Imgur Exploited To Channel Botnet Attacks At 4chan
An anonymous reader writes: Imgur has been compromised by attackers looking for an opportunity to direct large volumes of traffic to 4chan. A Reddit thread explains that "when an Imgur image is loaded from /r/4chan [...] imgur loads a bunch of images from 8chan, which causes a DDoS to those sites." Meaning that if a user clicks an Imgur link on /r/4chan, it automatically makes around "500 requests" for one image from imageboard 4chan.org/8chan.
Can we get a cleanup on this summary please, from someone who actually passed high school English class?
The short version: someone served up malicious javascript on 8chan by hosting it on imgur as images, revealing that imgur does not actually check to make sure its images are images. Some Flash on 8chan loads the javascript from the localstorage object, breaking same-origin. Once again the DOM is proven to be a horrible house of cards.
This was patched yesterday.
As I understand it the attack targets 8chan, not 4chan. That's a seperate site.
On a side note, 8chan is a popular target for social "justice" types because it serves as a hub for things they hate, e.g. Gamergate discussions. They're frequently under attack.
> imageboard 4chan.org/8chan
Wut?
Some posted how the code worked on Voat a few days ago, word seemed to spread from there. Mentioned it was an old hack developed by the CIA, something about creating off-screen i-frames. My code-fu is very rusty these days but it seemed to make sense. Can't seem to find the post now, forgot which sub it was.
The first comment explains how this was external to imgur.
Are you a fucking moron? That shit happens all the time. I'll answer my question for you: yes, you are a fucking moron.
Shhhh, let the InfoWars tinfoil hat crowd think there's a big SJW conspiracy for just a little bit longer.
Comment removed based on user account deletion
Are you a fucking moron? That shit happens all the time. I'll answer my question for you: yes, you are a fucking moron.
Martin Shkreli, is that you???
In the free world the media isn't government run; the government is media run.
No, that would be 8chan.
You are welcome on my lawn.
Some posted how the code worked on Voat a few days ago, word seemed to spread from there. Mentioned it was an old hack developed by the CIA, something about creating off-screen i-frames.
Those dastardly devils at the Culinary Institute of America are so cunning, with their JavaScript kung-fu!
Actually I wonder if 4chan is really a botnet under the costume of a image forum.
No, that would be 8chan.
I think you mean that would be Sarah Nyberg or perhaps Dan Olson.
Om, nomnomnom...
-.-
> tfw parent modded down by SJW with mod points.
Getting pretty hard to find places where you can speak uncensored. That seems pretty valuable IMO. Especially when bad actors of major websites are doing what they can to take down a low budget server run by a disabled dude.
>In the United States, as late as the 1880s most States set the minimum age at 10-12, (in Delaware it was 7 in 1895).[8] Inspired by the "Maiden Tribute" female reformers in the US initiated their own campaign[9] which petitioned legislators to raise the legal minimum age to at least 16, with the ultimate goal to raise the age to 18. The campaign was successful, with almost all states raising the minimum age to 16-18 years by 1920.
Feminists should be killed.
Imgur for some reason ran malicious javascript.
The javascript downloaded further obfuscated javascript from several servers, registered behind anonymity in Panama and using hacked cloud instances. One of those was 4cdns.org, imitating 4chan's 4cdn.org.
This inserted code into the localStorage object for 8chan, 8ch.net. 8chan was set up to include localStorage on every page.
The code was one that periodically requested further code from a command and control server. The C&C server was inactive when this was discovered. In the minutes this was tracked down, the "further javascript" was changed on the fly - the person doing this was basically responding to the investigation as it happened.
The end result was that every user of 8chan had a rudimentary back door, which through the localFavorties object requested code to run at every page refresh from a C&C server to be activated at some time in the future.
i lulz'd...once.
Excuse me? This could have had a huge impact on the entire Pepe economy. We're lucky it went by without much happening.
"It seems likely that the malicious Javascript was added by some SJW that works for imgur."
No, this was done by a notorious furfag on 8ch by the name of Bui. The fact that the originating SWF url comes from the /pokepaws/ board is pretty much the dead trigger, since Bui owns that board.
Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
This. It amazes me that so many people attack fullchan.
Pro-censorship folks cannot stand the fact that 8chan has relatively lax moderation while still quickly removing things that are actually illegal.
The feelings of SJWs are not protected by law. The real world isn't a safe space.
Enough said
christ, you neck beards have really gotten cantankerous in your old age.
I assume you mean Semtex. Note that it's not capitalized since it's not an abbreviation.