replace the members of staff who will now undoubtedly resign (good luck finding new ones).
Dear leader has already named his price. lmao
outside of the strange moving parts (e.g the PDF parsing) there's very little attack surface
I haven't read the source code; I
generally buy it that weird shit aside (like, /sci/ LaTex support, PDF shit etc.) it is probably not super vulnerable. You still have to audit the whole thing though. Hopefully they had offsite backups of, well, everything. Code, sure it's
hopefully all in version control somewhere; but the database? eh I'm not super confident. And you'll probably want to audit it as well...
And whatever ancillary scripts etc. you'd expect to see on their side... like, I throw up a little in my mouth just thinking about porting python2 (EoL was in 2015, around the EOL of FreeBSD 10.1).
And this is the thing, aside from the fact that it will take a full reinstall and pretty heavy retrofitting to a modern OS,
anything that wasn't backed up offsite and pretty carefully controlled will have to be audited. Doesn't matter if you had an rsync running that preserved some deployment script,
and that it still works on debian 13, if you
didn't actually skim through it to see if the attacker didn't leave a surprise there for you.
I think a team retarded enough not to maintain their server is too retarded to pull this off.
Null could, and shit if I was Hiroyuki idk who else I'd get. If Hiroshimoot can pay RapeApe +4k a month for his exceptional chief janny service, the site could probably afford ~15k/mo for an actual person doing actual work.