Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
I. M. Gei
Jun 26, 2005

CHIEFS

BITCH



UPDATE 07/07/2021

:siren: :siren: :siren: UPLOADS ARE WORKING AGAIN!! I REPEAT, NEW CHAPTER UPLOADS ARE BACK AND UPDATES ARE HAPPENING!!! (The UI is still kinda poo poo but hey, at least your fave stories are getting updates again.) :siren: :siren: :siren:

UPDATE 06/06/2021

:siren: MANGADEX IS BACK!!!!! … kinda… they’re still working on it BUT IT’S USEABLE :siren:

Blaze Dragon posted:

MangaDex is back! In an alpha state, but it's finally back!

https://mangadex.org/
____________________________________

https://www.youtube.com/watch?v=C2xFnKWSxdQ

As most of you already know, MangaDex — aka the website you go to to read all of your fave Jay-pan comic-picture-books for free without having to pay any of your precious monies to the poor overworked creators of said comicbooks so that they might clothe their cold naked bodies and perhaps feed their starving children — went offline late last month after a hacking incident compromised a number of peoples’ accounts there. Now, events like this aren’t exactly uncommon on MD, and normally whenever they happen the codejockeys that keep the site running patch up whatever got broke and MD is back up and running (... well up and running by MD standards, anyway) within a few hours or so. However, this time is different. This time MangaDex decided enough was enough and began a major project to rebuild the entire site from the ground up... better, faster, stronger, (hopefully) more secure than it has ever been before.

... we’ll see how all of that goes for them, but what this means for the rest of us is that MangaDex has been down since March, leaving many/most/all of you unable to catch up on your stories and, most likely, jonesing hard for your regularly-scheduled fix(es). While MD appears to be making some progress toward completing whatever the gently caress they’re working on, they haven’t announced any timeline as to when they expect to go back online, and I think I speak for everyone when I say that that added uncertainty isn’t making this whole long wait any easier.

The purposes of this thread are:
  1. To keep everyone up to speed on the status of MangaDex’s redesign and eventual (we hope :shepface:) return
  2. To post any relevant announcements and updates on the situation as they happen
  3. To recommend any other places we might be able to go to to read/catch up on/look at/get screenshots of our favorite serieses until MD is back online
  4. To maybe see if there are any goons whose knowledge/skills/services MangaDex could put to use to hopefully get this whole project done better faster, thereby potentially ending our long national nightmare sooner
  5. To generally just talk and bitch and moan about this whole situation and all of the assorted chills and body aches and psychotic episodes and poo poo we’re all going through due to comic-manga-book withdrawal


:siren: MOST RECENT UPDATE FROM MANGADEXPosted on April 6th, 2021 :siren:

"MangaDex.org posted:

After putting in two and a half weeks of effort towards v5, we have a good sense of where we are in terms of progress towards getting the site back up. Things did not go as smoothly as we dared to hope, but significant progress has still been made.

The backend Symfony API that will support search (exciting), authentication, and the creation, retrieval, updating, and deletion of users, manga, chapters, follows etc is almost complete with optimistic estimates towards getting it live this weekend for testing. This gives mobile apps a chance to code for the new API if they'd like, but they should also be wary that the API is subject to change as we develop the frontend.

The VueJS SPA frontend won't be up this week, but getting it up within the next two weeks is our ideal goal. To accelerate this estimate, we are once again accepting offers for help. If you have experience with Vue 2, Nuxt, and Vuetify specifically, we would love to have you on board to help.

We're currently using Vuetify to hasten MVP development but future v5 design would use a CSS framework rather than a UI library like Vuetify as well as migrating to Vue 3. We have a fairly complete design document to follow, all you would need to do is implement it. If you're interested in assisting with development of the initial MVP, join our Discord server and DM Plykiya#1738. We'll likely only accept a few so as to avoid having too many people attempting to work on the same thing at the same time, but in the future the frontend will become open-source for all to contribute to.

Sorry for the continued wait, we're just trying to do things right the first time, not the second or third.
:siren: :siren: :siren: :siren: :siren:
IF YOU OR ANYONE YOU KNOW IS GOOD AT COMPUTERS AND/OR KNOWS HOW TO DO WHATEVER THE gently caress THEY’RE TALKING ABOUT HERE, PLEASE GO TO THAT DISCORD (I EVEN LINKED IT FOR YOU BECAUSE I AM NICE LIKE THAT) AND VOLUNTEER YOUR SERVICES TO HELP THIS GREAT AND NOBLE CAUSE!

