4chan - the Internet hate machine

  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account

Will the 4chan hack be the end of it?

  • Yes, goodbye forever 4chan

    Votes: 1,051 18.2%
  • No, they will rise from the ashes, stronger than ever

    Votes: 363 6.3%
  • This will rattle them but it will be forgotten about next week

    Votes: 2,396 41.4%
  • I am just here for the janny phonebooking

    Votes: 1,122 19.4%
  • What the fuck is 4chan

    Votes: 252 4.4%
  • Yotsuba&!

    Votes: 599 10.4%

  • Total voters
    5,783
Yo, does anyone remember Poopy Joe, the /v/schizo who had a weird hateboner for Mother 3 and samefags/shits up every thread involvong the series? Wonder where he went?
I've been thinking a lot about the sheer volume of schizos who shit up 4chan and what they could possibly be doing without their little power trips of being allowed to shit up whatever thread they like as long as it's not one a janny is in.
 
I started up a YouTube video this morning, and it started with "So this is a green text story from 4chan". I was immediately disquieted by the prospect that there may never BE greentext stories from 4chan anymore. One of the most iconic, powerful meme formats on the Internet might be going extinct.

It feels surreal. It'd be like you told me the Appalachian mountains don't exist anymore. They've been a fixture of the cultural landscape long enough to be considered ancient history, and now they're just gone? It feels impossible, but that's where we're at. I can only hope whatever comes next is an improvement.
 
>a mistaken suid binary
Lol I thought this might the case.
For those interested in the technical details there, what this means is that there was an executable with a SUID permission bit set, which means that when it is ran, it runs with the privileges of the user who owns it, in this case root, the system administrator. Correction as I was wrong, seems it's instead some user called global. Probably serves a similar function.
There are a few binaries which have this by default, but if applied to the wrong binary, it can mean almost instant privilege escalation from a standard user, to admin. a more privileged user.
There are even automated tools which can check for potential privilege escalation vectors such as these, which just makes this even worse that it was possible.
it wasn't escalating to root though, it was escalating to user named "global" (it was mentioned in a sharty post, and the filename)
I guess that user could have been a sudoer... (if such a concept exists in BSD)
FreeBSD has both doas(1) and sudo(1). My guess is that the global had access to a file somewhere that contained the root or global password and at that point it/s trivial to do a sudo su root -c /bin/sh

I don't have a global user in my system's passwd so it has to be some admin user they set up. It's extremely likely it was in the doas/sudo users, and probably was in the wheel and operator groups as well.
 
Besides watching the absolute degenerate jannies finally getting their comeuppance, I also took great pleasure in revisiting late 00s early 10s 4chan memes & copypasta. Nostalgic shit almost brought a tear to my eye (which is probably a decent indicator I should finally kill myself).
 
I started up a YouTube video this morning, and it started with "So this is a green text story from 4chan". I was immediately disquieted by the prospect that there may never BE greentext stories from 4chan anymore. One of the most iconic, powerful meme formats on the Internet might be going extinct.

It feels surreal. It'd be like you told me the Appalachian mountains don't exist anymore. They've been a fixture of the cultural landscape long enough to be considered ancient history, and now they're just gone? It feels impossible, but that's where we're at. I can only hope whatever comes next is an improvement.
Why are you people being so dramatic, the website will be back in like a week.
 
To all of the 4channers, this is a good time - or maybe in a rare while to go OUTSIDE to finally get that GF.
But who am I kidding? They never wiwill.
A few open question to anyone using the term "4channer":
  1. Are you vaxxed?
  2. When were you "peaked" (because you're afraid to say "redpilled") on trannies?
  3. What is your most recent original thought?
  4. Can you rotate an image of an apple in your head?
 
FreeBSD has both doas(1) and sudo(1). My guess is that the global had access to a file somewhere that contained the root or global password and at that point it/s trivial to do a sudo su root -c /bin/sh
It was even sillier.
There was a setuid binary called /usr/local/bin/suid_run_global which simply execves a perl script. Said perl script was writable by www so it could be hijacked to acquire a shell.
 
I'm predicting now the resurrected version of 4chan is filled with holes and exploits and gets hacked again in a minute.
I seriously doubt they would do this. I'm sure there's a lot of work to do but it's important that they think about whitelisting mod/admin actions by IP instead of just username/password. If I had to guess, the code also needs to be audited before they just deploy again
 
Back
Top Bottom