Internet Archive breached again through stolen access tokens

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.
Link (Archive)

By Lawrence Abrams
October 20, 2024 10:46 AM
main1.png
The Internet Archive was breached again, this time on their Zendesk email support platform after repeated warnings that threat actors stole exposed GitLab authentication tokens.

Since last night, BleepingComputer has received numerous messages from people who received replies to their old Internet Archive removal requests, warning that the organization has been breached as they did not correctly rotate their stolen authentication tokens.

"It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor.

"As demonstrated by this message, this includes a Zendesk token with perms to access 800K+ support tickets sent to info@archive.org since 2018."

"Whether you were trying to ask a general question, or requesting the removal of your site from the Wayback Machine your data is now in the hands of some random guy. If not me, it'd be someone else."
main2.png
Internet Archive Zendesk emails sent by the threat actor
Source: BleepingComputer

The email headers in these emails also pass all DKIM, DMARC, and SPF authentication checks, proving they were sent by an authorized Zendesk server at 192.161.151.10.
main3.png
Internet Archive Zendesk email headers
Source: BleepingComputer

After publishing this story, BleepingComputer was told by a recipient of these emails that they had to upload personal identification when requesting a removal of a page from the Wayback Machine.

The threat actor may now also have access to these attachments depending on the API access they had to Zendesk and if they used it to download support tickets.

These emails come after BleepingComputer repeatedly tried to warn the Internet Archive that their source code was stolen through a GitLab authentication token that was exposed online for almost two years.

Exposed GitLab authentication tokens​


On October 9th, BleepingComputer reported that Internet Archive was hit by two different attacks at once last week—a data breach where the site's user data for 33 million users was stolen and a DDoS attack by a pro-Palestinian group named SN_BlackMeta.

While both attacks occurred over the same period, they were conducted by different threat actors. However, many outlets incorrectly reported that SN_BlackMeta was behind the breach rather than just the DDoS attacks.
main4.png

JavaScript alert on Internet Archive warning about the breach
Source: BleepingComputer

This misreporting frustrated the threat actor behind the actual data breach, who contacted BleepingComputer through an intermediary to claim credit for the attack and explain how they breached the Internet Archive.

The threat actor told BleepingComputer that the initial breach of Internet Archive started with them finding an exposed GitLab configuration file on one of the organization's development servers, services-hls.dev.archive.org.

BleepingComputer was able to confirm that this token has been exposed since at least December 2022, with it rotating multiple times since then.
main5.png
Exposed Internet Archive GitLab authentication token
Source: BleepingComputer
The threat actor says this GitLab configuration file contained an authentication token allowing them to download the Internet Archive source code.
The hacker say that this source code contained additional credentials and authentication tokens, including the credentials to Internet Archive's database management system. This allowed the threat actor to download the organization's user database, further source code, and modify the site.
The threat actor claimed to have stolen 7TB of data from the Internet Archive but would not share any samples as proof.
However, now we know that the stolen data also included the API access tokens for Internet Archive's Zendesk support system.
BleepingComputer attempted contact the Internet Archive numerous times, as recently as on Friday, offering to share what we knew about how the breach occurred and why it was done, but we never received a response.

Breached for cyber street cred​

After the Internet Archive was breached, conspiracy theories abounded about why they were attacked.
Some said Israel did it, the United States government, or corporations in their ongoing battle with the Internet Archive over copyright infringement.
However, the Internet Archive was not breached for political or monetary reasons but simply because the threat actor could.
There is a large community of people who traffic in stolen data, whether they do it for money by extorting the victim, selling it to other threat actors, or simply because they are collectors of data breaches.
This data is often released for free to gain cyber street cred, increasing their reputation among other threat actors in this community, as they all compete for who has the most significant and most publicized attacks.
In the case of the Internet Archive, there was no money to be made by trying to extort the organization. However, as a well-known and extremely popular website, it definitely boosted a person's reputation amongst this community.
While no one has publicly claimed this breach, BleepingComputer was told it was done while the threat actor was in a group chat with others, with many receiving some of the stolen data.
This database is now likely being traded amongst other people in the data breach community, and we will likely see it leaked for free in the future on hacking forums like Breached.
Update 10/20/24: Added information about how some people had to upload personal IDs when requesting removal from Internet Archive.
 
