Imagine how good a place it could have been if people over there talked like people on HN.
There is no “they”. Like many others coming from social web, you expect to find some kind of community which fashions everyone shares, an apparel you can put on. The idea is complete opposite: you don't need to follow any fashion, or imagine yourself “part of the team” any more than you want to. Even though it's not written in any rules, you don't have to use slang or tone if you find them dumb, overused (globally or…
Re: 4chan Sharty Hack And Janitor Email Leak
#904Earlier quoted context omitted.
A subset of the population will always be murderous and delusional about something. Just a fact of biology that not everyone is physically or mentally fit.
Sure. It's probably not a good thing we have spaces designed to cook the brains of users to the extent that their weakest links are driven to act on their worst impulses and commit ideologically-driven murder, though. I'm generally on the side of free speech, but having visited /pol/, I can't say it is/was a good place for its inhabitants or society at large.
Re: 4chan Sharty Hack And Janitor Email Leak
#905Earlier quoted context omitted.
Multiple white supremacist mass shooter have been 4chan users and they cheered on the Buffalo shooter who was live updating during his murder spree: https://www.thetrace.org/newsletter/4chan-moderation-buffalo... The christchurch shooter was a 4chan regular https://theconversation.com/christchurch-terrorist-discussed... The whole "boogaloo" white nationalist/supremacist movement started on 4chan: https://www.splcente…
How many of these used Facebook, Twitter or Reddit? They are not mentioned in mainstream media because they are popular, but I assure you there are a lot of deranged people that never even posted on 4chan and just stuck to the “good” ones.
Re: 4chan Sharty Hack And Janitor Email Leak
#906I did some digging and the hacker posted which exploit he used. Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell ac…
https://buer.haus/2019/10/18/a-tale-of-exploitation-in-sprea...
We published a PoC for file write as part of our research and bug bounty submissions:
https://gist.github.com/ziot/fb96e97baae59e3539ac3cdacbd0943...
Re: 4chan Sharty Hack And Janitor Email Leak
#907Earlier quoted context omitted.
There are no true free speech absolutist sites on the open internet. To run a site under free speech absolutist principles would require allowing and refusing to moderate illegal content. People like to confuse "free speech absolutism" for "tolerating right-wing speech" because the free speech absolutist narrative has been pushed by right-wing accelerationists, but every site has its limits, even 4chan.
“Illegal” where? There's a lot of different illegal stuff in a lot of different countries. The elephant in the room is that USA appointed itself as a policeman for the whole network. Demands of its state and business entities are somehow tied to the fact that there is no true free speech on the open internet.
Re: 4chan Sharty Hack And Janitor Email Leak
#908Earlier quoted context omitted.
It's so funny to read this. I've been involved in "internet culture" since the early to mid 90s. The only thing that I heard about that ever came out of 4chan was toxicity.
That's crazy. The whole "dank memes" thing and terms like based, boomer, wojak, and soy are all from channer culture. 4chan managed to brand gen Z as the "zoomer" generation. Its cultural pervasiveness is impossibly deep.
The internet is BIG and atomized.
Re: 4chan Sharty Hack And Janitor Email Leak
#909Earlier quoted context omitted.
No, it's mostly a cancer survivors support group. Every third post was about cancer, what is causing it, and frank expressions of helplessness in the face of it. About half the posts were pornography, racist rants, or memes making fun of someone, often for being mentally handicapped. Five percent was accusing the moderators of sleeping on the job. Edit: I love that people are down-voting this, it really shows how muc…
My understanding is the cancer was mostly killing bees.
Re: 4chan Sharty Hack And Janitor Email Leak
#910Earlier quoted context omitted.
Usually the attacker, on their own computer, or some other server they have root on, will open a port and expose it to the internet and listen. The exploit payload will then make an outbound connection to that port. Once it's connected, the exploit will give the attacker's computer shell access. Search terms include 'reverse shell'. It takes the normal client/server architecture and turns it inside out. If you rememb…
That's why it's a good idea to block connections of all protocols into address ranges where an attacker might be able to host a service. Even on internal networks, if you are a corporation. But it gets better than tunneling over ICMP: DNS tunneling. Pretty much all systems can talk to a DNS resolver. If it resolves arbitrary host names, you can set up a DNS for a zone you control and requests will end up there. With…
It's not a terrible idea, but it's pretty far down the list if things to do. It will stop mass scanners, but probably not any targeted attack unless you try REALLY hard (and then you have a chance of breaking your own infrastructure by accident doing this).
They should start with updating their ghostscript sometime over the last 10 years. Then maybe think about separating some parts of their infrastructure.
I mean, wow, that's really 2012 tech, looks like new owner d invested completely nothing since acquiring 4chan.