Plagued 4chan - the Internet hate machine

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.

Will the 4chan hack be the end of it?

  • Yes, goodbye forever 4chan

    Votes: 1,031 18.5%
  • No, they will rise from the ashes, stronger than ever

    Votes: 343 6.2%
  • This will rattle them but it will be forgotten about next week

    Votes: 2,323 41.7%
  • I am just here for the janny phonebooking

    Votes: 1,093 19.6%
  • What the fuck is 4chan

    Votes: 218 3.9%
  • Yotsuba&!

    Votes: 569 10.2%

  • Total voters
    5,577
Multiple file posting is fucking gay desu.
Sincerely one of my biggest pet peeves about 8chan in general, just look at this:
look at this.webp
1440 pixels worth of screenspace, the file info summary of the last image is ESCAPING the post container.
In a week of casually checking up on a few boards of 8chan, I have only seen multiple file uploading used for a "good reason" only once, every other time it's just a low effort porn dump or mismash of either reaction images + screenshot slog by someone who is completely indecisive on what they want to post, and as such they post ALL of it.
 
>4chan is actually coming back
Already? I bet they're using this time to update the website's UI mostly. Shit was outdated as fuck.
Better functionality is alright but I doubt it, they didn't bother to do so for years.
But if they give it a slick and modern look I think I will actually cry.
 
  • Feels
Reactions: stars.
Better functionality is alright but I doubt it, they didn't bother to do so for years.
But if they give it a slick and modern look I think I will actually cry.
it comes back with a highlight system where posts are automatically chosen as important based on the number of awards other anons have given them, allowing you to easily skip all posts that are low engagement to quickly catch up on a thread's goingons
 
Where are we supposed to go? Are you going to build any battered anon shelters? Didn't think so.
Everyone is anti-anonitic as fuck. They make us wear the star of pepe on our shoulders when we go out in public. All we want is a home.
The world hates us because we see the world clearly. Most people would prefer the comfortable lie instead of digging through piles of shit to find the truth. We are banned from all water coolers because we can't into the current thing.
This is the part of the Tyler Perry movie where you learn how to fend for yourself in a better environment and become better than your previous iteration.
Quit your abusive relationship!
 
I never understood gold/silver preppers. If shit hits the fan I want food, water, shelter, ammo/guns, tools and working devices, resources that will let me survive ya know. Shiny doubloons? Get the fuck off my property you post-apocalyptic jew. Do leave the gold behind, shekellubber.
View attachment 7271509
A pound of good steel is worth more than a pound of gold in such situations.
I suppose they are min-maxing for the late game once warlords start being decadent, but those people would rather devour you than trade unless you posses an equal or bigger force of arms, which you won't because your specced into future economics over bushcrafting.
Preppers are retarded because, as we all know,
NOTHING EVER HAPPENS
 
  • Agree
Reactions: Grog
Sincerely one of my biggest pet peeves about 8chan in general, just look at this:
View attachment 7271585
1440 pixels worth of screenspace, the file info summary of the last image is ESCAPING the post container.
In a week of casually checking up on a few boards of 8chan, I have only seen multiple file uploading used for a "good reason" only once, every other time it's just a low effort porn dump or mismash of either reaction images + screenshot slog by someone who is completely indecisive on what they want to post, and as such they post ALL of it.
If a feature bothers you, don't use it. Don't try to restrict other people because I find multi-file posts liberating.
 
"PM's aren't worth anything but someone will kill you for them therefore PM's are useless, but give me yer gooold" is the biggest dumb nigger argument in history.
Hoarding precious metals is more likely to get you killed in a failed state. Having the ability to move quickly and quietly with no burdens is something people underrate. In a failed state a reliable hand is more valuable to any warlord than a princeling who measures and presents his worth as shiny rocks that were only elevated to value by merchants and kings in the first place.
I would think any boomer that approached me with such a ridiculous burden thinks himself a merchant or a king, and neither would be a good first impression.
 
In a week of casually checking up on a few boards of 8chan, I have only seen multiple file uploading used for a "good reason" only once, every other time it's just a low effort porn dump or mismash of either reaction images + screenshot slog by someone who is completely indecisive on what they want to post, and as such they post ALL of it.
You weren’t there for the original 8chan then, week one people were generating entire meme genres based on multiple file posting which led to brand new content like cascading Quark laughter because it was literally impossible to do on 4chan with its single file posting. Get creative and use it as a tool, don’t have a toddler floorstomp fit and disregard an entire function over others usage.
 
I think as long as PDF upload is blocked the hack can't just be repeated as easily. Even with the source code leaked, you need to have a way to actually inject your code to the server somehow. Correct me if I'm wrong, but with the remaining file types (JPG, PNG, GIF, WEBM, MP4) there is no way to do that. The other way would be to use security holes in the server itself (operating system, whatever software they use for the web server, PHP, ...) but if they update it all there shouldn't be an obvious gaping hole there.

They might have also gone through the code in the meantime. The anons on Soyjak's /tech/ board they were already fixing the "OpenYotsuba" code for free.
The chain of this hack was essentially that some boards permitted PDF upload. This was done with an ancient (circa 2012) version of the Ghostscript library. This library was so old you could upload garbage that wasn't actually a PDF but was actually PostScript commands as arbitrary code. From there, the hacker found a binary that gave them a path to root.

Now, in terms of fixing the exact hack that was used to own the site, identify the mods/jans, etc., yes, removing the ability to remove PDFs prevents this exact hack from being repeated. Reinstalling the OS on new servers would likely prevent the secondary issue (a binary with bad file permissions/ownership giving a path to root [administrator on *NIX operating systems]).

The problem is that the public and potentially bad actors now have access to the site source code, which is by all accounts I've read, pretty trash in quality (hardcoding of credentials being just one of many sins). If they update the backend like PHP version, MySQL version, OS version, etc. it may not matter if they forget to update another library - like whatever image library is used resizes images and generates their thumbnails. Or if all the backend software is good but there's a bad piece of coding in the site's custom Yotsuba imageboard software that allows, say, SQL injection.

People on 4chan are extremely creative for better and worse. People used to post embedded RARs/Zip archives within images, for fun/better (pirated ebooks) and worse (CSAM). Embedded sound files. I used to be annoyed I couldn't repost the same recation image if someone else had posted it, so I had a BAT file on my desktop that would just apend a garbage abcde on the end of my JPG/PNG/etc. file and the site software would then except it because it technically had a different file hash, even though the actual image data was the same (they probably patched this circa 2014/2015 to remove garbage that wasn't within the image headers.

They may also accept help from the Soyjak types to do code improvement. The risk there is both in competency (how good are your volunteers, do they miss something) and trust (do you have a bad actor either deliberately not fixing something or trying to introduce an innocuous looking change that's actually a vulnerability).
 
Last edited:
  • Informative
Reactions: stars.
Hoarding precious metals is more likely to get you killed in a failed state. Having the ability to move quickly and quietly with no burdens is something people underrate. In a failed state a reliable hand is more valuable to any warlord than a princeling who measures and presents his worth as shiny rocks that were only elevated to value by merchants and kings in the first place.
I would think any boomer that approached me with such a ridiculous burden thinks himself a merchant or a king, and neither would be a good first impression.
I really thought this was somehow about like reactions here on KF.
 
Back