...... HUH? ... WHAT TH-... NO I DON’T MEAN “NOBLE CAUSE” IN THAT GONE WITH THE WIND WAY, WHAT THE gently caress. SERIOUSLY WH-...... WHY WOULD YOU EVEN ASK THAT? HOW IS THAT EV- WHAT THE gently caress DOES THAT EVEN HAVE TO DO WITH ANYTHING? JESUS CHRIST. GET THE gently caress OUT OF HERE WITH THAT RACIST poo poo. gently caress

:siren: :siren: :siren: :siren: :siren:

____________________________________________________________

ORIGINAL STORY FROM MANGADEX (In case anyone wants to see it)Posted on March 21st, 2021

"MangaDex.org posted:

Due to a recent hacking incident, MangaDex will be down until further notice.

Instead of keeping up a likely vulnerable website and wasting our time and efforts playing cat-and-mouse with constant attacks from DDoS to hacking, we have decided to take this opportunity to refocus and expedite our planned rewrite of the site, called v5. Contrary to our original plans, however, we will be launching this v5 as soon as the minimum essential features are ready.

As developing and maintaining MangaDex is nobody's actual job, it is difficult to give an accurate estimate as to when we'll be back up and running. It should go without saying that every one of us wants it to happen as soon as safely possible.

That said, if everything goes as smoothly as we dare to hope, we could be looking at a downtime of just a week or two. Or three.

For up-to-date news about our progress, please follow us on Twitter.
________________________________________________________________________________

In the meantime, please take the time to read this full write-up of what happened, what our options for plans of action were, how the data breach may have affected you, and how you may be able to help by disclosing vulnerabilities.

All timings are in UTC time.

1. A brief recap:

Three days ago (2021-03-17), we correctly identified and reported that a malicious actor had managed to gain access to an admin account through the reuse of a session token found in an old database leak through faulty configuration of session management. Following that event, we moved to identify the vulnerable section of code and worked to patch it up, also clearing session data globally to thwart further attempts at exploitation through the same method.

After the breach, we started spending many hours reviewing the code for possible further vulnerabilities, and started to patch what we could find to the best of our capabilities. This ran parallel to us opening the site after the breach, as we had incorrectly assumed that the attacker would not be able to gain further access. However, as a precaution, we had started rolling out monitoring of our infrastructure and had remained vigilant in the event the attacker returned.

2. Why did we go down again?

At 2021-03-20 01:52:48, the attacker had managed to access the account of one of our developers who had been previously offline for four days. However, this time around we noticed this immediately and shut the site down at 01:53:40 to investigate further.

At 2021-03-20 02:10, the attacker had sent an email out to the first ten users with the message body, “MangaDex has a DB leak. I suggest you tell their staff about it.” abandoning any pretenses of ransom. Moving forward, while we have no clear evidence that a database breach had happened, for best security practices, we will assume it has happened.

At 2021-03-20 03:41, the attacker had updated the git repository containing the source code leak, claiming that we had successfully patched two out of three possible CVEs. Without any way to confirm the claims, we assumed the worst case scenario and kept the site down to further investigate.

3. What have we done since then?

As of writing, we have invited numerous volunteers to assist our developers with identifying the last possible CVE claimed by the attacker in the codebase. Thanks to our volunteers, we have identified a good number of potential security flaws and moved to rectify them. However, at time of writing, we have still yet to identify the last possible CVE claimed by the attacker.

With that knowledge in mind, we were confronted with a difficult decision. If we had assumed incorrectly that the web code is now secure, we could end up being compromised again by the attacker. As a result of that, in good conscience, we could not possibly re-open the website to users presently.

Lastly, our staff consists of volunteers. Volunteers with real life commitments and duties that do not earn a single cent from volunteering for MangaDex. While we aim to provide the best service we can to you, the repeated attacks were starting to take a toll on us all, having to repeatedly scan through thousands of lines of code trying to find a figurative needle in a haystack. We have evaluated our choices on hand and have decided this is unsustainable to both our users, and ourselves.

