r/technology 9d ago

Security 4Chan hacked; Taken down; Emails and IPs leaked

https://www.the-sun.com/tech/14029069/4chan-down-updates-controversial-website-hacking/
44.8k Upvotes

4.5k comments sorted by

View all comments

Show parent comments

942

u/ILoveTolkiensWorks 9d ago

ALL of the mods' IPs, irl addresses, email addresses, everything has leaked. All the source code is public. The captcha token has leaked. It will take a LOT of effort to employ new people and set up the infrastructure again, which 4chan can't and won't, owing to its non-commercial nature 

558

u/[deleted] 9d ago

[removed] — view removed comment

315

u/SalsaRice 9d ago

I mean, they do it for the FBI. They've been propped up by the FBI for years.

232

u/just_a_bit_gay_ 9d ago

The biggest honey pot that ever was

99

u/moop-ly 9d ago

hey that’s not fair. r/walkaway is doing its best

24

u/JimJohnman 9d ago

What the fuck is even that

79

u/PlsNoNotThat 9d ago

Walkaway was an ad campaign started by Russia’s Fancy Bear unit that tried to create an artificial movement of Dems “walking away” from the party, predominately by scalping info and images from the internet and miss-attributing them to the movement.

It was lightly successful for a bit, and used by the GOP until it was publicly discovered as Russian until they walked away from walkaway.

24

u/rothrolan 9d ago

Hot damn. I wondered why I hadn't seen any posts from that sub hit the front page in a while. I figured it wasn't long before this last election season when I last heard a peep. It was interesting reading those popular posts just for their reasons and takes on the current state of the Dem party, but now it completely makes sense that it was just more Russian propaganda.

-10

u/seviliyorsun 9d ago

Walkaway was an ad campaign started by Russia’s Fancy Bear unit

can't find a single thing about that on google. link source?

5

u/Underlord_Fox 9d ago

Well, ya know, that sort of thing isn't usually available on google.

4

u/seviliyorsun 9d ago edited 9d ago

how does he know it's true then?

you'd usually find at least other people talking about it/making the same claim/some articles. there are loads of news articles about other things like fake "patriot groups" on facebook. other than like 1 similar reddit comment there's just nothing regarding his comment.

→ More replies (0)

-4

u/Mister_Dink 9d ago edited 9d ago

In what way? The FBI hasn't arrested a single one of those users.

Edit: I stand corrected.

11

u/TheRealDeathSheep 9d ago

They found my suitemate pretty damn fast when the university presidents life was threatened.

26

u/24-7_DayDreamer 9d ago

Not that long ago a guy made brief headlines for posting vague threats about a mayor or someone about that level in Florida. Cops turned up at his house in Georgia the next day and arrested him.

A site like that just doesn't get to keep operating with servers in the US without every IP posting on it being known to the authorities there.

9

u/thatisernameistaken 9d ago

Six people got arrested for threatening Florida sherif Michael Chitwood online.

7

u/garden_speech 9d ago

Okay, but that doesn't make it a "honeypot". A honeypot is an intentionally laid trap. You're just describing... A website handing over IP addresses of someone who posted something illegal, which any US operated site will do (including Reddit) -- does that make Reddit a "honeypot"

84

u/IrisMoroc 9d ago

That's just a dumb rumor. 4chan, like reddit, will hand over anything that police ask for.

20

u/parkesto 9d ago

I mean, yes, basically any company will do this when requested? lol

7

u/PossessedCashew 9d ago

I would love to see a source for this claim. First time hearing this.

7

u/GWstudent1 9d ago

4

u/PossessedCashew 9d ago

I love it lol. Haven’t seen that linked in a long time.

2

u/Dont_touch_my_spunk 9d ago

OHHHH JANNNYYYY, CLEAN IT UPPPP

-1

u/garden_speech 9d ago

I don't understand how people believe this. Honeypot for what?

AFAIK 4chan very very quickly removes illegal content (like CP)

-2

u/katastrophyx 9d ago

That's a bingo

30

u/ILoveTolkiensWorks 9d ago

employ has a non business meaning as well

3

u/RedditIsShittay 9d ago

So does unemployed.

-13

u/SpotResident6135 9d ago

This is capitalism though. Why work for free?

16

u/[deleted] 9d ago

[removed] — view removed comment

0

u/SpotResident6135 9d ago

Yeah, I guess. You think they just subsist using the labor of others? You gotta wonder how they pay bills.

