quinn | they/them | queer | heavy reblogger | gay space ladies | reblogging is strongly encouraged

pingwen:

TVTropes gets made fun of a lot but it is a little astonishing how consistent that wiki’s voice is. It’s a great wiki to go to if you want to simulate having one specific autistic fifteen-year-old computer nerd infodump to you about any piece of media that exists. To be clear I am saying this as an overwhelmingly positive thing

biggest-gaudiest-patronuses:

heirrogance:

biggest-gaudiest-patronuses:

we need a film where the opening scene features a protagonist coughing up what is very clearly an eggsac. i don’t have a plot synopsis we should just start and go from there

image

i think tumblr fucky wucky’d and made this post twice. the notes on both are unique, and their post time is 1min apart

thanks for letting me know! why are we waterboarding me

malliestop:

ambidisastrous:

theshape0fpunktocome:

mismaxx:

image
image
image
image
image

Clean it up hiro….

Former infosec worker here, my 2 cents on this:

>4chan was running on an EXTREMELY OLD version of php so it was vulnerable as fuck

>hacker found vulnerability back on 2021 and played the long game so they could take down the entire site

>alongside admin info, entire source code leaked

>site used deprecated connections to MySQL server, insecure as shit

>site had a file with whitelisted countries that could post freely while others needed to wait for 900 SECONDS TO GET THE CAPTCHA.

>whole code base needs to be updated in order to get the server running up again, which could take a long long time, and could be deemed not worthy by Hiro, so this may actually be the end of 4chan

Remember kids, update and patch vulnerabilities if you don’t want to get nuked out of the face of the earth by the hacker known as 4chan

News link: https://techcrunch.com/2025/04/15/notorious-image-board-4chan-hacked-and-internal-data-leaked/

I'm going to be clearing some things up about the hack... What was the exploit used? Contrary to popular belief, it was not SQL injection. The exploit is such: 4chan allows uploading PDF to certain boards (/gd/, /po/, /qst/, /scil, /tg/) They neglected to verify that the uploaded file is actually a PDF file. As such, PostScript files, containing PostScript drawing commands, can be uploaded. Said PostScript file will be passed into Ghostscript to generate a thumbnail image. The version of Ghostscript that 4chan uses is from 2012, so it is trivial to exploit. From there, we exploit a mistaken suid binary to elevate to the global user. I am a 4chan Pass user, is my data at risk? NO. I am not interested in leaking user data. I do not possess this information. I verified my email on 4chan, do you now have my email? NO. This is not possible because 4chan hashes user emails. Other stuff. There are no janitors or mods on 4chan with a gov email address. This is a mistruth.ALT