Infosec company pwned by 4chan user
maia.crimew.gay
maia.crimew.gay
If you wanted to download additional repo in the jenkins script sure, but Jenkins Git plugin just accepts credential (whether its password or pub/priv key pair), just paste URL and select one from the list
That said, I doubt that what happened here was a Jenkins configuration problem, and instead something to do with the build scripts they're running on Jenkins. You can't solve every class of stupid, sadly.
But sure enough, jenkins FAR outweighs it: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=jenkins
In case anyone needs reminding, Java developers, on purpose, put a line in a logging library that can fetch and execute code when given a url string for a log statement.
Nobody should be touching anything Java in 2023.
No regrets.
I honestly don't even blame the developers of Log4J that much, because after all its open source, and nobody is paying them to use it despite the idiocy surrounding shit like that.
I do however blame the developers that use Java, see things like this happen, and then continue to use it with Log4j after the patch like nothing ever happened.
I worked for a company a couple years ago that had Jenkins running on a Windows EC2 with a bare public IP, no TLS, and a single set of admin credentials shared by everyone. Also, the host did double duty as some sort of DBA jump box and had every possible credential.
It was like in-defense in depth. I tried to explain how crazy it was. They weren’t interested in fixing it. I moved on.
Some companies just don’t care… soc 2 btw.
Very much does, just because you don't know them doesn't mean they don't.
However, it is not self-authored as can be seen in the history of the article.
Further, the conclusion about Jenkins being the attack vector is drawn without much thought or explanation, and it is also interesting that they've used the same attack vector elsewhere.
I follow her on Tumblr and I assure you this is not the case. She's very ebullient and loves answering questions about her hacking.
Kind of seals it. I admire their brazenness.
(Unironically keep slaybossing, OP)
Costs $20 per year and can be paid with various cryptocurrencies. Since 4chan keeps IP logs, this seems like a good deal for someone leaking company source code.
4chan blocks both Tor and VPNs. It's a terrible place to leak things, but a hacker can most probably find innocuous IPs.
Great episode.
(safe for work)
2. see who clicks it
3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan
Something like that.
It only takes a dozen people having money and fearing court for this to be profitable. The lawyer doesn't want to go to court because that costs money, he just wants you to confess and get paid.
ahahah 4chan is almost as mainstream as Reddit. ahahahahahahaaaaaaa you really think they would waste time like this for IP addresses to "keep track of"
So...yes. Yes I do.
https://www.jta.org/2023/04/27/united-states/a-florida-sheri...
The sheriff's parents' house was swatted. These are the 4chan posts which were included in the various news articles.
https://sports.yahoo.com/4chan-2-men-used-online-170958670.h...
> "It's too bad Mike Chitwood isn’t safe now that I'm planning to kill him. I'm going to shoot Mike Chitwood. I'm going to kill him by shooting him to death."
> "Just shoot Chitwood in the head and he stops being a problem. They have to find a new guy to be the problem. But shooting Chitwood in the head solves an immediate problem permanently. Just shoot Chitwood in the head and murder him."
https://www.clickorlando.com/news/local/2023/04/20/3rd-4chan...
> “I WILL KILL CHITWOOD, MARK MY WORDS.”
https://maia.crimew.gay/posts/how-to-hack-an-airline/
Previously discussed here:
I think you may have perhaps misjudged just how entrenched Jenkins is in corp/enterprise.
This is true for X11 and this is true for the QWERTY layout. The benefit of switching must outweigh the enormous hassle of doing so. It's easy to find something that's a little bit better, but that's simply not good enough to merit a switch.
Often they're around because when it comes around, they do a such a decent job and it's difficult to actually produce something that has that sort of advantage.
QWERTY seems to be too embedded even for that, but I wonder if it gets closer to replacement the higher the percentage of software keyboards climbs vs physical ones.
I'm sympathetic to wanting legacy mindhorrors replaced with modern stuff, but genuine question:
When do you ever have such problems xD
I've multimonitored on X11 for like 4 years and never experienced that.
This wasn't an old-school problem, either, it was three months ago.
There are hundreds of people here for that I'm not in HR, but I guess that's a lot of money spent each year, just to get the same issues we had last year
It takes a lot of money to not improve the situation
Say you were developing inn Angular and Python. Which one of these "alternatives" should I look in to? ie. Which is most requested by typical requiters?
Switching away from Jenkins would cost effort and offer no competitive advantage to your end product, so then why do it?
Near-every other CI also can't just browse which tests failed and with what message without digging directly into logs
- Woodpecker CI: https://woodpecker-ci.org/
- Buildbot: https://buildbot.net/
- GitLab Runners: https://docs.gitlab.com/runner/
- Gitea Actions: https://docs.gitea.io/en-us/usage/actions/overview/
- Forgejo Actions: https://forgejo.org/2023-02-27-forgejo-actions/
- Drone CI: https://www.drone.io/
- CircleCI (not free nor open-source, but self-hosted): https://circleci.com/pricing/server/
- GitHub Runners (same deal as CircleCI): https://docs.github.com/en/actions/hosting-your-own-runners/...
