CURRENT MISSION: Conclude the 2026 soyjak.party hack page, aswell as any pages relating to it, such as the Summer 2026 Crisis page.
Update Quotecord with any relevant info. See the blackboard for more info.

Talk:2026 soyjak.party hack: Difference between revisions

From Soyjak Wiki, the free ensoyclopedia
Jump to navigationJump to search
Rickert (talk | contribs)
Tag: tor
Rickert (talk | contribs)
Tag: tor
Line 32: Line 32:
:Whatever is logging it claims its all since 2023. I can't establish what it is for exactly yet. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:47, 11 August 2026 (UTC)
:Whatever is logging it claims its all since 2023. I can't establish what it is for exactly yet. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:47, 11 August 2026 (UTC)
:: It might be an external IP dataset rather than a dump of Sharty users. None of the addresses tested across the full leak appear elsewhere except for... wait for it... 67 that overlap the included Tor exit-node lists. A random IP I looked up was a Pakistani residential IP doe. One was a VPN, other four were datacenters. Sixth check is a US vpn, seventh is an Austrian residential... hmm... I'll elaborate more in a bit {{e|neutral}} [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:55, 11 August 2026 (UTC)
:: It might be an external IP dataset rather than a dump of Sharty users. None of the addresses tested across the full leak appear elsewhere except for... wait for it... 67 that overlap the included Tor exit-node lists. A random IP I looked up was a Pakistani residential IP doe. One was a VPN, other four were datacenters. Sixth check is a US vpn, seventh is an Austrian residential... hmm... I'll elaborate more in a bit {{e|neutral}} [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:55, 11 August 2026 (UTC)
:: One reported "Services:VPN Server Forum spam source (8) Country:Indonesia" [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:58, 11 August 2026 (UTC)


== marge ==
== marge ==
I honestly can't make sense of any of this, soysurgency happens, site goes down with cftunnel 1033 then 503 host for a few days, the sites come back incrementally, there's a disk problem and a fuckton of images but only images are lost, someone hacked it on the 5th the same day it started, when the site goes back up there's a new owner and the site turns into a battlefield with gore running rampant.  doesn't seem like anyone knows what the fuck is going on, quote is silent, salt or whoever this nuadmin is isn't saying much. literally no one who'd be in the loop seems to know whats going on/is saying anything. Even this wiki's chain of command and order of things seems to have fallen apart. Well I wouldn't say entirely, but shit's getting done at a slower pace and everything's more dispersed  [[User:JDS1948|JDS1948]] ([[User talk:JDS1948|talk]]) 11:44, 11 August 2026 (UTC)
I honestly can't make sense of any of this, soysurgency happens, site goes down with cftunnel 1033 then 503 host for a few days, the sites come back incrementally, there's a disk problem and a fuckton of images but only images are lost, someone hacked it on the 5th the same day it started, when the site goes back up there's a new owner and the site turns into a battlefield with gore running rampant.  doesn't seem like anyone knows what the fuck is going on, quote is silent, salt or whoever this nuadmin is isn't saying much. literally no one who'd be in the loop seems to know whats going on/is saying anything. Even this wiki's chain of command and order of things seems to have fallen apart. Well I wouldn't say entirely, but shit's getting done at a slower pace and everything's more dispersed  [[User:JDS1948|JDS1948]] ([[User talk:JDS1948|talk]]) 11:44, 11 August 2026 (UTC)

Revision as of 11:58, 11 August 2026

Findings

TL;DR: Server was hacked, guy is legit.

I inspected the leak in a DFIR OS. The leak is genuine. The archive contains a Git working tree whose remote is ssh:/<censored cause I don't want trouble>/quote/soyjakparty. The local Git identity belongs to Quote. There is also a 72 KB inc/instance-config.php, along with runtime/install material.

Most of the files are timestamped August 5, 2026 at ~22:51 UTC or earlier, consistent with a bulk copy/archive operation. The guy also left behind an untracked README which states:

"I'm quote and my opsec is garbage, here is the source code of my entire site.
H*cked by anonymous ~ 2026 08 05"

The README was written on August 11, while everything else examined so far is timestamped August 5 or earlier. Taking it all into account, this is a smoking gun.

