• Annoyed_🦀 A
    link
    2
    edit-2
    1 year ago

    Shit, lemmy world got hacked, click on that Israel will lead you to explicit picture of a bunch of naked old man sucking each other, and also pop’s up lead to porn site.

    Avoid at all cost.

    • @zen
      link
      5
      edit-2
      1 year ago

      deleted by creator

      • Annoyed_🦀 A
        link
        11 year ago

        Thanks Zen, you’re a lifesaver. Brb pressing the emergency button

      • Annoyed_🦀 A
        link
        11 year ago

        Ahh, that’s what it called, no wonder it’s somehow familiar.

        • @zen
          link
          3
          edit-2
          1 year ago

          deleted by creator

          • Annoyed_🦀 A
            link
            11 year ago

            Merely open the dm? Or do we have to click the link for it to happen?

            • @zen
              link
              1
              edit-2
              1 year ago

              deleted by creator

              • @cendawanita
                link
                11 year ago

                damn, i feel like we can check off one success criteria: suddenly so attractive for hacks.

    • zen
      link
      fedilink
      21 year ago

      https://github.com/LemmyNet/lemmy-ui/issues/1895 has more information on mitigations, which may not be necessary if no custom emojis were added.

      it also has something for invalidating all json web tokens by changing the signing key (all users will need to re-login after doing that), which may be necessary depending on whether the tech team believes any of them (especially any of the admin’s) have been compromised (there is currently no expiry date on the tokens).

      #lemmyworldhacked #fediversedrama

      • Annoyed_🦀 A
        link
        11 year ago

        Thanks, i’m giving it a read but i’m not coding literate so may need some time to parse 😂

          • Annoyed_🦀 A
            link
            11 year ago

            The team are currently working on the bot though, but thanks for the suggestion 😁

      • jellodiMA
        link
        21 year ago

        like we’re ever going to give it up

    • @ruk_n_rul
      link
      0
      edit-2
      1 year ago

      Goddammit. The fediverse drama continues.

      Btw admins it’s best that we defederate for the time being.

    • @ruk_n_rul
      link
      -1
      edit-2
      1 year ago

      https://kbin.social/m/android@lemdro.id/t/168524/Lemmy-world-and-another-instance-have-been-compromised#entry-comment-661712

      The linked comment suggests that the entire Lemmy platform is currently vulnerable to the cookie stealing exploit that already happened to several instances.

      Now, if only we have automod that could detect code injection in markdown links and tempban offenders…