halubilo.social
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
@[email protected] to [email protected] •
edit-2
2 years ago

PSA: Lemmy.world has been compromised! (Edit: Multiple Instances are down)

message-square
128
fedilink
68
message-square

PSA: Lemmy.world has been compromised! (Edit: Multiple Instances are down)

@[email protected] to [email protected] •
edit-2
2 years ago
message-square
128
fedilink

FYI!!! In case you start getting re-directed to porn sites.

Maybe the admin got hacked?


edit: lemmy.blahaj.zone has also been hacked. beehaw.org is also down, possibly intentionally by their admins until the issue is fixed.

Post discussing the point of vulnerability: https://lemmy.ml/post/1896249

Github Issue created here: https://github.com/LemmyNet/lemmy-ui/issues/1895

  • RoundSparrow
    link
    fedilink
    English
    3•2 years ago

    The JWT are likely a hot issue, already some Issues on GitHub about them not being revoked properly.

    • @[email protected]
      link
      fedilink
      English
      1•2 years ago

      Oh man, that would be brutal if they are resetting the password and it isn’t kicking the attacker out…

      • Max-P
        link
        fedilink
        English
        1•2 years ago

        That’s probably what happened here because they did revoke the admin’s access, but it continued.

      • RoundSparrow
        link
        fedilink
        English
        0•2 years ago

        JWT issue opened 4 days ago: https://github.com/LemmyNet/lemmy/issues/3499

        • @[email protected]
          link
          fedilink
          English
          1•2 years ago

          The issue does say changing the password should kick the user out, but yeah, still not good.

[email protected]

[email protected]

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A community dedicated to fediverse news and discussion.

Fediverse is a portmanteau of “federation” and “universe”.

Getting started on Fediverse;

  • What is the fediverse?
    • Short ver.
    • Full ver.
  • Fediverse Platforms
  • How to run your own community
  • 203 users / day
  • 610 users / week
  • 857 users / month
  • 3.62K users / 6 months
  • 20.5K subscribers
  • 946 Posts
  • 13.4K Comments
  • Modlog
  • mods:
  • Sean Tilley
  • wakest
  • BE: 0.19.3
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org