this post was submitted on 09 Jul 2023
3 points (100.0% liked)

Café

18 readers
1 users here now

Welcome to our virtual third place, The Café.

Come on in and make a new human connection over a cup of coffee (or Teh Tarik). This is a casual community, do whatever you want, share your oyen pics, your frustrations, and even organize a weekend picnic with the community. The world is your oyster.

Rules are simple, be kind and civil with each other. As with any other café, rude patrons will be kicked out.

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Annoyed_Crabby@monyet.cc 1 points 1 year ago* (last edited 1 year ago) (7 children)

Shit, lemmy world got hacked, click on that Israel will lead you to explicit picture of a bunch of naked old man sucking each other, and also pop's up lead to porn site.

Avoid at all cost.

[–] zen@monyet.cc 3 points 1 year ago* (last edited 1 year ago) (1 children)

this is bad. rumour has it this is due to an admin's json web token being leaked.

so I would advise all admins here not to log into 3rd party web apps (mobile apps should be okay) with their admin accounts, as the web apps usually proxy your requests (hence, they have your token), and they proxy not due to nefarious purposes, but due to some problem with cors (in other words, being forced to proxy your request isn't really their fault, and once the cors problem is fixed in the lemmy backend, they can stop doing that).

[–] Annoyed_Crabby@monyet.cc 1 points 1 year ago

Thanks Zen, you're a lifesaver. Brb pressing the emergency button

[–] oyenyaaow@lemmy.zip 1 points 1 year ago (1 children)

is it the lemon party picture?...........feels old.

welcome to pre-rickroll internet.

[–] Annoyed_Crabby@monyet.cc 1 points 1 year ago

Ahh, that's what it called, no wonder it's somehow familiar.

[–] ruk_n_rul@monyet.cc 1 points 1 year ago* (last edited 1 year ago)

Goddammit. The fediverse drama continues.

Btw admins it's best that we defederate for the time being.

[–] ruk_n_rul@monyet.cc 0 points 1 year ago* (last edited 1 year ago)

https://kbin.social/m/android@lemdro.id/t/168524/Lemmy-world-and-another-instance-have-been-compromised#entry-comment-661712

The linked comment suggests that the entire Lemmy platform is currently vulnerable to the cookie stealing exploit that already happened to several instances.

Now, if only we have automod that could detect code injection in markdown links and tempban offenders...

load more comments (3 replies)