4. What are we planning to do now?

Seeing as the attacker has no intention of helping us to resolve the security issues and is instead more keen on causing maximum disruption to MangaDex, we have decided to keep the site offline till we are confident in its security. We considered a number of options on hand, namely:

  1. Bring the site back in its (potentially vulnerable) current state, and continue watching for signs of more attacks. We decided against this as it could lead to more emergency downtime, which would be frustrating for our users as well as our staff.
  2. Bring the site back in a nerfed/read-only state, making it impossible for the attacker to make any further changes. We decided against this because this would mean that the public would not be able to upload, and only our moderators could, which would place a large burden on them.
  3. Gut the site of most of its features such that only essential, non-abusable features remain. However, the time spent doing so would be better spent on v5, so this is not a sensible option.
  4. Close the site until v5 (the total site rewrite) is completely ready. As mentioned previously, the attacker has access to the v3 code, so this option would be relatively more secure. However, given the current progress of v5, this would mean that the hacker will have successfully deprived the community of manga for a longer period of time, which is most likely the hacker’s motive at this point (to force us offline).
  5. Close the site until a barebones version of v5 is complete. This would only contain the minimum essential features, namely to allow readers to read, follow, and groups to upload, much like how v1 of MangaDex was originally released (for those of you who have stuck by us since then) but using the same technologies we’ve planned for v5.

We have decided that option (e) would be the best approach, as it strikes a good balance between downtime and working to bring the site back up in a usable and (most importantly) secure state.

5. Data Breach & You

While we have numerous signs that the attacker had access to information not typically visible from the context of a normal user, we have not been able to confirm a full host compromised, or an up-to-date database breach. We intend to continue to keep a close eye on both and aim to update as we investigate and discover further. Moving forward however, it is in both our users’ interest and ourselves that we will consider the database breached.

As a user, we will encourage that you would assume that your data has been breached, and take precautions immediately, such as changing the passwords of any accounts that might share the same password as your MangaDex account. As a generally good security practice, password managers are highly recommended to keep your online identity secure.

6. Disclosures

In the meantime, we are still open to any suggestions or responsible disclosures of vulnerabilities found in the leaked v3 source code. While we have found numerous at time of writing, and have moved to patch most of it, we appreciate all attempts at helping us to find more. For more information, or for disclosures, please kindly approach a staff member on our Discord.

7. Bug Bounties

Moving forward from this incident, we sincerely intend to improve upon the security on existing and future infrastructure, and while some of our developers have experience in the security fields, we have decided that having some form of a bug bounty program for v5 will only prove to be beneficial to MangaDex. As means of backing that, we intend to consider payouts depending on the severity of reported bugs. More details to be released in the near future.

I. M. Gei fucked around with this message at 04:17 on Jul 9, 2021

Adbot
ADBOT LOVES YOU

I. M. Gei
Jun 26, 2005

CHIEFS

BITCH



https://twitter.com/MangaDex/status/1382371202497384450?s=20
https://twitter.com/MangaDex/status/1382371296860893194?s=20
https://twitter.com/MangaDex/status/1382371378624618497?s=20

I. M. Gei fucked around with this message at 07:01 on Apr 15, 2021

drilldo squirt
Aug 18, 2006

a beautiful, soft meat sack
Clapping Larry
Why is mangadex closed? I want my mangas.

HenryEx
Mar 25, 2009

...your cybernetic implants, the only beauty in that meat you call "a body"...
Grimey Drawer
This downtime loving sucks, mang.

The database leak seems to have been confirmed, btw. So change your passwords.

Nuebot
Feb 18, 2013

The developer of Brigador is a secret chud, don't give him money
It's amazing how bad other manga reader sites are. I've gotten so used to Mangadex that I forgot that.

Sagabal
Apr 24, 2010

the helck sequel is pretty comfy btw, check it out if you haven't yet

drilldo squirt
Aug 18, 2006

a beautiful, soft meat sack
Clapping Larry
I don't know how. :smith:

Wallrod
Sep 27, 2004
Stupid Baby Picture
I mainly use Tachiyomi to read mangos on my tablet, you can make it scrape from various sites, though mangledicks being so monolithic still means stuff comes slower or you have to go looking across a few sources. At least it saves you from awful layouts and ads.

Blaze Dragon
Aug 28, 2013
LOWTAX'S SPINE FUND

Alejandro Sanchez posted:

the helck sequel is pretty comfy btw, check it out if you haven't yet

There's a Helck sequel?! God, I need that now.