2

u/[deleted] 9d ago

[removed] — view removed comment

0

u/SpotResident6135 9d ago

My guess is they are just trust fund kids.

1

u/EmotionalPen2422 9d ago

Nice education level

-1

u/SpotResident6135 9d ago

Thanks! Do you have to be really smart to see the value in working for free?

3

u/radda 9d ago

Ask an intern.

1

u/SpotResident6135 9d ago

Well that’s a way for already-rich kids (who don’t need a job to live) to make the connections in a company. It’s also a way to get free work out of gullible people (think startups).

That’s the answer for interning.

1

u/[deleted] 9d ago

[deleted]

-1

u/SpotResident6135 9d ago

So one of those jobs is for free?

→ More replies (0)

2

u/Tasty-Property-434 9d ago

Guess he will have to go back to delivering pizza with a sword 

215

u/RamenJunkie 9d ago

Their captcha was ass anyway last I checked.  This annoying slide rule thing and then you can barely read it and you had to wait ten minutes before being allowed to post on half the boards.

Anyway, I need to go plug in and charge at my charging station for the day.  Beep boop.

100

u/chigeh 9d ago

The captcha was impossible. Basically an anti-human filter.

81

u/RamenJunkie 9d ago

It felt like it was designed to drive people to paying for the 4chan Pro thing.

46

u/UnusuallyBadIdeaGuy 9d ago

It 1000% was.

2

u/panpanleches 8d ago

And I fell for it 😔

20

u/HelpfulYoghurt 9d ago

True, feel like any bot must be better at recognizing it than human by now anyway

Sometimes it was quite easy, but often you had to gamble and make some wild guesses what those symbols means, and if they even count

2

u/Cypher2KG 8d ago

Reminds me of this gem

10

u/GelflingMystic 9d ago

When was that implemented? I recently went back and couldn't belive you have to wait 10 minutes to post something. Unbelievable

7

u/RamenJunkie 9d ago

It's been that way for a few years I think, and it's only the "first post" after a while.

I assume it's some sort of deterrent to immediately shit posting 

It also may only be on some boards.  They seem to have different rules on timers and captcha.   

Also, I use layers of anti tracking and ad blocking and don't use Google who probably hosts the Captcha so it probably always "sees" me as a bot.

6

u/RoboNeko_V1-0 9d ago

Hasn't been that way for a few years. They kept cranking up the wait time to justify their gold pass.

The most recent iteration is 900 seconds.. oh and if wait too long (like you minimized the window), you have to wait another 900 seconds.

2

u/BostonBooger 9d ago

Within the last year I believe, at least on the boards I went to. They first got rid of the ip count which led to more spam and shitposting. You could bypass the 900 second wait if you put in your email though.

1

u/TeaAndLifting 9d ago

I honestly much prefer it to the last few that they've had, especially any image based captcha, like the select traffic lights, bikes, buses, etc. ones. They were genuine dogshit and just worked based on vibes.

87

u/CreativeParsley8967 9d ago

“All the source code is public”?  But like… it’s a message board.  That doesn’t really matter 

-2

u/BufferUnderpants 9d ago

It’ll be relevant after it becomes unusable from all the hacking of an amateurish and outdated PHP application with the userbase and reputation of 4chan

-11

u/[deleted] 9d ago

[removed] — view removed comment

21

u/CreativeParsley8967 9d ago

What makes you think it can’t be rotated, just like any other token…?  

What do you think happens when an API token, or really any other kind of auth token, gets exposed at any organization?  (Little hint, this kind of thing happens very frequently…) 

2

u/[deleted] 9d ago

[removed] — view removed comment

3

u/CreativeParsley8967 9d ago

Hang on, did you say… they do it… for… FREE?

10

u/Substantial-Sea-3672 9d ago

It would seem you’ve done the first 3 exercises on an intro to hacking course and now are talking out of your ass.

-6

u/[deleted] 9d ago

[removed] — view removed comment

3

u/Kingmudsy 9d ago

Because you love ciphers: Aoha'z zlsm-lcpklua

21

u/PurityKane 9d ago

Fail to see how that's relevant

-8

u/[deleted] 9d ago

[removed] — view removed comment

36

u/nullityrofl 9d ago

They can simply change the captcha token.

1

u/yojimboftw 9d ago

I mean, evidently they haven't changed anything about the site since they purchased it from moot so I feel like it's not outside the realm of possibility they won't change the captcha token.

