Baraza
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
@G59@lemmy.ml to Fediverse@lemmy.mlEnglish •
edit-2
2 years ago

PSA: Lemmy.world has been compromised! (Edit: Multiple Instances are down)

message-square
75
fedilink
177
message-square

PSA: Lemmy.world has been compromised! (Edit: Multiple Instances are down)

@G59@lemmy.ml to Fediverse@lemmy.mlEnglish •
edit-2
2 years ago
message-square
75
fedilink

FYI!!! In case you start getting re-directed to porn sites.

Maybe the admin got hacked?


edit: lemmy.blahaj.zone has also been hacked. beehaw.org is also down, possibly intentionally by their admins until the issue is fixed.

Post discussing the point of vulnerability: https://lemmy.ml/post/1896249

Github Issue created here: https://github.com/LemmyNet/lemmy-ui/issues/1895

alert-triangle
You must log in or register to comment.
  • @Candelestine@lemmy.ca
    link
    fedilink
    English
    48•2 years ago

    Yea, I switched to this alt. It appears to be one of the assistant admins accts. Seems like an old fashioned anon prank, to me, they’re mainly just trying to make stuff offensive and redirect people to lemonparty.

    So, y’know, old school.

    I don’t know if any data is actually in danger, but I doubt it. I don’t see why assistant admins would need access to it.

    • @CMahaff@lemmy.ml
      link
      fedilink
      English
      14•
      edit-2
      2 years ago

      My concern is that configuring the site to automatically redirect users sounds like they have pretty large control over the site - the kind of control that I would assume is usually limited to users with root access on the server.

      Obviously hope nothing of value is lost and that there is a proper off-site backup of the content.

      Edit: See Max-P’s comment, it looks like the site redirection was accomplished in a way that IMO suggests they do NOT have full control over the site. We’ll obviously have to wait for the full debrief from the admins.

      • @thanks_shakey_snake@lemmy.ca
        link
        fedilink
        English
        2•2 years ago

        Yeah the “redirect somewhere else” attack definitely doesn’t necessarily require any particular control of the site. Usually it’s noticing that you can trick some text into being run as Javascript, instead of interpreted as text… And then you just stick in a cheeky little <notarealscript>window.location = "https://www.badsite.horse"</notarealscript> into that spot.

        Then every time that comment, username, (in this case apparently) custom emoji, etc. gets loaded, whoops, the code runs and off you go!

        So no control of the site is required at all.

    • @Vilian@lemmy.ca
      link
      fedilink
      English
      6•2 years ago

      probably even the top admin don’t, it’s gonna be encrypted, so even they don’t know your password(except if they changed the code to store it in .txt) but always use differnt password in the internet

  • @bigben111@lemmy.ml
    link
    fedilink
    English
    34•2 years ago

    How did it happen and what does this mean for me as a user of lemmy.ml who also follows people on lemmy.world?

    • Stovetop
      link
      fedilink
      English
      35•2 years ago

      One of the admin accounts appears to have been compromised. The owner/other admins appear to be aware now because that account had its admin access revoked and offending posts are being removed.

      Definitely opens up a big question about the security of Lemmy instances that I am sure will be discussed over the next few days.

      • @bigben111@lemmy.ml
        link
        fedilink
        6•2 years ago

        Thanks for the context

      • @ebits21@lemmy.ca
        link
        fedilink
        English
        5•2 years ago

        They really need to improve their 2fa implementation

  • @upt@lemmy.ml
    link
    fedilink
    28•2 years ago

    Being a part of Lemmy in these early days has been kind of interesting, seeing all of the bugs and bits that will be ironed out over time. One day when Lemmy is as old as Reddit it will all be folklore. Maybe.

    • @Candelestine@lemmy.ca
      link
      fedilink
      12•2 years ago

      This’ll definitely be remembered. It’s good for us, we needed the wakeup call.

