CURRENT MISSION: Conclude the 2026 soyjak.party hack page, aswell as any pages relating to it, such as the Summer 2026 Crisis page.
Update Quotecord with any relevant info. See the blackboard for more info.
Talk:2026 soyjak.party hack: Difference between revisions
~Chud22783 (talk | contribs) |
No edit summary Tag: tor |
||
| Line 26: | Line 26: | ||
::: README timestamp is 2026-08-11 04:16:39 UTC, then in Moscow time (UTC+3) it was August 11, 2026 at about 7:16 AM, when he wrote it. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:27, 11 August 2026 (UTC) | ::: README timestamp is 2026-08-11 04:16:39 UTC, then in Moscow time (UTC+3) it was August 11, 2026 at about 7:16 AM, when he wrote it. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:27, 11 August 2026 (UTC) | ||
:::: 5 in the morning also discredits the notion that its Quote, unless hes a night owl. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:29, 11 August 2026 (UTC) | :::: 5 in the morning also discredits the notion that its Quote, unless hes a night owl. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:29, 11 August 2026 (UTC) | ||
: There's 58 files that had their filesystem metadata change, '''however their timestamps did not change''' at 22:49 (2 mins before). possibly this Russian checking if he can start his op o algo or a little fuckup. My guess is he got access to the SSH at this point. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 12:33, 11 August 2026 (UTC) | |||
== Compromised == | == Compromised == | ||
Be warned that a huge amount of IPs (a grand total of 59,216) have been all leaked. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:43, 11 August 2026 (UTC) | Be warned that a huge amount of IPs (a grand total of 59,216) have been all leaked. [[User:Rickert|Rickert]] ([[User talk:Rickert|talk]]) 11:43, 11 August 2026 (UTC) | ||
Revision as of 12:33, 11 August 2026
Findings
TL;DR: Server was hacked, guy is legit.
I inspected the leak in a DFIR OS. The leak is genuine. The archive contains a Git working tree whose remote is ssh:/git.soyjak.st/quote/soyjakparty. The local Git identity belongs to Quote. There is also a 72 KB inc/instance-config.php, along with runtime/install material.
Most of the files are timestamped August 5, 2026 at ~22:51 UTC or earlier, consistent with a bulk copy/archive operation. The guy also left behind an untracked README which states:
- "I'm quote and my opsec is garbage, here is the source code of my entire site.
- H*cked by anonymous ~ 2026 08 05"
The README was written on August 11, while everything else examined so far is timestamped August 5 or earlier. Taking it all into account, this is a smoking gun.
Ask me any questions you have below. I don't have the time to write the full article myself as I'll be busy soon. I'll investigate more later. P.S. for some reason, there's minecraft player data in the server. Rickert (talk) 09:38, 11 August 2026 (UTC)
- There's a untracked file named
gzip_bomb.gz. Its a (small) decompression bomb. The file is dated June 27, 2026, so it predates the August hack. Not sure what its doing there. Rickert (talk) 09:57, 11 August 2026 (UTC)- is it actually a bomb? --
Gem (talk) 10:08, 11 August 2026 (UTC) 10:08, 11 August 2026 (UTC)
- if you extract it it'll go from 1mb to 1gb, all zeros. that's why I said it's small. Serious ones go for petabytes to put things into context. Seems to be irrelevant tbh, just surprised its there. Rickert (talk) 10:12, 11 August 2026 (UTC)
- is it actually a bomb? --
- The server was last operational at August 5, at 18:01 UTC. The copywrite happened around ~22:51 UTC as mentioned earlier, meaning the hacker had full access to the server for some quite time. "Around August 5, 18:00 UTC" https://soyjakwiki.org/2026_outage. Rickert (talk) 10:30, 11 August 2026 (UTC)
18:00 1 file 18:01 1 file 22:51 4,004 filesRickert (talk) 10:33, 11 August 2026 (UTC)- this shit just keeps getting wackier geeeeeg i'd say the minecraft player data probably has something to do with soycraft / /craft/ JDS1948 (talk) 10:41, 11 August 2026 (UTC)
- That weird telegram thing has one voice message in it, but upon listening its just some random fan noise. No talking o algo. Rickert (talk) 10:59, 11 August 2026 (UTC)
- Overall, its hard to establish any conclusions, but I can't rule out that it was Quote himself, there's really nothing pointing to a sudden compromise and nuke that explains the shutdown, doe I haven't checked for the alleged ki starting point to see if something originated from there, yet. TL;DR I have yet to encounter any attacker evidence (other than the copy, which doesn't establish anything identity wise). Don't take this and start spreading it everywhere that it was Quote who did it, as I said, there's nothing to prove it, or prove otherwise. 2/10 odds best Rickert (talk) 11:12, 11 August 2026 (UTC)