Numero6
Oct 10, 2012

ここは地の果て 流されて俺
今日もさすらい 涙も涸れる
ブルーゲイル

Blaze Dragon posted:

There's a Helck sequel?! God, I need that now.

It's not a direct sequel but it's called "Verndio - Surreal Sword Saga".

Swilo
Jun 2, 2004
ANIME SUCKS HARD
:dukedog:
it's up on the scanlation group's site https://reader.kireicake.com/series/helck_vlundio_surreal_sword_saga/

I. M. Gei
Jun 26, 2005

CHIEFS

BITCH



Just a heads-up that MangaNelo is probably the best MangaDex substitute I have found so far. It’s got a bunch of ads and occasionally small popups, and you have to scroll up and down your screen to go from page to page instead of clicking the right or left side like you do on MD, but it has tons and tons of the same titles available on MD, or at least the ones that I follow.

Several of the titles I’ve clicked on on there haven’t been updated since February or March though. Whether this is due to scanlators not knowing about MangaNelo’s existence since MD went down, or COVID-related holdups on the production and/or scanlation of certain mangas (or both), I can’t say, but I feel like I should make a note of it.


EDIT: I went ahead and stuck this in the OP so it’s more visible

I. M. Gei fucked around with this message at 08:16 on Apr 29, 2021

Captain Invictus
Apr 5, 2005

Try reading some manga!


Clever Betty
Readm.org has been the place I've been reading stuff, when I've been reading anyways. not having my bookmarks and such has slowed my reading frequency a good bit. but aside from it being absolutely clogged with manhwa/manhua, it's got most everything mangadex had as well.

Acerbatus
Jun 26, 2020

by Jeffrey of YOSPOS
Apparently the mangadex twitter got suspended? No announcement on their site yet.

RatHat
Dec 31, 2007

A tiny behatted rat👒🐀!

Acerbatus posted:

Apparently the mangadex twitter got suspended? No announcement on their site yet.

Might've been a mass report from the people who hacked the site. There's also these guys going around

https://twitter.com/MattikarpArt/status/1390976501332406276?s=20

DrSunshine
Mar 23, 2009

Did I just say that out loud~~?!!!
Shaka, when the walls fell.

Xelkelvos
Dec 19, 2012
https://twitter.com/MattikarpArt/status/1391229035825434625

I. M. Gei
Jun 26, 2005

CHIEFS

BITCH



MangaDex has a new Twitter account. They are now @MangaDexRE

Also their old url appears to have stopped working, so here’s a link that works

Blaze Dragon
Aug 28, 2013
LOWTAX'S SPINE FUND

MangaDex is back! In an alpha state, but it's finally back!

https://mangadex.org/

Nipponophile
Apr 8, 2009
I'm glad it's back, but goddamn they have hosed up the front end something fierce.

Swilo
Jun 2, 2004
ANIME SUCKS HARD
:dukedog:
The features list is absolutely hilarious

their reddit account posted:


What we have right now:
• Homepage: Popular manga, latest uploaded chapters
• Basic reader with a few settings.
• Covers
• Manga Pages
• Login
• Follows Feed
• List of followed manga
• Basic manga searching (available to guests as well now!)

What we don't have yet:
• User settings (there's no escaping the light theme)
• Views/Ratings (no more bandwagons!)
• Creating or editing anything (exists in the API, but will be postponed until moderation tools exist to prevent abuse)
• Uploading chapters (exists in the API, postponed for the same reason)
• Reports
• Registration/Resetting your password (exists in the API, hasn't been implemented in the frontend)
• Group pages
• User pages
• Deleting your account
• The forums/DMs/comments/etc
• Advanced searches (exists in the API, use MangaUpdates for now)
Better than nothing I guess, and at least you can click "Load more..." a million times to see all your follows.

Arkanian
Sep 18, 2013


Nipponophile posted:

I'm glad it's back, but goddamn they have hosed up the front end something fierce.

Apparently it's just a hack of the front end from the mobile version of the site, rather than a prototype for the final product. I guess they prioritized being able to access the manga themselves over everything else, which seems fair.

sinky
Feb 22, 2011



Slippery Tilde
The comments in thread say it's temporarily using the mobile UI, hopefully that's true.

e: ^ :argh:

Clarste
Apr 15, 2013

Just how many mistakes have you suffered on the way here?

