Ksvo Contributor Posts: 7 kołdry Joined: Wed Nov 06, 2024 9:30 pm Wikipedia User: OrientalTraveller

Sucks claims to have "hacked" Wikipedia

Unread post by Ksvo » Wed Jul 16, 2025 8:05 am

https://wikipediasucks.co/forum/viewtop ... f=5&t=3520

Bbb23sucks wrote: Recently, I successfully managed to leak hundreds of gigabytes of sensitive information from Wikimedia sites. Including millions of deleted articles, tens of millions of deleted revisions, and (!!!) hundreds of thousands of overnighted revisions.

Given the sheer scale of the data, it's going to take me some time to release it all publicly. So far, I've created a demo for meta.wikimedia.org: https://unoversight.netlify.app/metawiki

In the coming weeks, I plan to release the rest of it. First English Wikipedia, then hopefully the rest of the WMF wikis.



User avatar

C&B Habitué Posts: 2058 Joined: Wed Aug 01, 2018 2:16 pm Location: with cheese.

Re: Sucks claims to have "hacked" Wikipedia

Unread post by C&B » Wed Jul 16, 2025 9:35 am

Ksvo wrote:

Wed Jul 16, 2025 8:05 am

overnighted revisions.

Next day delivery, nice.

"Someone requests clarification and before you know it you find yourself in the Star Chamber."



User avatar

AndyTheGrump Habitué Posts: 4129 Joined: Sat Aug 11, 2012 11:44 pm Wikipedia User: AndyTheGrump (editor/heckler)

Re: Sucks claims to have "hacked" Wikipedia

Unread post by AndyTheGrump » Wed Jul 16, 2025 9:50 am

Given the sort of stuff that gets oversighted, that looks like a good way to get sued. And not by the WMF. By people/corporations etc who you've just recklessly published libel on. Or maybe find yourself having to explain why you are endangering minors to law enforcement.

Assuming it isn't complete bullshit, which it most likely is.


FOARP Contributor Posts: 87 Joined: Mon Aug 01, 2022 9:27 pm Wikipedia User: FOARP

Re: Sucks claims to have "hacked" Wikipedia

Unread post by FOARP » Wed Jul 16, 2025 10:05 am

AndyTheGrump wrote:

Wed Jul 16, 2025 9:50 am

Given the sort of stuff that gets oversighted, that looks like a good way to get sued. And not by the WMF. By people/corporations etc who you've just recklessly published libel on. Or maybe find yourself having to explain why you are endangering minors to law enforcement.

Assuming it isn't complete bullshit, which it most likely is.

Yeah if this is real there's going to be a bunch of libel and CSE in there. The attack-page a weird stalker (guy who I played a small role in exposing as a fake lawyer in my China days and who has stalked me ever since) created about me, under my real name, which got speedied is going to be in there.

Better if it's just BS.

AFAIK oversighter is a special permission and not just something that just any admin has, so if it's been hacked that's a major failure. I'm not a cyber-security guy but I would assume they would have applied the kind of stuff they use to protect databases of passwords to the oversighted edits database? Like, salting the data, that kind of thing? Most likely avenue (if it genuinely has been hacked) would therefore be stolen credentials?

Sucks hosting this is a major fail on their part too.





User avatar

Carcharoth Habitué Posts: 1653 Joined: Sat Jan 10, 2015 1:44 am Wikipedia User: Carcharoth

Re: Sucks claims to have "hacked" Wikipedia

Unread post by Carcharoth » Wed Jul 16, 2025 2:45 pm

Giraffe Stapler wrote:

Wed Jul 16, 2025 2:13 pm

Surprisingly, it seems legit. :popcorn:

If it is legit, I would have expected some sort of activity on Wikipedia about this, or from the WMF. Surely they would have records showing if a large amount of sensitive data was exfiltrated? Or maybe not.




FOARP Contributor Posts: 87 Joined: Mon Aug 01, 2022 9:27 pm Wikipedia User: FOARP

Re: Sucks claims to have "hacked" Wikipedia

Unread post by FOARP » Wed Jul 16, 2025 3:27 pm

Randy from Boise wrote:

Wed Jul 16, 2025 3:11 pm

Giraffe Stapler wrote:

Wed Jul 16, 2025 2:13 pm

Surprisingly, it seems legit. :popcorn:

Dunno, the links on the big table of oversighted content by month were all empty for me.

t

The ones I looked at (March 2021) had content, but not the oversighted/revdel'd content I was aware of from that month (Lugnuts's fake suicidal posting that he pulled to try to derail an AN discussion about him that was headed towards imposing sanctions - it's beyond me that he wasn't indef'd for that BS).