  • maegul (he/they)
    link
    fedilink
    20•
    edit-2
    2 years ago

    Hmmm. Don’t know what the fall out of this will be. But a lot of lemmy is on that server. Unfortunately. Maybe we’ll learn a lesson in the value of decentralisation.

    Ruud also runs mastodon.world, FYI.

    • @Vilian@lemmy.ca
      link
      fedilink
      5•2 years ago

      was just some of the admin in the lemmy, i don’t think they share the same admins

  • @CMahaff@lemmy.ml
    link
    fedilink
    English
    14•2 years ago

    4AM in the Netherlands where the instance owner Ruud lives… hopefully his assistant admins can clean it up, but it might be a bit before he even knows anything is wrong.

  • RoundSparrow
    link
    fedilink
    14•2 years ago

    • @G59@lemmy.mlOP
      link
      fedilink
      10•2 years ago

      we did it Reddit! /s

    • Lenins2ndCat
      link
      fedilink
      8•2 years ago

      lmao

    • MrNemobody
      link
      fedilink
      3•2 years ago

      Twitter taking Threads down and posting this lol

    • @klyde@lemmy.ml
      link
      fedilink
      1•2 years ago

      deleted by creator

  • @PrivateOnions@lemmy.ml
    link
    fedilink
    12•
    edit-2
    2 years ago

    deleted by creator

    • Stovetop
      link
      fedilink
      12•2 years ago

      It looks like they’re in the process. The compromised account was demoted from admin and I see posts are being removed. There will definitely need to be some sort of investigation into how this happened, though.

      • @PrivateOnions@lemmy.ml
        link
        fedilink
        12•
        edit-2
        2 years ago

        deleted by creator

  • RoundSparrow
    link
    fedilink
    7•
    edit-2
    2 years ago

    I’m seeing zero comments come out of Lemmy.world in the past 15 minutes, app users shouldn’t have been redirected… and users commenting from other servers should be going to communities homed there. I wonder if they shut off federation. I normally see over 10 comments a minute: https://lemmyadmin.bulletintree.com/query/comments_ap_id_host_prev?output=table&timeperiod=15

    • maegul (he/they)
      link
      fedilink
      4•2 years ago

      Hmm. They seem to have cleaned up a lot of things by now. If federation is an issue that might something the hacker did? Though pausing federation as a precaution makes sense.

  • 𝙚𝙧𝙧𝙚
    link
    fedilink
    7•
    edit-2
    2 years ago

    They’re stealing jwt tokens and noting when they’re admin tokens.

    https://lemmy.sdf.org/post/696053 https://lemmy.sdf.org/comment/850269

  • RoundSparrow
    link
    fedilink
    7•2 years ago

    The “Hot” sort topic:

  • Vamp
    link
    fedilink
    6•2 years ago

    Looks like this thread is getting mass downvoted by bots btw

  • The Cuuuuube
    link
    fedilink
    English
    6•2 years ago

    Is @Ruud’s mastodon.world instance still okay?

    • maegul (he/they)
      link
      fedilink
      English
      5•2 years ago

      Seems to be.

  • RoundSparrow
    link
    fedilink
    5•2 years ago

  • ImOnADiet🇵🇸 (He/Him)
    link
    fedilink
    English
    5•2 years ago

    Compromised in what way? Can you post proof?

    • RoundSparrow
      link
      fedilink
      English
      7•
      edit-2
      2 years ago

      image here ![] (https://lemmy.ml/pictrs/image/0332b83a-ab01-4c99-9155-2a08b02fb652.png)

      among several others

      • ImOnADiet🇵🇸 (He/Him)
        link
        fedilink
        English
        3•2 years ago

        Could you spoiler that weirdo image

        • RoundSparrow
          link
          fedilink
          English
          5•2 years ago

          How do you spoiler an image in Lemmy markdown?

