kiwi-farms-website-hacked!-admin-warns-of-data-leak

Share news article

Share on facebook
Share on twitter
Share on linkedin
Share on email

Kiwi Farms Website Hacked! Admin Warns of Data Leak

Kiwi Farms is a website that hosts user-generated content and discussion forums. The site has been accused of doxing, harassment, and cyberbullying. Last month Hackread.com reported about Kiwi Farms and Cloudflare issues and now, reports are that the website has been hit by a cyber attack.

According to Kiwi Farms’ creator Joshua Moon, the site (kiwifarms dot net)has become a victim of a data breach leading to hijacking his administrator account and possibly users’ accounts.

Data Breach Details

Cybersecurity researcher Kevin Beaumont says that someone hacked Kiwi Farms website and proxy service after which all avatars were replaced with the logo of another “free speech” forum, and deleted every node on the forum index one at a time.

However, since Kiwi Farms had backups, none of the data was deleted permanently but the personal information of users could have been compromised.

How The Hack Occurred?

According to Joshua Moon, the site’s offshore hosting provider was compromised, and the hacker(s) accessed an unknown number of user accounts and his admin account using the session hijacking technique.

In this method, the attacker obtains authentication cookies set by the site after an account holder logs in successfully by entering valid authentication credentials and completing 2FA verification.

The attacker could perform this technique after uploading malicious content on a site XenForo, which Kiwi Farms uses to run its user forums. 

Per Moon, the attacker uploaded a webpage disguised as a ‘.opus’ audio file on XenForo and elsewhere may be through an inline frame. This caused random users to generate automated requests and send their authentication cookies outside of the site. The attacker then used them to access their accounts.

The same mechanism was used to hack Moon’s admin account. Once there, the attacker issued a command for XenForo to send data of all users, but the system logs couldn’t fulfill this command.

Kiwi Farms Website Hacked, Emails, Passwords, Device IPs May Be Leaked
Homepage of Kiwi Farms at the time of publishing this article

What Data was Leaked?

Moon stated that he was unsure if user information was leaked. Analysis of his access logs revealed that the attackers tried to download all user records in one go, which caused an error, and the attempt remained fruitless.

Moon assured users of Kiwi Farms that their emails, posts, usernames, recent activity, and other sensitive data were safe. However, the possibility that the attacker issued other commands or scripts that were successfully executed cannot be ruled out at this point, Moon noted.

Launched in 2013, Kiwi Farms has remained in hot waters lately. The forum has been accused of cyberbullying and frequently targeting non-binary, transgender people, LGBTQ community members, and females.

Cybersecurity experts had long anticipated hackers would eventually target the site because of its involvement in swatting and doxing activities. Eventually, on Monday, the forum’s creator posted a notice on the site to alert users about the hack, claiming that user passwords, IP addresses, and emails may have been stolen.

  1. New tool lets teens report, remove their nude photos online
  2. Firm calls cops on researcher for responsibly disclosing data leak
  3. 4chan hackers tried changing voting results of NASA student challenge
  4. WT1SHOP Cybercrime Market Seized by US and Portuguese Authorities
  5. FBI Seizes RaidForums and Arrests Alleged Founder Diogo Santos Coelho

Author

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cyber security and tech world. I am also into gaming, reading and investigative journalism

Related News

Portion of Twitter’s proprietary source code leaked on GitHub

Portion of Twitter’s proprietary source code leaked on GitHub

Reportedly, the source code remained public for several months before being taken down by GitHub. According to a news report…
Pwn2Own 2023: Tesla Model 3, Windows 11, Ubuntu and more Pwned

Pwn2Own 2023: Tesla Model 3, Windows 11, Ubuntu and more Pwned

At Pwn2Own 2023, participants were awarded a full bounty (more than $1,000,000) in each round for successful exploits. Pwn2Own, as…
Latitude Financial Data Breach: 14 Million Customers Affected

Latitude Financial Data Breach: 14 Million Customers Affected

The Australian consumer lender, Latitude Financial, has suffered a major cyber attack, leading to a data breach of passport and…