Mashable 04月28日 15:34
4chan is back up, but not all features are returning
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

知名图片论坛4chan在经历两周的宕机后已基本恢复,但并非所有版块都会回归。官方博客证实,此次宕机源于黑客攻击,导致源代码泄露。黑客利用过时软件的PDF上传漏洞入侵服务器,窃取大量源代码并破坏网站。由于资金和人手不足,4chan未能及时更新代码,导致此次“灾难性”事件。目前,4chan已更换受损服务器并更新软件,但Flash版块/f/因安全风险永久关闭。尽管如此,4chan的运营已基本恢复正常。

🔒4chan因黑客攻击导致宕机两周,起因是黑客利用英国IP地址,通过PDF上传漏洞入侵服务器,窃取了大量源代码,并破坏了网站,最终导致网站关闭。

🛠️4chan团队承认,由于缺乏足够的资金和技术人员,未能及时更新过时的操作系统和代码,是导致此次攻击事件的主要原因。尽管去年下半年已部分迁移到新服务器,但关键功能仍依赖旧硬件。

🚫Flash版块/f/已被永久关闭,原因是使用.swf文件存在无法避免的漏洞风险。Adobe早在2017年就宣布停止支持Flash Player,并在2020年正式停止服务。

4chan is finally back up and running — mostly. The infamous imageboard initially went down two weeks ago, scattering its anonymous denizens to the winds. It has now been largely restored, with users flocking back to their familiar fetid stomping grounds. However, not all of 4chan's boards will be returning.

In the first substantial post to its official blog in eight years, 4chan's team confirmed speculation that the outage was due to a hacker, and that the source code had been compromised. Specifically, the blog stated that a hacker with a UK IP address was able to access 4chan's servers by exploiting its outdated software via a PDF upload. The hacker subsequently extracted a substantial amount of 4chan's source code, before vandalising the website and prompting moderators to shut it down.

"While not all of our servers were breached, the most important one was, and it was due to simply not updating old operating systems and code in a timely fashion," read 4chan's blog on Friday.

Calling the damage "catastrophic," the blog stated that 4chan's failure to update its code was due to both an "insufficient skilled man-hours available" and a lack of funds. Unsurprisingly, it seems that advertisers are leery of associating with a website commonly described as "the cesspool of the internet," which has made acquiring the cash for new servers difficult. As such, while 4chan partially moved to new servers in the second half of last year, key functions were still being taken care of by its old hardware.

"Everything about this process took much longer than intended, which is a recurring theme in this debacle," wrote 4chan. "The free time that 4chan’s development team had available to dedicate to 4chan was insufficient to update our software and infrastructure fast enough, and our luck ran out."

4chan's two-week outage gave its development team time to patch up holes in its security, as well as start bringing on more volunteers. The blog states that 4chan's team has since replaced the compromised server, as well as updated its software. The server status checker on 4chan's blog indicated that full functionality has still not returned at time of writing, though posts on the imageboard largely appeared to be business as usual.

Yet despite this, 4chan won't ever return to its former incarnation. The ability to upload PDFs is expected to return soon, having been temporarily disabled in light of this breach. However, Flash board /f/ has been killed for good since "there is no realistic way to prevent similar exploits using .swf files." While /f/ is currently still available on 4chan's front page and navigation bar, it seems likely it will eventually be removed in light of this announcement.

Even without the hack, the death of /f/ was a long time coming. Adobe first announced it would stop supporting Flash Player back in 2017, finally declaring that it had reached the end of its life in 2020.

4chan has a controversial history and reputation, to put it lightly. Launched over two decades ago in 2003, the dubious internet stalwart became a breeding ground for memes, controversies, and movements such as hacktivist group Anonymous and far-right conspiracy theory QAnon.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

4chan 黑客攻击 安全漏洞 Flash 图片论坛
相关文章