Imgur has been compromised! Yet another reason to not use Flash

inf1nity

Golden Member
Mar 12, 2013
1,181
3
0
Popular image hosting service imgur, just had their servers compromised. Some images, when loaded from imgur, seem to have a .swf animation embedded in them, which launches a DDoS attack on 8chan.

Basically, anyone who opened up certain images from imgur.com, and happened to have flash enabled had their computers turned into botnets, that were then used to launch DoS attacks on 8chan imageboard servers.

The full extent of this attack is not yet known. A lot of it is going over my head, since I'm not a technically proficient person myself. Here the thread where discussion is happening.

https://www.reddit.com/r/technology...g_used_to_create_a_botnet_and_ddos/?limit=500

Anyways, I sure am glad I listened to fellow Anandtech members and removed flash! :D
 

Elixer

Lifer
May 7, 2002
10,371
762
126
Yesterday a vulnerability was discovered that made it possible to inject malicious code into an image link on Imgur. From our team’s analysis, it appears the exploit was targeted specifically to users of 4chan and 8chan via images shared to a specific sub-reddit on Reddit.com using Imgur’s image hosting and sharing tools. The affected images were not published to the galleries on Imgur.com.

The vulnerability was patched yesterday evening and we’re no longer serving affected images, but as a precaution we recommend that you clear your browsing data, cookies, and localstorage.

As we learn more about the nature of the issue, we’ll update this post. In the meantime, if you have any questions, we’d be happy to address them at support@imgur.com.
http://imgur.com/blog/2015/09/22/imgur-vulnerability-patched/
 

ninaholic37

Golden Member
Apr 13, 2012
1,883
31
91
I usually have flash DISABLED GLOBALLY unless I am using it...
Same here. I think I went to imgur once, and it asked for Flash, and I was too lazy to turn it on or it didn't seem worth it so I just left the site and said "screw it".