- There's 58 files that had their filesystem metadata change, however their timestamps did not change at 22:49 (2 mins before). possibly this Russian checking if he can start his op o algo or a little fuckup. My guess is he got access to the SSH at this point. Rickert (talk) 12:33, 11 August 2026 (UTC)
Compromised
Be warned that a huge amount of IPs (a grand total of 59,216) have been all leaked. Rickert (talk) 11:43, 11 August 2026 (UTC)
- yeah that one's kind of to be expected, do you know how extensive it is (how long it gets stored, how many as a percentage of posters)? JDS1948 (talk) 11:45, 11 August 2026 (UTC)
- Whatever is logging it claims its all since 2023. I can't establish what it is for exactly yet. Rickert (talk) 11:47, 11 August 2026 (UTC)
- It might be an external IP dataset rather than a dump of Sharty users. None of the addresses tested across the full leak appear elsewhere except for... wait for it... 67 that overlap the included Tor exit-node lists. A random IP I looked up was a Pakistani residential IP doe. One was a VPN, other four were datacenters. Sixth check is a US vpn, seventh is an Austrian residential... hmm... I'll elaborate more in a bit
Rickert (talk) 11:55, 11 August 2026 (UTC)
- One reported "Services:VPN Server Forum spam source (8) Country:Indonesia" Rickert (talk) 11:58, 11 August 2026 (UTC)
- It might be an external IP dataset rather than a dump of Sharty users. None of the addresses tested across the full leak appear elsewhere except for... wait for it... 67 that overlap the included Tor exit-node lists. A random IP I looked up was a Pakistani residential IP doe. One was a VPN, other four were datacenters. Sixth check is a US vpn, seventh is an Austrian residential... hmm... I'll elaborate more in a bit
- TL;DR its a global list of IPs that mostly return VPN or data center, but there are also residentials mixed in. Make what you will from that. Indian, Pakistani, Brazilian IPs seem to pop up a lot and never report VPN, might have to do with the Brownocaust. Rickert (talk) 12:03, 11 August 2026 (UTC)
- probably a blacklist/greylist of some kind then, maybe the main one or just one list of multiple. could you tell me if there are any israeli ips in there? (or anywhere else in the src) not in a "I NEED TO FIND THE CONNECTION BETWEEN THIS AND DA JOOZ" way it's cuz whenever I connected to the sharty without my proxy/vpn it wouldn't block me from posting + i saw IL on /soy/ and /int/ (which could be vpns) despite a bunch of people saying that israeli ips were blocked from posting which i'm still confused about JDS1948 (talk) 12:21, 11 August 2026 (UTC)
- TL;DR its a global list of IPs that mostly return VPN or data center, but there are also residentials mixed in. Make what you will from that. Indian, Pakistani, Brazilian IPs seem to pop up a lot and never report VPN, might have to do with the Brownocaust. Rickert (talk) 12:03, 11 August 2026 (UTC)
marge
I honestly can't make sense of any of this, soysurgency happens, site goes down with cftunnel 1033 then 503 host for a few days, the sites come back incrementally, there's a disk problem and a fuckton of images but only images are lost, someone hacked it on the 5th the same day it started, when the site goes back up there's a new owner and the site turns into a battlefield with gore running rampant. doesn't seem like anyone knows what the fuck is going on, quote is silent, salt or whoever this nuadmin is isn't saying much. literally no one who'd be in the loop seems to know whats going on/is saying anything. Even this wiki's chain of command and order of things seems to have fallen apart. Well I wouldn't say entirely, but shit's getting done at a slower pace and everything's more dispersed JDS1948 (talk) 11:44, 11 August 2026 (UTC)
- >quote is inactive
- >many jannycords get leaked
- >soysurgencies (protests against admins) happen all around
- >quote becomes even more inactive
- >sharty starts to get ddosed by foodists who were ddosing kiwifarms previously (you'd get a cloudflare check every time you've changed an IP on the shiki and sharty)
- >quote gives up, and sells the sharty to his IRL friend (named by soyteens as salt) for $25000 after meeting in a pub in london
- >while changing the site's ownership, quote fucks up and opens a window for some kiwicaca to hack the sharty
- >quote and salt shut down the soysphere
- >quote and salt were able to get it back, first the booru, then the wiki then the sharty