@dawcas@kaia@georgia the only reason the cow is still extant is because they're farmed by humans. If you stop eating cows, the cow will stop existing entirely. In the interest of reducing suffering you would murder the planet. I say to you, go kill yourself. Now.
@noyoushutthefuckupdad there hasn't been a happening in years, I'm really enjoying it. I was using 4chan in 2024 for the AI art threads too and the jannies had actually just pissed me off not 3 days earlier to the point of exhaustion. It's cathartic
the attacker created a "foo.pdf" file that actually was a Postscript file.
This file contained an exploit that exists in old Ghostscript versions.
4chan is using Ghostscript from 2011.
The malformed PDF file was uploaded to /tg/
Since it was a .pdf file, the upload was accepted and the backend ran an operation to sanitize the file.
This operation involved shelling out to Ghostscript using a the command line, and giving the filename to the malformed PDF file as an argument.
Since Ghostsciript can work with both PDF and Postscript files, and the malformed PDF file had a Postscript MIME header, the command executed successfully and the payload was delivered.
I'm not sure how the final access was obtained but my guess is an ssh key was injected into root's homedir or something. It's BSD 10.1 which has been out of service since 2017 so there are basically infinite ways to escalate privilege from here.
@mint I didn't look closer but someone on kf did bring that up. Generally the event is rather amusing, someone is going to try to fire up a copy of 4chan on a vps later today and try to replicate the pdf file exploit to see if the sharty was blowing smoke
lolicon defenderSysadmin of posting.lolicon.rocks.Oldfag from 4chan day 1.If you post a duck face selfie at me I will choke you out with my penis.(((they))) / (((them)))#SEST, #AyyTeam, #Seele, #Solution6The virgin Mary was 13 when she gave birth to Jesus Christ :sonnenrad: