Postmortem Site compromised 10-Sep-2019

Status
Not open for further replies.
I find it funny that they want to attack us, when we are the ones cleaning up their fandom by exposing the sexual predators and animal rapist in their community. They should be thanking us.

Right. After the site was back, I searched for it in twitter and I saw some rando normie talking about someone (whose name I forgot, sorry). She said "I was reading the info about X in this kiwifarm forum, and X is indeed a predator and a pedo". Normies don't know all the crazy shit surrounding KF, they only know there is info here and that's it.
 
I think Null left Redis wide open on one of the non-Cloudflare servers (e.g. kiwifarms.pl). I've had it happen where software firewalls fail to start after a reboot due to kernel updates and then accidentally leave a server wide open. So these kind of mistakes happen quite often if you're using a regular "bare" VPS without a hardware firewall and it was only a matter of time before some random port scanner bot found it anyway (though it would have helped for Redis to be password protected it's common for it not to be if only clients from the private network are supposed to connect).

Then you could just connect with a Redis client, list all keys, and download them. I think all the .txt files are cache fragments but someone would need to look into the Xenforo source to confirm if these are commonly cached page fragments. The emails come from your account settings page where you can edit your own email and perhaps @Null could improve things by censoring them like a*@b*.c*.

The IPs were probably part of the cache keys or something to make sure people were served the correct fragments.

What I don't understand is why it all ended up as Markdown. Perhaps Xenforo caches multiple output formats and he happened to download the MD one.

Personally I would have released only the IPs + emails in a CSV with no further explanation. I think that would have spooked Null more as it would be less obvious how they were stolen.
The Redis auth key was 64 length base 64. I don't actually know how they got in. I've just shut down everything except the site proper and locked it all up again.
 
This entire thread is just fifty pages of r.etards gloating about VPNs and asking other people to check if they're on the list. Spoiler alert: it doesn't fucking matter. But this entire debacle has been really amusing, to say the least. This has also made me frighteningly aware of how fucking stupid most kiwis are. inb4 late 👻 come on, Null, give us some speshul badges
No u
 
I don't know why people are freaking. This shit was an inevitability. Do you know how many enemies this place has? Do you know how many people hate that we get to say whatever the fuck we want with impunity? Pretty much every person would have given the fuck up with the shit he's had to go through.

Everything has a price. Freedom isn't ever free.

Also I'd like a purple heart icon since I was shot by the doxing of the autistic faggots by other autistic faggot degenerate pedophile troon furry communists of September 11th 2019 Never Forget War
 
I don't know why people are freaking. This shit was an inevitability. Do you know how many enemies this place has? Do you know how many people hate that we get to say whatever the fuck we want with impunity? Pretty much every person would have given the fuck up with the shit he's had to go through.

Everything has a price. Freedom isn't ever free.

Also I'd like a purple heart icon since I was shot by the doxing of the autistic faggots by other autistic faggot degenerate pedophile troon furry communists of September 11th 2019 Never Forget War
Way I see it, if anyone's freaking out and not being sarcastic about it, is probably going to be ousted as a lolcow, and they don't want that. Especially with the e-mails that might not be burners/throwaway.

Of course, anyone legitimately worrying about IP addresses should at least knock it down a notch, as I don't think a company like Comcast or whoever your ISP provider is will simply hand out information to a bunch of basement dwelling furfags.
 
So I am one of the ""doxed ones"" and I went into 'my' files..
It appears everyone has a file extension with

-account
-contributed
-conversations
-hp
-proving
-started
-tts

In -account I get
[Profile](/members/yiknemoshmoall.37615/)
Light tell gaia to please help stop the spread of ebola in Africa


Not anything to do with my account, although I am now tempted to add it.

In contributed it's pretty accurate on first view.

In conversations I get
[Jul 28, 2019](/conversations/badanimal.52600/latest)

[YikNemoShmoall](/members/yiknemoshmoall.37615/)
[Start a new conversation](/conversations/add)

![](/styles/custom/logos3p/engadget.svg)
"KiA became infested with racism and sexism... and other ism's (though many
ism's are not real). GG forums were created on KiwiFarms and 8chan as a
result," David-me posted. "This was the best and worst thing. The monster was
now a virus. We banned links to, and then mention of certain links and topics.
Now we became the enemy."
* [Kiwi Farms (Dark Theme)](/misc/style)


The thing is here I did start a conversation titled 'bad animal' nothing about KIA though...

In hp
Not going to copy/paste just a random selection of posts some I viewed and some I didn't

In proving
[Profile](/members/yiknemoshmoall.37615/)
used to use kiwi until I couldn't ignore the agenda anymore. I hate myself
for staying. He would yell at us for posting what he doesnt like


Hello? who, what, where why?

In starting
[Show all ](/conversations/) [Start a new conversation](/conversations/add)
[ ![YikNemoShmoall](https://no-
cookie.kiwifarms.pl/data/avatars/s/37/37615.jpg) YikNemoShmoall
](/account/)
[Profile](/members/yiknemoshmoall.37615/)
they doxed my grandma
# Threads started by YikNemoShmoall
![](/styles/custom/logos3p/splc.svg)
"As the alt-right attempted to regain its pre-Charlottesville momentum,
several leaders engaged in a belated PR campaign while vicious flame wars
raged on the The Right Stuff s 504um, Gab.ai and the KiwiFarms.com. These
debates and online battles were framed around the question of optics,
tactics and messaging."


So.. dear hacker bot am I anti or pro the alt right???

-tts
[General Chat](/chat/general-chat.1/) [Arguments & /pol/tards](/chat
/arguments-pol-tards.2/)
[ ![YikNemoShmoall](https://no-
cookie.kiwifarms.pl/data/avatars/s/37/37615.jpg) YikNemoShmoall
[ ![YikNemoShmoall](https://no-
cookie.kiwifarms.pl/data/avatars/s/37/37615.jpg) YikNemoShmoall
[Profile](/members/yiknemoshmoall.37615/)
Kirby: i have been completely vindicated of being a pedophile nothing you say
matters anymore
[ ![YikNemoShmoall](https://no-
cookie.kiwifarms.pl/data/avatars/s/37/37615.jpg)
](/members/yiknemoshmoall.37615/)
![](/styles/custom/logos3p/splc.svg)
"The Internet sleuths at the site Kiwi Farms, where she had at one time been
an active member, further tracked Souvanarrath s activities and ascertained
that she had also been an active member at a forum devoted to fascist ideology
called Iron March, which is apparently operated by a man named Alexander
Slavros."


Uh?

So what is weird (to me) about this, they have connected my account to things I said on it (so viewable on public KF) but also to a ragtag of things I haven't. I really can't see how I am more damaged by what 'this hack' has assigned to me. It just seems so random with a vague altrighty charlotteville fascist miasmaish mess.

Anyone else have bizzarro-files?

Edit: ahh OK thanks for the clarification. Just skimmed the thread and didn't release the random.txt was referring to within the user files and didn't recognise those in mine. What a pointless waste to generate these files (yes I know I'm late with that to),
 
Last edited:
Status
Not open for further replies.
Back