Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
The Internet Security

4chan Has Been Down Since Monday Night After 'Pretty Comprehensive Own' (arstechnica.com) 22

4chan was reportedly hacked Monday night, with rival imageboard Soyjack Party claiming responsibility and sharing screenshots suggesting deep access to 4chan's databases and admin tools. Ars Technica reports: Security researcher Kevin Beaumont described the hack as "a pretty comprehensive own" that included "SQL databases, source, and shell access." 404Media reports that the site used an outdated version of PHP that could have been used to gain access, including the phpMyAdmin tool, a common attack vector that is frequently patched for security vulnerabilities. Ars staffers pointed to the presence of long-deprecated and removed functions like mysql_real_escape_string in the screenshots as possible signs of an old, unpatched PHP version. In other words, there's a possibility that the hackers have gained pretty deep access to all of 4chan's data, including site source code and user data.

4chan Has Been Down Since Monday Night After 'Pretty Comprehensive Own'

Comments Filter:
  • "own" is more of... they left it to fend for itself.
    • by PPH ( 736903 ) on Tuesday April 15, 2025 @09:40PM (#65309187)

      Nah. They've been working on it actively. Trying to mine users information (it was supposed to be an anonymous board) for marketing purposes. "Either put up with a 15 minute delay to post or verify your e-mail address with us."

      And they had ClownFlare working with them. To make sure everyone had JavaScript turned on. So their scammy banner ads would work.

      • by Anonymous Coward
        The 15 minute delay is if you don't have the cookie that indicates recent activity. They had too much trouble with bot posters that would post for the "first time". The side-effect is if you don't use a particular computer to post for a few days, the cookie expires and you have to go through the 15 minute delay again. And there are other ways to get around the ads. Slashdot made a change to ad blocking a few months ago that's much more annoying than what 4chan does.
    • Why would they stop updating? Seems completely illogical.
    • Nothing of value was lost...
  • Actual Attack Vector (Score:5, Interesting)

    by Hudson9 ( 10106782 ) on Tuesday April 15, 2025 @08:33PM (#65309083)

    "Contrary to popular belief, it was not SQL injection.
    The exploit is such:
    4chan allows uploading PDF to certain boards (/gd/, /po/, /qst/, /sci/, /tg/)
    They neglected to verify that the uploaded file is actually a PDF file. As such, PostScript files, containing PostScript drawing
    commands, can be uploaded.
    Said PostScript file will be passed into Ghostscript to generate a thumbnail image.
    The version of Ghostscript that 4chan uses is from 2012, so it is trivial to exploit.
    From there, we exploit a mistaken suid binary to elevate to the global user."

  • I've never seen such an uplifting post on /.

    Too bad 4Chan went down after their members took over the US government.

  • by spazmonkey ( 920425 ) on Tuesday April 15, 2025 @10:32PM (#65309239)

    Historically, if 4chan had an outage for any length of time, the rest of the internet would suffer what was released upon it.
    Reasonable forums would be overrun with trolling and shitposting.
    No idea if that still holds true, or if 4chan is even still relevant. But it used to do the job of holding in all the excrement and keeping it away from the rest of us.
    I am betting that they still don't just stop posting just because 4chan is down. Reddit mods are probably having a very bad day

  • Not PHP (Score:4, Insightful)

    by Kisai ( 213879 ) on Tuesday April 15, 2025 @10:43PM (#65309261)

    This isn't a PHP issue, this is literately they "fed stuff to ghostscript via php" thus ghostscript ran postscript code inside the webserver process.

    Like on it's face this is a pretty basic, dumb, hack. A properly secured site, regardless of the PHP version would not run "non-php" shell programs. All it would have taken is uploading a PDF file that grabbed a known file (eg index.php) and post it, and then figure out the configuration data from that.

The opulence of the front office door varies inversely with the fundamental solvency of the firm.

Working...