Most of the revdel'd content appeared to be hidden IP numbers, email addresses and so-forth, so yeah, that's not great. Some of it clearly wasn't from EN WP either, but instead from Wikimedia, which suggests possibly this was a database-level breach and not stolen credentials (if, again, this is a legit leak).

It's possible that ARBCOM's internal wiki is in this data somewhere....


User avatar

utbc Critic Posts: 247 Joined: Sun Sep 18, 2022 1:28 am

Re: Sucks claims to have "hacked" Wikipedia

Unread post by utbc » Wed Jul 16, 2025 3:44 pm

FOARP wrote:

Wed Jul 16, 2025 3:27 pm

Randy from Boise wrote:

Wed Jul 16, 2025 3:11 pm

Giraffe Stapler wrote:

Wed Jul 16, 2025 2:13 pm

Surprisingly, it seems legit. :popcorn:

Dunno, the links on the big table of oversighted content by month were all empty for me.

t

The ones I looked at (March 2021) had content, but not the oversighted/revdel'd content I was aware of from that month (Lugnuts's fake suicidal posting that he pulled to try to derail an AN discussion about him that was headed towards imposing sanctions - it's beyond me that he wasn't indef'd for that BS).

Most of the revdel'd content appeared to be hidden IP numbers, email addresses and so-forth, so yeah, that's not great. Some of it clearly wasn't from EN WP either, but instead from Wikimedia, which suggests possibly this was a database-level breach and not stolen credentials (if, again, this is a legit leak).

It's possible that ARBCOM's internal wiki is in this data somewhere....

Guess you missed the original post? It says what's being published is "demo" for meta. Next will be en.wp, and then the rest possibly over weeks.



User avatar

C&B Habitué Posts: 2058 Joined: Wed Aug 01, 2018 2:16 pm Location: with cheese.

Re: Sucks claims to have "hacked" Wikipedia

Unread post by C&B » Wed Jul 16, 2025 4:26 pm

Carcharoth wrote:

Wed Jul 16, 2025 2:45 pm

If it is legit, I would have expected some sort of activity on Wikipedia about this, or from the WMF. Surely they would have records showing if a large amount of sensitive data was exfiltrated?

With their usual alacrity and future proofing?

Carcharoth wrote:

Wed Jul 16, 2025 2:45 pm

Or maybe not.

:B'

"Someone requests clarification and before you know it you find yourself in the Star Chamber."


User avatar

rhindle Habitué Posts: 1688 Joined: Wed Mar 21, 2012 7:44 pm Wikipedia User: Kafkaesque Wikipedia Review Member: rhindle Location: 'Murica

Re: Sucks claims to have "hacked" Wikipedia

Unread post by rhindle » Wed Jul 16, 2025 4:29 pm

I dunno how legit this is, but it can't be ignored. This kind of reminds me of the old Arbcom leaker back in the day. We'll see how it all pans out.



User avatar

ScotFinnRadish Gregarious Posts: 821 Joined: Thu Jan 20, 2022 1:13 pm Wikipedia User: ScottishFinnishRadish Actual Name: Stephen Root Vegetable

User avatar

C&B Habitué Posts: 2058 Joined: Wed Aug 01, 2018 2:16 pm Location: with cheese.

Re: Sucks claims to have "hacked" Wikipedia

Unread post by C&B » Wed Jul 16, 2025 4:46 pm

Cat in the box wrote:

Wed Jul 16, 2025 4:32 pm

I emailed WMF about it. They will probably issue a statement if its legit.

They will do what they always do. As little as possible, and that too late.

"Someone requests clarification and before you know it you find yourself in the Star Chamber."








User avatar

tarantino Denizen Posts: 5875 Joined: Thu Mar 15, 2012 7:19 pm

Re: Sucks claims to have "hacked" Wikipedia

Unread post by tarantino » Wed Jul 16, 2025 7:20 pm

C&B wrote:

Wed Jul 16, 2025 7:05 pm

Is still there for me; unless a cache thing?

Yeah the front page is there, but if I try to search I get a 404 error

Page not found

Looks like you’ve followed a broken link or entered a URL that doesn’t exist on this site.


User avatar

rhindle Habitué Posts: 1688 Joined: Wed Mar 21, 2012 7:44 pm Wikipedia User: Kafkaesque Wikipedia Review Member: rhindle Location: 'Murica

Re: Sucks claims to have "hacked" Wikipedia

Unread post by rhindle » Wed Jul 16, 2025 7:54 pm

tarantino wrote:

Wed Jul 16, 2025 7:20 pm

C&B wrote:

Wed Jul 16, 2025 7:05 pm

Is still there for me; unless a cache thing?

Yeah the front page is there, but if I try to search I get a 404 error

Page not found

Looks like you’ve followed a broken link or entered a URL that doesn’t exist on this site.

