Plagued 4chan - the Internet hate machine

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.

Will the 4chan hack be the end of it?

  • Yes, goodbye forever 4chan

    Votes: 1,031 18.5%
  • No, they will rise from the ashes, stronger than ever

    Votes: 343 6.2%
  • This will rattle them but it will be forgotten about next week

    Votes: 2,322 41.6%
  • I am just here for the janny phonebooking

    Votes: 1,093 19.6%
  • What the fuck is 4chan

    Votes: 218 3.9%
  • Yotsuba&!

    Votes: 569 10.2%

  • Total voters
    5,576
It matters because if they rebuild or rollback using the same source the vulnerabilities than enabled the hack will still be valid.

A partial or complete rebuild is necessary and Gookmoot has neither the technical knowledge to do it himself nor the financial resources necessary to hire someone.

Tldr he's fucked.
Pretty sure he does more than just 4chan, dude. Wasn't he the 2ch founder? Seems like he runs another Japanese imageboard these days and prob has money from ad revenue via both.
 
Someone more technical could give a better answer, but I've seen so many "SOURCE CODE LEAK GUYZ" stuff with games and then nothing ever happens. I think most people don't care to do anything with it so it goes no where. I guess someone could make 4Chan2, but that requires work
this isn't a case of software with only a couple vulnerabilities getting leaked, there are multiple examples upthread where people have taken raw user-entered data and are apparently shelling out and using it as command-line arguments without sanitization. With some of the info in here I could upload a pdf file that would just tell the server to delete itself
 
7 fucking mods for /ck/, where were they that one time a thread with some guys dick as the OP was left on the catalog for what felt like weeks? And wow, I'm not surprised /m/ has only two mods (might as well be zero), no wonder a few shitposters have easily taken over the catalog there with their low quality daily spam.
i believe the same guy was responsible for the "dick on deck" threads on /v/, the penises looked the same
 
They should just open source it.

Host a gitlab, let the community rebuild it, no more anonymous mods, etc.
Not like the mods have been unknown for years anyway. Hell, I've interacted with mods myself. People act like they were always extremely super sekrit, but even a bit of offsite activity linked there will get at least one's attention.
 
Pretty sure he does more than just 4chan, dude. Wasn't he the 2ch founder? Seems like he runs another Japanese imageboard these days and prob has money from ad revenue via both.
He got busted for messing up credit card stuff with 2ch and then the 8chan guys somehow got involved with domain rights and it's all really weird. The point being that I don't think he actually gives a fuck and will dump 4chan if it's becoming a hassle.
 
  • Informative
Reactions: NuII's Clitty💦
/vg/ jannies/mods were so retarded. one time i caught a 3 day ban for actually discussing a game and calling out other retards for shitting up a thread by compiling their posts and posting it. it was during a new season game release so lots of people around.
i then evaded the ban and posted the ban reason to tell the janny to fuck off, which earned me a perma. i evaded that as well and literally called them tranny jannys, after which i don't know how, they gave me another perma AND took away my media posting privileges.
i evaded the ban as usual, but every time i went to post an image, i got an error and the post just simply refused to be posted until i removed the media. it was only on /vg/ and it lasted months until i moved places.
*spits on every single janny* you got what you deserved if you're reading this.
 
i believe the same guy was responsible for the "dick on deck" threads on /v/
'ick on 'eck was a legend, him and that fucker from "vidya butts" gave the jannies a run for their money hotpockets
the penises looked the same
1650743806814.webp
 
Someone more technical could give a better answer, but I've seen so many "SOURCE CODE LEAK GUYZ" stuff with games and then nothing ever happens. I think most people don't care to do anything with it so it goes no where. I guess someone could make 4Chan2, but that requires work
It's different when the source code reveals how hilariously outdated everything is. It's now a giant billboard that says "here's a door that looks like swiss cheese, I sure hope nobody tries to get in"
 
There's no need for such a thing. 4chan is outdated in terms of the Internet media and general web culture. It didn't evolve toward something new, but ended up with the same shit as every other site, just in different boxers.
And I disagree; nature abhors an empty niche, there will always be competitors to fulfill it.
Hey, kill yourself. :)
 
@S0I1337 I might've missed it, but did you see which storage providers they were using? (Pure, NetApp, etc..), did you also have access to the KVM? I am getting more interested to see how garbage the stack was
 
can someone please make a summary of what was actually compromised ?

So far i gather that 4chan gold paypigs got they emails and ips leaked.
Also 4chan recently used to ask for email verification just to bypass catchphras easier, was that compromised too?
 
  • Disagree
Reactions: Punished Magician
Someone more technical could give a better answer, but I've seen so many "SOURCE CODE LEAK GUYZ" stuff with games and then nothing ever happens. I think most people don't care to do anything with it so it goes no where. I guess someone could make 4Chan2, but that requires work
I'm guessing the problem is that the source code has been shown to be outdated, unsafe, and pajeet-tier. If it were safe and well-written, then there shouldn't be any issue with the source code going public.

I don't think there's any value in making "4chan2" when superior open-source imageboard software already exists (e.g., vichan).
 
I'm guessing the problem is that the source code has been shown to be outdated, unsafe, and pajeet-tier. If it were safe and well-written, then there shouldn't be any issue with the source code going public.

I don't think there's any value in making "4chan2" when superior open-source imageboard software already exists (e.g., vichan).
The libraries they use are also going to be out of date. Knowing php, many of the libraries may just be abandoned now so it's not going to be a drop-in replacement with new versions either. They'd probably be better off just forking one of the repos available on GitHub and making it their own (if they can).
 
Someone more technical could give a better answer, but I've seen so many "SOURCE CODE LEAK GUYZ" stuff with games and then nothing ever happens. I think most people don't care to do anything with it so it goes no where. I guess someone could make 4Chan2, but that requires work
The thing with web backends being leaked is that some autist WILL read through the entire thing and find vulnerabilities that can be used for god knows what. The probability of this happening is near 1 especially considering it's 4chan. Either they scrap and rewrite this entire hunk of shit or they'll be pwned again, but honestly it's hard to tell for sure because merely updating your software stack's version fixes a lot of vulnerabilities.
@S0I1337 I might've missed it, but did you see which storage providers they were using? (Pure, NetApp, etc..), did you also have access to the KVM? I am getting more interested to see how garbage the stack was
1744816602017.webp

1744816668718.webp

I just skimmed the code and configs and I think maybe, just maybe, they just uploaded files to their disk directly.
 
Last edited:
  • Like
Reactions: coffin swamp
Someone more technical could give a better answer, but I've seen so many "SOURCE CODE LEAK GUYZ" stuff with games and then nothing ever happens. I think most people don't care to do anything with it so it goes no where. I guess someone could make 4Chan2, but that requires work
In theory, if you grab the true source code, you might find ways to circumvent """safety checks""", such as hardcoded bans, filters, JavaScript sanitization (should be mod+ only privilege), and even captcha (can consider this as the holy grail, allows spamming, etc).
 
Back