4chan Blog

Still standing

On the afternoon of April 14th, a hacker using a UK IP address exploited an out-of-date software package on one of 4chan’s servers, via a bogus PDF upload. With this entry point, they were eventually able to gain access to one of 4chan’s servers, including database access and access to our own administrative dashboard. The hacker spent several hours exfiltrating database tables and much of 4chan’s source code. When they had finished downloading what they wanted, they began to vandalize 4chan at which point moderators became aware and 4chan’s servers were halted, preventing further access.

Over the following days, 4chan’s development team surveyed the damage, which to be frank, was catastrophic. While not all of our servers were breached, the most important one was, and it was due to simply not updating old operating systems and code in a timely fashion. Ultimately this problem was caused by having insufficient skilled man-hours available to update our code and infrastructure, and being starved of money for years by advertisers, payment providers, and service providers who had succumbed to external pressure campaigns.

We had begun a process of speccing new servers in late 2023. As many have suspected, until that time 4chan had been running on a set of servers purchased second-hand by moot a few weeks before his final Q&A, as prior to then we simply were not in a financial position to consider such a large purchase. Advertisers and payment providers willing to work with 4chan are rare, and are quickly pressured by activists into cancelling their services. Putting together the money for new equipment took nearly a decade.

In April of 2024 we had agreed on specs and began looking for possible suppliers. Money is always tight for us, and few companies were willing to sell us servers, so actually buying the hardware wasn’t a trivial problem. We managed to finalize a purchase in June, and had the new servers racked and online in July. Over the next few months we slowly moved functionality onto the new servers, but we had still been relying on the old servers for key functions. Everything about this process took much longer than intended, which is a recurring theme in this debacle. The free time that 4chan’s development team had available to dedicate to 4chan was insufficient to update our software and infrastructure fast enough, and our luck ran out.

However, we have not been idle during our nearly two weeks of downtime. The server that was breached has been replaced, with the operating system and code updated to the latest versions. PDF uploads have been temporarily disabled on those boards that supported them, but they will be back in the near future. One slow but much beloved board, /f/ - Flash, will not be returning however, as there is no realistic way to prevent similar exploits using .swf files. We are bringing on additional volunteer developers to help keep up with the workload, and our team of volunteer janitors & moderators remains united despite the grievous violations some have suffered to their personal privacy.

4chan is back. No other website can replace it, or this community. No matter how hard it is, we are not giving up.

Notes
  1. yourfirstnamealoud said: @bestbahavior well I guess it will go down forever eventually
  2. lateantiquechud reblogged this from bestbahavior and added:
    most retarded thing ive read all week
  3. bestbahavior said: @bestbahavior *4Chan. All chans need to die off.
  4. bestbahavior said: @yourfirstnamealoud No fucking shit it’s about tumblr going back up. I want it go back down forever. #SupporTheHackers
  5. commandersya reblogged this from cyle
  6. assburgerssyndrome reblogged this from dr-retard
  7. dr-retard reblogged this from fuggmuff
  8. fuggmuff reblogged this from reve-nant
  9. noent said: Stay fucking dead
  10. reve-nant reblogged this from wormist-priest
  11. yandereine said: @yourfirstnamealoud they say it is dangerous to let hate cloud your judgement. That was a whole nebula
  12. wormist-priest said: @bestbahavior Lol owned
  13. wormist-priest reblogged this from 4chan
  14. sweetestapplepie reblogged this from cyle
  15. w-aterfall said: thank you but can you get rid of the stupid ass cooldowns that can only be bypassed by entering your email or paying
  16. fox-bright reblogged this from cyle
  17. analyticrambles reblogged this from cyle
  18. cyle reblogged this from 4chan
  19. seenbyeveryone reblogged this from 4chan
  20. caligulasterrarium reblogged this from 4chan
  21. 4chan posted this
    On the afternoon of April 14th, a hacker using a UK IP address exploited an out-of-date software package on one of...