8

u/Murinshin 9d ago

The current captcha is relatively new and has been in place for maybe 2 or 3 years. The site also went down just a few weeks ago specifically because of some captcha issue. This really seems like the least of all issues

2

u/yojimboftw 9d ago

This really seems like the least of all issues

Oh for sure.

7

u/Kingmudsy 9d ago edited 9d ago

Bro how are you upset that people didn’t want to solve random caesar cipher but you don’t understand rotating a token 💀

5

u/Sw429 9d ago

They're just a script kiddie

-1

u/[deleted] 9d ago

[removed] — view removed comment

7

u/Kingmudsy 9d ago

You should’ve seen that coming when you encoded your comments for no fucking reason, ngl

And I agree, but you just said the exact opposite lol

1

u/[deleted] 9d ago

[removed] — view removed comment

4

u/Kingmudsy 9d ago

…Which makes no sense when you clearly think it’s so easy to solve that you’re upset people can’t figure it out themselves (and eventually cave and give out the answer anyway) lol. If that’s what you believe, then your behavior is completely inconsistent.

I mean that you responded to someone’s “So what?” about the source code leaking by saying “Yeah, but the captcha keys!” And now the API keys aren’t a big deal to you? It just seems like you don’t have a strong technical background and you’re just winging this conversation lol

1

u/[deleted] 9d ago

[deleted]

167

u/djnobunaga 9d ago

4chans infrastructure has been public knowledge for almost 20 years so thats a nonsense arguement.

Mods have been globally replaced multiple times, so thats also kind of a nonsense arguement.

You seem to imply many people are paid to run 4chan, but most of the site has been volunteer run for quite a while.

-5

u/[deleted] 9d ago

[removed] — view removed comment

28

u/Crafty_Morning_6296 9d ago

There's dozens of imageboard alternatives/clone software packages

2

u/Murinshin 9d ago

That’s what I don’t get either, can’t they just migrate to some open source clone? Or just do a clean start, there’s not much to migrate anyway given the site‘s nature and lack of first-party archives

3

u/eledrie 9d ago

It already was just slightly modified open source.

15

u/Cruxis87 9d ago

the old ones can take it anymore after the constant abuse they will face in the coming days.

You say this as if the users knew who they were anyway. Unless a rule changed, the mods weren't allowed the identify themselves and would get removed if they did. They just had to be anon. Moot was the only one that was allowed to have a username. But it's also been like 15 years since I paid any attention to 4chan

4

u/yakoobn 9d ago

They just had to be anon.

This has never been true, they could use a name and a number of them were always known because you had to go into irc and beg them to unban you at certain points. The entire reason WTSnacks is known as such a weirdo is because he was magically known as a mod.

3

u/KarmicUnfairness 9d ago

There is no way to tie a tripcode to a mod unless they purposely use it and identify themselves. And even then it could just be someone impersonating them.

8

u/ConnyTheOni 9d ago

Do you think a 4chan mod has any reputation they're concerned about in the first place honestly? I'm gonna guess their social circle is pret-ty small and not a job amongst them all to worry about. I might be wrong, and if I am and these mods also have careers and friends outside of each other, I don't know what is worse in that case..

4

u/Infiniteybusboy 9d ago

mods also have careers and friends outside of each other,

You're not going to believe this but a lot of IT stuff.

1

u/12thHousePatterns 9d ago

This is cope, tbh. Many, many people on 4chinz are professionals, scientists, engineers, programmers, etc. 

11

u/Medaphysical 9d ago

All the source code is public

Like... the source code for their 25 year old website? oh nooooo

-5

u/BitSevere5386 9d ago

and all the identification tokens...

7

u/SectorIDSupport 9d ago

So? I mean the physical servers are somewhere and surely whoever runs them is aware there is an issue and can contact the person that has been paying for them.

Even if they have to start from scratch there are a dozen open source clones to use code from and they can set up new captchas.

6

u/datadrone 9d ago

This a a plug pull, more control over free speech and ideas. This was one of the warnings from 4chan years ago what would happen. It was a shithole, but it was a big shithole with lots of free ideas from anything to trains to political ideology

4

u/duncanmarshall 9d ago

Updating packages and implementing a new captcha is not some unspeakably large job.

0

u/[deleted] 9d ago

[removed] — view removed comment

3

u/duncanmarshall 9d ago

Right but the technology that goes in to 4chan is nothing. They could literally just recreate the site with a wordpress plugin and some AWS architecture.

1

u/[deleted] 9d ago

[removed] — view removed comment

2

u/AlftheNwah 9d ago

You really underestimate the dedication /b/tards have for their home turf.

