- Joined
- Apr 7, 2025
As someone whose web dev experience is making a hello world.html page once, what is the harm in disabling PDFs and just putting the site back up? To me it seems like the worst case is that someone finds another exploit and they deface everything and call the jannies niggerfaggots, but that is the status quo without having a website up
Because the source code was leaked included the CAPTCHA key, admin salts, hashes, and general codebase layout. It's a blueprint for future hacks. Even if those other things weren't embedded as a lateral layer, the web server's OS is at EoL and unmaintained for a decade, running on the most vulnerable version of Ghostscript ever released, and shell execution paths on a shared storage path without sandboxing.