Ask me any questions you have below. I don't have the time to write the full article myself as I'll be busy soon. I'll investigate more later. P.S. for some reason, there's minecraft player data in the server. Rickert (talk) 09:38, 11 August 2026 (UTC)

There's a untracked file named gzip_bomb.gz. Its a (small) decompression bomb. The file is dated June 27, 2026, so it predates the August hack. Not sure what its doing there. Rickert (talk) 09:57, 11 August 2026 (UTC)
is it actually a bomb? --Gem Gem (talk) 10:08, 11 August 2026 (UTC) 10:08, 11 August 2026 (UTC)
if you extract it it'll go from 1mb to 1gb, all zeros. that's why I said it's small. Serious ones go for petabytes to put things into context. Seems to be irrelevant tbh, just surprised its there. Rickert (talk) 10:12, 11 August 2026 (UTC)
The server was last operational at August 5, at 18:01 UTC. The copywrite happened around ~22:51 UTC as mentioned earlier, meaning the hacker had full access to the server for some quite time. "Around August 5, 18:00 UTC" https://soyjakwiki.org/2026_outage. Rickert (talk) 10:30, 11 August 2026 (UTC)
18:00 1 file 18:01 1 file 22:51 4,004 files Rickert (talk) 10:33, 11 August 2026 (UTC)
366 22:51:32 722 22:51:33 1892 22:51:34 1024 22:51:35 he got it all in 4 seconds. Rickert (talk) 10:35, 11 August 2026 (UTC)
no way kek --Gem Gem (talk) 10:39, 11 August 2026 (UTC) 10:39, 11 August 2026 (UTC)
this shit just keeps getting wackier geeeeeg i'd say the minecraft player data probably has something to do with soycraft / /craft/ JDS1948 (talk) 10:41, 11 August 2026 (UTC)
That weird telegram thing has one voice message in it, but upon listening its just some random fan noise. No talking o algo. Rickert (talk) 10:59, 11 August 2026 (UTC)
Overall, its hard to establish any conclusions, but I can't rule out that it was Quote himself, there's really nothing pointing to a sudden compromise and nuke that explains the shutdown, doe I haven't checked for the alleged ki starting point to see if something originated from there, yet. TL;DR I have yet to encounter any attacker evidence (other than the copy, which doesn't establish anything identity wise). Don't take this and start spreading it everywhere that it was Quote who did it, as I said, there's nothing to prove it, or prove otherwise. 2/10 odds best Rickert (talk) 11:12, 11 August 2026 (UTC)
The hacker claims to be Russian. --Gem Gem (talk) 11:22, 11 August 2026 (UTC) 11:22, 11 August 2026 (UTC)
README timestamp is 2026-08-11 04:16:39 UTC, then in Moscow time (UTC+3) it was August 11, 2026 at about 7:16 AM, when he wrote it. Rickert (talk) 11:27, 11 August 2026 (UTC)
5 in the morning also discredits the notion that its Quote, unless hes a night owl. Rickert (talk) 11:29, 11 August 2026 (UTC)

Compromised

Be warned that a huge amount of IPs (a grand total of 59,216) have been all leaked. Rickert (talk) 11:43, 11 August 2026 (UTC)

yeah that one's kind of to be expected, do you know how extensive it is (how long it gets stored, how many as a percentage of posters)? JDS1948 (talk) 11:45, 11 August 2026 (UTC)
Whatever is logging it claims its all since 2023. I can't establish what it is for exactly yet. Rickert (talk) 11:47, 11 August 2026 (UTC)
It might be an external IP dataset rather than a dump of Sharty users. None of the addresses tested across the full leak appear elsewhere except for... wait for it... 67 that overlap the included Tor exit-node lists. A random IP I looked up was a Pakistani residential IP doe. One was a VPN, other four were datacenters. Sixth check is a US vpn, seventh is an Austrian residential... hmm... I'll elaborate more in a bit {{e|neutral}} Rickert (talk) 11:55, 11 August 2026 (UTC)
One reported "Services:VPN Server Forum spam source (8) Country:Indonesia" Rickert (talk) 11:58, 11 August 2026 (UTC)

marge

I honestly can't make sense of any of this, soysurgency happens, site goes down with cftunnel 1033 then 503 host for a few days, the sites come back incrementally, there's a disk problem and a fuckton of images but only images are lost, someone hacked it on the 5th the same day it started, when the site goes back up there's a new owner and the site turns into a battlefield with gore running rampant. doesn't seem like anyone knows what the fuck is going on, quote is silent, salt or whoever this nuadmin is isn't saying much. literally no one who'd be in the loop seems to know whats going on/is saying anything. Even this wiki's chain of command and order of things seems to have fallen apart. Well I wouldn't say entirely, but shit's getting done at a slower pace and everything's more dispersed JDS1948 (talk) 11:44, 11 August 2026 (UTC)