I'm getting them. I clicked the link that says "deleted pages" and I get an index and click on the (supposedly) deleted content. I went to revdel and oversighted but got links but the ones I saw were all blank.








User avatar

Randy from Boise Been Around Forever Posts: 14863 Joined: Sun Mar 18, 2012 2:32 am Wikipedia User: Carrite Wikipedia Review Member: Timbo Actual Name: Tim Davenport Nom de plume: T. Chandler Location: Boise, Idaho

Re: Sucks claims to have "hacked" Wikipedia

Unread post by Randy from Boise » Thu Jul 17, 2025 2:17 pm

Meh, Richard Arthur Norton syndrome.

Sourcing and cut-and-paste standards changed over time, leaving early Wikipedians who were free-and-easy with their adherence to copyright with huge icebergs of potential problems with the editing of their first years.

Then CCI — whose methodology totally does not scale for massive contributors — tells the editor to effectively cut down the tallest tree in the forest with a herring, terminating current activity until they revisit everything they ever did 15 or 20 years ago, edit by edit. Most of these edits have subsequently been changed or deleted by others, mind you.

The quality of one's current work doesn't matter a whit to CCI. They want the ancient bad editing fixed. One is "morally required" to clean up the "mess"...

The only possible response of a sane person is "fuck that shit, I'm outta here."

t



User avatar

Randy from Boise Been Around Forever Posts: 14863 Joined: Sun Mar 18, 2012 2:32 am Wikipedia User: Carrite Wikipedia Review Member: Timbo Actual Name: Tim Davenport Nom de plume: T. Chandler Location: Boise, Idaho

Re: Sucks claims to have "hacked" Wikipedia

Unread post by Randy from Boise » Fri Jul 18, 2025 3:11 am

I wish Sucks would close up shop, and have a beer with the current management, and come to WPO with spiffy new names. Except for Eric, who is the OG of Wikipedia critics. He is Eric. Not pleased to meet you.

We need the vinegar.

t


FOARP Contributor Posts: 87 Joined: Mon Aug 01, 2022 9:27 pm Wikipedia User: FOARP

Re: Sucks claims to have "hacked" Wikipedia

Unread post by FOARP » Fri Jul 18, 2025 6:22 am

Randy from Boise wrote:

Thu Jul 17, 2025 2:17 pm

Meh, Richard Arthur Norton syndrome.

Sourcing and cut-and-paste standards changed over time, leaving early Wikipedians who were free-and-easy with their adherence to copyright with huge icebergs of potential problems with the editing of their first years.

Then CCI — whose methodology totally does not scale for massive contributors — tells the editor to effectively cut down the tallest tree in the forest with a herring, terminating current activity until they revisit everything they ever did 15 or 20 years ago, edit by edit. Most of these edits have subsequently been changed or deleted by others, mind you.

The quality of one's current work doesn't matter a whit to CCI. They want the ancient bad editing fixed. One is "morally required" to clean up the "mess"...

The only possible response of a sane person is "fuck that shit, I'm outta here."

t

Which was why straight deleting all Lugnuts unimproved single-source stubs was always the better path. Just cut the damn knot already.


Ognistysztorm Critic Posts: 176 Joined: Mon Oct 24, 2022 5:55 am Actual Name: Ogden (they/them)

Re: Sucks claims to have "hacked" Wikipedia

Unread post by Ognistysztorm » Sun Jul 20, 2025 2:53 pm

Bbb23sucks had been involved in automated email-spam campaigns before.
viewtopic.php?f=8&t=13309

On a personal capacity I do not officially endorse the leak(s) at all due to the obvious illegality and because of the possibility that it will inadvertently backfire by lot, especially by jeopardizing an endgame plan I've privately disclose to Midsize Jake through PMs the other day.





Ognistysztorm Critic Posts: 176 Joined: Mon Oct 24, 2022 5:55 am Actual Name: Ogden (they/them)

Re: Sucks claims to have "hacked" Wikipedia

Unread post by Ognistysztorm » Sun Jul 20, 2025 5:54 pm

Carcharoth wrote:

Sun Jul 20, 2025 4:58 pm

If someone hacked that way, can the article content be compromised? Article history and so on. Or does that require root access?

The possibilities cannot be ruled out at this moment. Now that's its confirmed the biggest question is, why isn't this being discussed on the Village Pump yet?

Please refer me as Ron Merkle (Justapedian) if you're discussing this at the Village Pump.


User avatar

C&B Habitué Posts: 2058 Joined: Wed Aug 01, 2018 2:16 pm Location: with cheese.

Re: Sucks claims to have "hacked" Wikipedia

Unread post by C&B » Sun Jul 20, 2025 6:10 pm

Boy there's a couple of guys in this thread (in more than one, actually), more juiced up than Florida :evilgrin:

"Someone requests clarification and before you know it you find yourself in the Star Chamber."