An uncountable number, to be sure.

sinky posted:

The comments in thread say it's temporarily using the mobile UI, hopefully that's true.

e: ^ :argh:

I mean, I browse the site on mobile and it's still worse than it used to be.

Captain Invictus
Apr 5, 2005

Try reading some manga!


Clever Betty
huh, it's not loading for me, did the site go back down?

Wark Say
Feb 22, 2013

by Fluffdaddy
Seems to be up for me. Make sure to Shift + F5 since it might be using an old-rear end cache of the website.

Captain Invictus
Apr 5, 2005

Try reading some manga!


Clever Betty

Wark Say posted:

Seems to be up for me. Make sure to Shift + F5 since it might be using an old-rear end cache of the website.
after clearing cache/cookies and using different browsers it's not working for me. weird.

Swilo
Jun 2, 2004
ANIME SUCKS HARD
:dukedog:
There was something going on with the API servers not being routed properly through certain ISPs like Verizon, not sure if there was a resolution or workaround for it since I'm not affected. Maybe a VPN?

edit: https://www.reddit.com/r/mangadex/comments/no0cfi/mangadex_block_investigation/

Swilo fucked around with this message at 23:24 on Jun 6, 2021

I. M. Gei
Jun 26, 2005

CHIEFS

BITCH




so you can read mangas, but you can’t post new chapters?

lol what’s even the point

I guess they had to post SOMETHING since it’s been a month since the last status update, but drat you’d think they’d have more to show by now. who’s loving running this poo poo, radium?

Swilo posted:

Better than nothing I guess

yeah like Mighty No. 9

Captain Invictus
Apr 5, 2005

Try reading some manga!


Clever Betty

Swilo posted:

There was something going on with the API servers not being routed properly through certain ISPs like Verizon, not sure if there was a resolution or workaround for it since I'm not affected. Maybe a VPN?

edit: https://www.reddit.com/r/mangadex/comments/no0cfi/mangadex_block_investigation/
wow, I'm on verizon and that corresponds to roughly when the site stopped working altogether for me. gently caress's sake.

HenryEx
Mar 25, 2009

...your cybernetic implants, the only beauty in that meat you call "a body"...
Grimey Drawer
I've been waiting for literal months by now, i guess i can wait a little longer until the UX goes back to not-atrocious

Arkanian
Sep 18, 2013


I. M. Gei posted:

so you can read mangas, but you can’t post new chapters?

lol what’s even the point

I guess they had to post SOMETHING since it’s been a month since the last status update, but drat you’d think they’d have more to show by now. who’s loving running this poo poo, radium?

I follow the subreddit, and there have been a lot of posts there asking about ways to access their follow list since they couldn't remember the names of all the manga they were following. So that's probably a big part of it too.

chiasaur11
Oct 22, 2012



I. M. Gei posted:

so you can read mangas, but you can’t post new chapters?

lol what’s even the point


The point is me getting back to where I left off in Yokohama Kaidashi Kikou.

So, mission accomplished, basically.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Not being able to search by genre sucks. But at least it's back.


Also I'm switching to Verizon as isp shortly and now I'm worried it'll disappear again

I. M. Gei
Jun 26, 2005

CHIEFS

BITCH



https://twitter.com/MangaDexRE/status/1401604431364427785?s=20

that must be some fine backend :tutbutt:

Swilo
Jun 2, 2004
ANIME SUCKS HARD
:dukedog:
Who exactly was complaining about the site's "performance and speed" that it needed addressing? Stability was the problem with the ongoing and unmitigated DDoS attacks and routine Wednesday self-DDoS from solo leveling updates, and they can't make any claims about that until the site is feature-complete.

Oh and I guess a little thing called security.

Pollyanna
Mar 5, 2005

Milk's on them.


Optimization is easy. Security and stability is hard. Might as well flaunt the low hanging fruit if you can’t get the latter.

Lamebot
Sep 8, 2005

ロボ顔菌~♡
https://mangadex.network

I. M. Gei
Jun 26, 2005

CHIEFS

BITCH




the gently caress is this?

Adbot
ADBOT LOVES YOU

I. M. Gei
Jun 26, 2005

CHIEFS

BITCH



no seriously what the gently caress is that poo poo supposed to be? I get that it’s stats but stats of WHAT?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply