Lutra Security<p>tHe eNd oF A LeGaCy?!?</p><p>Cyber-attacks are not only an existential threat to businesses, they can also hit underground message boards: the infamous website 4chan, known not only for being an endless source of memes, but also for doxxing and coordinating cyber-attacks, spreading hate and conspiracy theories, has itself been hit by hackers.</p><p>The site has been offline since early this morning and internal data, including emails from moderators and the admin and parts of the source code, have been leaked. Many users who used to post anonymously on the message board are now worried about the consequences of their online behaviour.</p><p>The details of the hack are still unknown, but an outdated PHP tech stack seems to be the reason why access to databases, source code etc. is now possible. Reading about outdated PHP and leaked source code, and possibly database takeover, we immediately think of an unpatched RCE vulnerability, but we will probably find out soon.</p><p><a href="https://infosec.exchange/tags/4chan" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>4chan</span></a> <a href="https://infosec.exchange/tags/anonymous" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>anonymous</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>