16 April 2009

Marblecake

Those wacky kids on 4chan were at it again. Their target this month? The Time.com poll of the 100 most influential people in the world. Their goal had originally been to put 4chan creator Moot at the top, but after that proved to be too easy they aspired to a higher purpose and gamed the results to spell a "secret message" with the first letters of the names in the list. Eschewing the mundane (e.g. spelling out "eat me" or some such), they went with the more cryptic "marblecake, also the game". Take that, NSA.

I'd first seen the result from a post on Reddit and, honestly, almost didn't believe that they could do it. But after reading Music Machinery's interview with one of the perpetrators [ also via Reddit ], I can't believe what web dev dorks the people at Time.com are. If the interview is to be believed, their poll accepted any and any number of GETs to add a vote. ?!? While the rest of us are puzzling over XSS vulnerabilities, Time breaks the first rule of GET. The rest of the interview (with Zombocom, referencing the always-entertaining http://www.zombo.com/) revealed the details of how they wrote tools to attack each part of the problem. One script busily kept names beginning with unwanted letters out of the top; another sorted the remaining names to spell the message. Although the interviewer grossly overstated the importance of what was done, the casual manner that web skills are applied by this community is interesting. Kids used to work on car engines.

So, what next for 4chan? Well over the past few days they've been working to put both Ashton Kutcher and CNN in their place. The two are in a battle to be the first Twitter users with 1,000,000 followers. 4chan has put it's weight behind a certain account called basementdad. Followers (whose IDs consist of a suspicious mangle of the same few names) appear to be increasing at a few hundred every 15 minutes or so.

[ updated 28 Apr 2009 ]

Music Machinery posted an update [ via Reddit ] on how Anonymous beat the last-minute addtion of CAPTCHA and finished with a win. Bravo.

[ posted by sstrader on 16 April 2009 at 8:26:45 AM in Internet | tagged anonymous ]