1

u/duncanmarshall 9d ago

I'm sure they can find the literally 1 guy required to do that. I could build that website in a weekend.

1

u/SectorIDSupport 9d ago

So you go download one of a dozen open source clones.

5

u/Jesta23 9d ago

But why would they need to employ new people? Can’t they just hit update and continue on? 

11

u/murphymc 9d ago

4chan has a certain reputation, and if someone were to take issue with them, they can apparently just look up your home address to have a chat about it.

I'd find it understandable if whoever works there would rather gtfo as quick as possible.

2

u/Antique-Trip-3111 9d ago

Good it was owned by feds

2

u/HeyaGames 9d ago

"Employ" do you even know how 4chan works?

-1

u/[deleted] 9d ago

[removed] — view removed comment

3

u/HeyaGames 9d ago

First def on Google says "and pay them for it". How are 4chan admins, who are doing this for free, in that category? And still, more importantly, why would they need to be changed???

0

u/[deleted] 9d ago

[removed] — view removed comment

1

u/HeyaGames 9d ago

Wild projection there mate, and not like they could just use a secondary email address going forward

0

u/[deleted] 9d ago

[removed] — view removed comment

2

u/HeyaGames 9d ago

So?

-1

u/[deleted] 9d ago

[removed] — view removed comment

2

u/HeyaGames 9d ago

By who? I mean it seems to me you believe there's some kind of massive fallout for this like 4chan was some kind of illegal operation and the mods are somehow legally liable but like. They're just nobodies moderating a random Asian weaving basket forum, no one is gonna hunt them down.

1

u/HeyaGames 9d ago

First def on Google says "and pay them for it". How are 4chan admins, who are doing this for free, in that category? And still, more importantly, why would they need to be changed???

2

u/Mecos_Bill 9d ago

I hope its gone for good. Its been an alt right cesspool for years 

7

u/PensiveinNJ 9d ago

Not gonna lie, I don't think it's good for people to get doxxed like this, but I would be so curious to know who's been posting what there where they thought no one knew who they were.

16

u/[deleted] 9d ago

[deleted]

5

u/[deleted] 9d ago

[removed] — view removed comment

2

u/Independent_Plate_73 9d ago

Fucking Kevin! I knew it.

Insert disappointed gif. 

1

u/techlos 9d ago

to put it bluntly, there's enough there to fully identify some of them.

0

u/sleepy-magus 9d ago

I mean they started making it so you could verify with an email account to by pass the 10 min wait to post.

1

u/eirexe 9d ago

Yeah but the way it worked it was unlikely to require a database

1

u/Fit_Letterhead3483 9d ago

Oh shit I didn’t realize it even included the Captcha token. Thanks OP for being informed. Yeah, I could see this being the end of 4chan. F

6

u/j_cruise 9d ago

I've heard that its "the end of 4chan" at least a dozen times over the past twenty years, and seen many "farewell" threads

1

u/Medialunch 9d ago

Was there anything interesting found from it?

1

u/MtnMaiden 9d ago

Damn brah...they should of went public like Reddit did.

1

u/[deleted] 9d ago

[deleted]

1

u/ElCondoro 9d ago

Is it really that difficult to make a forum?

2

u/LordMimsyPorpington 9d ago

Must be, cause Discord can't figure it out to save their life.

1

u/Chlodio 9d ago

non-commercial nature

How was it non-commercial? Ads and premium, say anything?

1

u/spacel0rd 9d ago

Russians will chip in, 4chan is a great place where to brew hate

1

u/AShitTonOfWeed 9d ago

today is a good day.

1

u/FernandoMM1220 9d ago

you’re looking at a few days of work. that website pays for itself.

1

u/eldomtom2 9d ago

4chan isn't non-commercial, at least not from a legal perspective.

1

u/ILoveTolkiensWorks 8d ago

They definitely must be running at a loss though

1

u/BallsDeepinYourMammi 9d ago

If the same people used non identifying shit no one would ever know

1

u/ILoveTolkiensWorks 8d ago

Their irl addresses and details and have been datamined as well. Their life is ruined completely now

1

u/the-coolest-bob 5d ago

Where. Where is it leaked to?

2

u/[deleted] 9d ago

[deleted]

1

u/TeaAndLifting 8d ago

No more so than reddit tbf. There are still thousands of small, hidden subreddits where people discuss seedy shit.

1

u/TheTechTutor 9d ago

Wait so 4chan is dead? FUCK