Poa.st / Chudbuds.lol General Discussion Thread - !! Poa.st and Bae.st have been compromised, all direct messages have been leaked. !!

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.
"We have been working on security" graf said.
"The only way anything would happen would be via social engineering" he said.
:story: :story: :story: :story: :story:

lmao.png
 
The alleged smoking gun. Neat.
Deleted accounts don't appear in leaks unless they have already been sweeped up. Also may be the same if accounts had zero DM activity. The only ones with egg on their face are those trying to be sneaky in post dms or sending nudes/embarrassing shit.
 

Attachments

  • Screenshot_20230525_213628_Husky Beta.jpg
    Screenshot_20230525_213628_Husky Beta.jpg
    788.7 KB · Views: 35
  • SmartSelect_20230525_213718_Husky Beta.jpg
    SmartSelect_20230525_213718_Husky Beta.jpg
    149.9 KB · Views: 36
deleting an account probably doesn't cascade to each dm or post that is stored in the database
Deleted accounts still had their DMs leaked, but not emails as far as I can tell.

Luckly I migrated my account to chudbuds.lol :)
Hopefully poa.st deleted my account from their database when I moved. I don't want my dox to get out.
You should be fine so long as you didn't send private info in DMs.
 
Why do so many retards send nudes on these "alternative" sites? It would be more secure to email them or fucking print them out and send through the actual mail.
ftfy

The alleged smoking gun. Neat.
Isn't it the way we were attacked last year? I mean, through a script disguised as some non-executable file, used as an attachment and the executed once it was uploaded.
 
This was attached to graf's message there.
So, no real social engineering. They spun up a fediverse-specific attack, using the way things federate to get the oauth token-capturing file to execute locally. That's kind of slick.

It's unclear if it required a user to even open it. I think it might get triggered with just the way previews work.
 
The alleged smoking gun. Neat.
Deleted accounts don't appear in leaks unless they have already been sweeped up. Also may be the same if accounts had zero DM activity. The only ones with egg on their face are those trying to be sneaky in post dms or sending nudes/embarrassing shit.
Why would user-deleted accounts not be in the database, but ones that got banned are? Seems weird to delete one and not the other.
 
The tranny mastodon side of the fediverse are 100% going to be all over this. They have nothing better to do. If your a nigger/nazi/loli poaster and registered with real.name@job or your .edu account expect problems.
Hopefully nobody is stupid enough to use their real names on websites like this in general.
 
Why do some of these conversations look one sided when they clearly weren't? Would users that got banned or moved instances get their messages purged or something?
Not sure, but maybe if a user is banned/defederated their messages are purged? I think a couple vanished from my DMs back when people were using it during the Keffals bullshit, but I don't know if that would remove them from the server records.
 
Back