Also those who want to avoid vendor lock in. Git repo might be moved around, do you like changing CI/CD scripts every time you change your git hosting service?
GHA work really well for simple stuff. For more complex in a larger organization there is no clear winner.
- Drone CI: https://www.drone.io/
- Buildbot: https://buildbot.net/
- Gitea Actions: https://docs.gitea.io/en-us/usage/actions/overview/
- Fogejo Actions: https://forgejo.org/2023-02-27-forgejo-actions/
- GitLab Runners: https://gitlab.com/gitlab-org/gitlab-runner
You could also use Ansible playbooks/roles to run your build, although that's going to be a bit more manual: https://www.ansible.com/
Not necessarily endorsing any of the alternatives, just pointing them out.
Jenkins still lives in legacy, and probably will for some time.
Bitbucket is also a big part of this story.
That results in seeing Jenkins all over the ding-darn place at Boeing, LockMart, RC, L3, NGA, etc.
Of course, all that is thrown right out the window if you wire up the Jenkins instance to the goddamn internet.
Over time, there's so much stuff that it does that replacing it is a ton of work. And by work I mean verification and communication. Many developers have no idea how stuff gets built, or how dependencies are managed in the build system. You forget one thing and the build is toast. Hunting this info down takes a ridiculous amount of time.
Now expand that to X number of projects, and you're looking at a year of work...and a delay while QA checks everything again.
For what?
Good luck getting that prioritized.
And when you do now install and most of plugins is out of date and with security bugs...
EDIT: So to be clear, I'm not saying "Jenkins is better than GitLab". I would say GitLab CI is better designed, more robust and stable, but Jenkins is more configurable, extendable and has more features through it's plugin ecosystem. So personally, I wouldn't go back to Jenkins, but I also don't find it ridiculous that people still use it.
It was a bit painful to write the same stuff in GitHub actions. Jira's groovy script made loops, storing variables very easy compared to GitHub actions' YAML.
And that's like the fucking basic feature every CI/CD should have.
Fun times.
Nope, not really. It just takes one mistake and you're pwned. Imagine giving the intern a small project, you're losing your head due to your main project, no time to supervise. Boom.
/e: Or imagine an update in one of your libs/apps. In order to not to be hacked you need to make everything right. In order to hack you just need to find one mistake. Well, kinda, but you know what I mean
wow she seems smart. I hope ko-fi is enough
I'll take that over having to wade through Reddit 12 times out of 10.
In other words, what OP is trying to say is that websites should be designed with the users goals in mind, and IMO it's fair to say that this website wasn't designed that way.
Yes I blocked it with ublock
A little cat chasing my cursor is just plain fun. No malice involved.
There’s a browser setting, "prefers reduced motion" for accessibility reason. And yes, I have that enabled.
the cat following the cursor should now apparently be properly disabled with the reduced motion acessibility setting
Now I want to go demake mine.
The constant revitalization of the parody through new works ensures that the future will also include some mention. I think 90s aesthetic/internet-culture is a bit like that -- the projects that include those themes beget new similar projects in the future as long as they have some level of audience exposure.
Add me if you have a SpaceHey account! https://spacehey.com/josh
Agree. I read recently that digital cameras have been taking off among younger people in the way vinyl took off among millennials. I'm excited to see how people that grew up with excessive, toxic social media manage to find better solutions for dealing with the internet
Kind of funny how we carry these different meanings to mostly meaningless things.
https://github.com/thinkitdata/GOBBLES/blob/master/advisorie...
Specifically about this style though, I feel it fits right into the blog series about "domestic cozy"[1]. It aims to be exactly that, imply super casual/low effort tone, make it feel a bit more personal, and simultaneously about ignoring social traditions that feel redundant to them. Like all trends, it takes effort to follow, and part of this is encouraging friends to turn off auto-capitalization on your phone.
So I would say it's a bit more than just trying to make something hard to read, and focusing on that bit might make you miss the rest of their storytelling process!
Gah.. it's all embarrassing to look back on for other reasons...
The second form is different cases, “he/him”. I have theory that people started using that because they didn’t want to put just “he”. They were following the multiple case form and it stuck. People aren’t really specifying cases because nobody uses different cases and nobody puts cases in the multiple pronouns form.
Sadly archive.org doesn't have a copy from its live state—however I saved the home page at the time (MHTML ftw) and here's a video capture of it*: https://streamable.com/zon5wy
* Expires in one day
Edit: for context Lulzsec were a hacking group a decade back responsible for various headline-making leaks and website hacks.
They're using "owned" in leet speak sense, infiltrated security.
For me owned was as in "CIA owned Crypto AG" not "netrunner owned the Chrome"
not that Chrome
I too thought it would be about a company who was a sole proprietor of an infosec corp lol
Edit: oops, I meant s/ow/pw/.