This just feels like such a shitty thing to do. Why would you target IA except to be a dick? Target a fucking porn company or someone.
Because Muslims are retarded and the Jihadis attacking IA think that the Wayback Machine is owned by the U.S. government, that and because they have no balls to attack real U.S. infrastructure. A soft target that's kind-of-sort-of adjacent-ish to the government but not really.
how fucking cucked was their security for them not to realize that leaving another attack vector unchanged? Did the security team consist of trannies that acked themselves when the first breach happened and all they could do was hire contractors?
My guess is they stopped developing IA after it became operation and they've been coasting on existing infrastructure ever since.
 
This just feels like such a shitty thing to do. Why would you target IA except to be a dick? Target a fucking porn company or someone.
Because sometimes the only way to get an organization to improve it's security practices is through teaching them the hard way. I'm sure the IT team at the IA have been aware of these flaws for years and thought no one would ever find out. Putting off important work is never a good thing. If a hard lesson is needed then so be it.
 
Maybe should have put more resources on actual storage, security and management instead of a shitty online book lending whose only purposed was giving copyright kikes a opening to sue and absolutely pants on head retarded marketing about how EEEEEVIL CONSERVATIVES were gonna make the physical existence of books literally illegal while at the same time painting monopoly busting Google as bad. (Fun fact: this little stunt, done at the start of 2020, has actually been stealth edited and seems to not exist in it's original form anymore. Mentions of the "Monopoly busting" have been removed but still show up if you try and look up what google sites look like in 2046.)
 
I guess giving into the trannies demand to remove KF didn't work out for them after all.
That and add then it happened close to the American elections but it's only a coincidence or "cohencidence".
Did the security team consist of trannies that acked themselves when the first breach happened and all they could do was hire contractors?
I think it could also be some "DIEversity" hires as well.
 
This just feels like such a shitty thing to do. Why would you target IA except to be a dick? Target a fucking porn company or someone.
Please stop giving them the benefit of the doubt when the org has been nothing but self destructive. The lawsuit against them was an obvious loss and they fought it out to the end then appealed it for literally no reason. The org has most likely been pozzed and they're trying to kill it from the inside.
 
(Fun fact: this little stunt, done at the start of 2020, has actually been stealth edited and seems to not exist in it's original form anymore. Mentions of the "Monopoly busting" have been removed but still show up if you try and look up what google sites look like in 2046.)
Was it saved on archive.today?
 
Because Muslims are retarded and the Jihadis attacking IA think that the Wayback Machine is owned by the U.S. government, that and because they have no balls to attack real U.S. infrastructure. A soft target that's kind-of-sort-of adjacent-ish to the government but not really.
I saw mention that a "pro-Palestine group" was behind the attack and that left me scratching my head. Was wondering what the connection was there.
 
  • Like
Reactions: AWizard
This is a co-ordinated attack on archive sites by major players. Just like that time KF was under constant, crippling DDoS because they laughed at some skanky-ho daughter of a glowie.

These aren't little hackers doing it. Internet archive and its ilk are enemy of the state. It's the board with the Animal Farm doctrines on and it needs wiping clean before we're told "old ways good, new ways better".
 
I saw mention that a "pro-Palestine group" was behind the attack and that left me scratching my head. Was wondering what the connection was there.
I halfway believe that the pro-Palestine part is just some stupid cover for the real motive but I can't surmise a better one. It's so retarded it must be true.
 
Was it saved on archive.today?

No idea, let me check.