          • ImOnADiet🇵🇸 (He/Him)
            link
            fedilink
            English
            3•2 years ago

            Are you on an app? It’s this symbol on lemmy

            Looks like this if you need to do it yourself

            • RoundSparrow
              link
              fedilink
              English
              3•2 years ago

              I don’t think it works on an image?!

              • ImOnADiet🇵🇸 (He/Him)
                link
                fedilink
                English
                3•2 years ago

                Works like this

                • RoundSparrow
                  link
                  fedilink
                  English
                  4•2 years ago

                  I mangled the link enough that it isn’t rendering inline.

                  I tried 4 underscores, i tried 5. I can not tell from your screenshot exactly how many.

              • ImOnADiet🇵🇸 (He/Him)
                link
                fedilink
                English
                2•2 years ago
                testing spoiling an image

                • RoundSparrow
                  link
                  fedilink
                  English
                  3•2 years ago

                  ok, what’s the trick? I tried 4 underscores

          • ImOnADiet🇵🇸 (He/Him)
            link
            fedilink
            English
            2•
            edit-2
            2 years ago

            Nvm Im not 100% sure how to use it

          • ImOnADiet🇵🇸 (He/Him)
            link
            fedilink
            English
            2•2 years ago

            It works like this

            spoiler test

            Test

            • Duży Szef [he/him]
              link
              fedilink
              English
              4•2 years ago

              The image isn’t spoilered? lmao

              • ImOnADiet🇵🇸 (He/Him)
                link
                fedilink
                English
                3•2 years ago

                I wasnt trying to spoiler that image

                • Duży Szef [he/him]
                  link
                  fedilink
                  English
                  3•2 years ago

                  Huh, ok I guess.

                  I’ll try it myself here

                  spoiler

                  Yay it works :D

            • RoundSparrow
              link
              fedilink
              English
              4•2 years ago

              I can’t get it to work on an image. Is it 4 underscores?

              • ImOnADiet🇵🇸 (He/Him)
                link
                fedilink
                English
                2•2 years ago

                sorry for this being so hectic, I was walking back to my apartment trying to do all this on my phone lol

              • ImOnADiet🇵🇸 (He/Him)
                link
                fedilink
                English
                2•2 years ago


                It’s 3

                • RoundSparrow
                  link
                  fedilink
                  English
                  3•2 years ago

                  3 underscores did not work in preview, I’ll just leave it as is now, a clickable link (not rendered inline)

    • Stovetop
      link
      fedilink
      English
      5•2 years ago

      One of their admins (MichelleG) began posting messages about federation with only Threads. The site is redirecting users to Lemonparty (now there’s a throwback). Site information has been vandalized with racist slurs.

      • Hot Saucerman
        link
        fedilink
        English
        4•2 years ago

        Well, that escalated quickly.

    • @dsemy@lemm.ee
      link
      fedilink
      English
      0•
      edit-2
      2 years ago

      Just go to lemmy.world and see for yourself. (Or don’t actually, might give you a virus or something idk)

      • ImOnADiet🇵🇸 (He/Him)
        link
        fedilink
        English
        0•2 years ago

        Yeah I would like someone to post a screenshot i dont want to leak my ip

  • RoundSparrow
    link
    fedilink
    5•2 years ago

    Technical details, is it the sidebar: https://lemmy.ml/post/1896249

Fediverse@lemmy.ml

!fediverse@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !fediverse@lemmy.ml

A community dedicated to fediverse news and discussion.

Fediverse is a portmanteau of “federation” and “universe”.

Getting started on Fediverse;

  • What is the fediverse?
    • Short ver.
    • Full ver.
  • Fediverse Platforms
  • How to run your own community
  • 230 users / day
  • 708 users / week
  • 799 users / month
  • 2.29K users / 6 months
  • 19.4K subscribers
  • 1.31K Posts
  • 7.53K Comments
  • Modlog
  • mods:
  • Sean Tilley
  • wakest
  • BE: 0.19.3
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org