/8leaks/ - 8chan leaks

Treat your users better next time

Posting mode: Reply

Check to confirm you're not a robot
Name
Email
Subject
Comment
Password
Drawing x size canvas
File(s)

Board Rules

Max file size: 350.00 MB

Max files: 5

Max message length: 4096

Manage Board | Moderate Thread

Return | Magrathea | Catalog | Bottom

Expand All Images


Defender 04/04/2017 (Tue) 11:18:56 [Preview] No. 18
Around October last year when it was believed that Assange was missing there were several posts that were deleted in the Assange threads.

Some people alleged that these were the keys.

Can you see anything in your database on this?


Defender 04/04/2017 (Tue) 20:26:10 [Preview] No. 36 del


Defender 04/04/2017 (Tue) 22:51:31 [Preview] No. 39 del
He probably doesn't have the database.


Defender 04/04/2017 (Tue) 23:03:01 [Preview] No. 40 del
>>39
the 8ch database was posted in >>>/operate/

8archive's data is all public


Defender 04/05/2017 (Wed) 01:56:44 [Preview] No. 47 del
If they had the database they would need to know the post numbers to check if there were any matches in the modlogs tables.


Defender 04/05/2017 (Wed) 20:42:36 [Preview] No. 69 del
>>40
That's just the source code.


Defender 04/05/2017 (Wed) 20:43:47 [Preview] No. 70 del
>>40
Check for yourself. >>>/operate/6019 is merely the .zip repack of 8chan.7z (>>1).

Until I see a plausible .sql dump or /var/lib/mysql backup I won't believe the database was compromised. Although it's suspicious inc/config.php has empty MySQL credentials…


Defender 04/05/2017 (Wed) 21:06:45 [Preview] No. 71 del
>>70
>Although it's suspicious inc/config.php has empty MySQL credentials…
How is that suspicious?
The credentials are in inc/secrets.php because otherwise they would be tracked and included in the open source repository.

As far as I know the inc/config.php shouldn't even be modified.
If the admin wants to change something in the $config variable, it should either be defined on inc/instance-config.php or inc/secrets.php.


Defender 04/05/2017 (Wed) 21:23:31 [Preview] No. 75 del
>>71
I see. I'm only used to simple web forum software which only has a central config file for all the crucial settings.

This means the attacker had all the relevant pieces of information to connect to the MySQL database. As it's external to the web server (and hopefully protected by firewalls and MySQL ACLs), it all depends on whether that access was writable as well, because that means you could have dropped in a small PHP dumper script that exports the whole database, for example.


Defender 04/05/2017 (Wed) 21:42:53 [Preview] No. 81 del
>>75
He wouldn't need a script.
mysqldump was likely available in the server which would have exported the whole database to a file.

The question is whether it would be worth doing that since 99% of the information in the dump would already been public anyway.


Defender 04/06/2017 (Thu) 00:11:56 [Preview] No. 92 del
>>81
Depending on the vulnerability and whether PHP-FPM runs in safe mode (we don't have the php.ini), you could run it directly or do it yourself. The bottom line is, it's quite possible there's at least a partial copy of the database.

Of course, the majority of the database is public, but it contains quite sensible information too. For example, the IP obfuscation is only in the frontend, they're stored in cleartext in the modlogs and posts_* tables.


Defender 04/14/2017 (Fri) 23:58:23 [Preview] No. 426 del
I have this. There was some talk about the keys being hidden in the bitcoin blockchain and people were looking through it with some python tools.


Defender 04/15/2017 (Sat) 00:03:34 [Preview] No. 427 del
The topic was discussed here, but it's gone: https://lainchan.org/sec/res/3101.html
http://archive.is/ZEpLY
IIRC the thread was much longer.
https://archive.is/jFIRA
There are some posts on the topic on reddit: https:// www.reddit.com/r/WhereIsAssange/search?q=insurance+keys&restrict_sr=on


Defender 04/15/2017 (Sat) 00:13:43 [Preview] No. 428 del
/pol/ logs have always been public.

Why didn't people check those to see who deleted the posts you're talking about?


Defender 04/15/2017 (Sat) 00:14:51 [Preview] No. 429 del
https://archive.is/pMEmC
Not sure which /pol/ he's talking about but it might be what you're looking for.

Key Dump
eta numeris 392D8A3EEA2527D6AD8B1EBBAB6AD
sin topper D6C4C5CC97F9CB8849D9914E516F9
project runway 847D8D6EA4EDD8583D4A7DC3DEEAE
7FG final request 831CF9C1C534ECDAE63E2C8783EB9
fall of cassandra 2B6DAE482AEDE5BAC99B7D47ABDB3


Defender 04/15/2017 (Sat) 00:27:29 [Preview] No. 430 del
>>428
The topic was very fringe even for most tinfoilhats, most ppl thought it was just some LARPers. Threads kept getting deleted so people went to small sites like lainchan.
It was said that if you posted the real keys you'd get XKeyscored aka your internet would be shut down and the people who claimed to have found keys in the blockchain were reluctant to post. One user claimed to have extracted a file but refused to give evidence.

Found some old threads that were not deleted however:
>>>/pol/res/34716.html
https://archive.4plebs.org/pol/thread/99307017/


Defender 04/15/2017 (Sat) 00:27:55 [Preview] No. 431 del


Defender 04/15/2017 (Sat) 00:34:02 [Preview] No. 433 del
>>431
Man I'm such a newfag. To top it off, have another reddit link:
https: //www.reddit.com/r/Bitcoin/comments/5dqufl/blockchain_experts_the_world_needs_your_help_the/



Top | Catalog | Post a reply | Magrathea | Return