Nope. The oldest one still around is from September 2021, when the was for the 25th anniversary which means it had to have been started at around May 2021. Many of the retarded things already been removed by them like the 2029 Monopoly Commission that killed Google but for some reason allowed the Global News Network monopoly to stay around, this this version of the webpage they still claim it is a "Conservative News Monopoly". which is formed in 2023 unlike later on when they remove the explicit political leaning.

Other bangers include:

- "MUH MONEY FOR EDUCATION!!!!!!" schools wont be able to afford books and will need to use provided digital books
- "US withdrawls from all climate agreements" which for some reason relates to the Internet Archive?
- The last physical copy of 1984 destroyed in a fire in 2043, lmao
- Some faggot spams people with a pdf of 1984 in 2044 and is sentenced to life in prison over it
- The IA FOR SOME REASON waits until 2046 to organize their resistance to this shit

Honestly for as amazing of a service as they provide shit like this is why I laugh at them. These fuckers started operation in 1996, and seem to be ideologically and mentally stuck back then still.
 
I wrote it already in the other thread, but IA always was ran by retards in most retarded way and (((Jason Scott))) was right for giving them shit for their unreliable, closed-source structure that can't be easily backed up by dedicated archivist team. IA will blame everyone else but themselves on shit they get after making some truly retarded decisions, like coof library which brought the lawsuits from big publishers. Which most was used to fearmonger for gibs. They literally told people that them getting shit for breaching rules of CDL scheme, removing all limits and providing easy acess to PDFs that any retard could download, is literally OPPRESSION of librarians who literally RESIST evil capitalists. Getting HQ jpgs of books from IA requires some computer literacy, setting up cygwin and using command line is too much for majority of IA's biggest defenders. IA had enough audacity to literally pull a stint that them losing this lawsuit will make greedy publishers literally shut down all libraries.

They never did shit to make site more usable. Search was getting extremely unstable on my end since late August when they got even more gibs after their appeal was rejected. Even setting filters is a nightmare because it fucking reloads page every single time if you set another one.

Edit: typo
 
Last edited:
I halfway believe that the pro-Palestine part is just some stupid cover for the real motive but I can't surmise a better one. It's so retarded it must be true.
The hilarious bit is actually in this article:
While both attacks occurred over the same period, they were conducted by different threat actors. However, many outlets incorrectly reported that SN_BlackMeta was behind the breach rather than just the DDoS attacks.
...
This misreporting frustrated the threat actor behind the actual data breach, who contacted BleepingComputer through an intermediary to claim credit for the attack and explain how they breached the Internet Archive.
it was 2 separate people, the Palestinians just did the DDOS and called it a day. :story:
 
They forced people to do this, but when a power tripping troon wanted KF's archives taken down, they're gone. Lmao. I wonder in what cases they actually required the IDs of people for removal?
I had a friend who for personal reasons needed to take off her blog off wayback. She had to put her legal name on her site and email she used to message IA, with screenshot of mails excachanged with support on her blog to have them comply with her request but it was ages ago.
 
The hilarious bit is actually in this article:

it was 2 separate people, the Palestinians just did the DDOS and called it a day. :story:
Isn't it weird how hackers always want credit for the crimes they do? One would think they'd be happy that a retarded scapegoat is just willing to paint a target on their own back and draw attention away from themselves.
 
This just feels like such a shitty thing to do. Why would you target IA except to be a dick? Target a fucking porn company or someone.
If it's not a legitimate hostile actor (a government or corporate party that wants it gone), and it really is just some random asshole sowing chaos, the IA is a much juicier target than Bob's Internet Forum With Four Users™.
 
This is some clown shoes shit. Get your act together (((Brewster Kahle))). I have no idea if he's really a jew, I just have a hunch.
If this was such a rinky-dink Mickey Mouse operation, I wonder why they didn't try to ask for donations, Wiki style.
They do. Have you never been to the site near the end of the year?
 
Back