I hacked it. Im gonna make a 4chan coin and its gonna be launching next week on the site
Parempi Paimen
•
2 pv
>Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell access. https://news.ycombinator.com/item?id=43691334