this post was submitted on 10 Jul 2023
247 points (100.0% liked)

Fediverse

757 readers
1 users here now

A community dedicated to fediverse news and discussion.

Fediverse is a portmanteau of "federation" and "universe".

Getting started on Fediverse;

founded 5 years ago
MODERATORS
 

FYI!!! In case you start getting re-directed to porn sites.

Maybe the admin got hacked?


edit: lemmy.blahaj.zone has also been hacked.

top 50 comments
sorted by: hot top controversial new old
[–] Candelestine@lemmy.ca 70 points 1 year ago (5 children)

Yea, I switched to this alt. It appears to be one of the assistant admins accts. Seems like an old fashioned anon prank, to me, they're mainly just trying to make stuff offensive and redirect people to lemonparty.

So, y'know, old school.

I don't know if any data is actually in danger, but I doubt it. I don't see why assistant admins would need access to it.

[–] hawkwind@lemmy.management 40 points 1 year ago (4 children)

All the bean memes are in danger! On a serious note, old-skool or not, it's a huge loss of trust in something the community-at-large is excited to see replace reddit.

[–] Candelestine@lemmy.ca 47 points 1 year ago (2 children)

Par for the course. This system will never be immune to things like that. That's part of what happens when you decentralize your power. Instead of a single target that can be made highly secure, you have a distributed array of targets.

People should certainly be engaging on here with full awareness of the reality of the Fediverse, not expecting reddit 2.0. We never will be able to offer exactly what they did. We'll be naturally worse in some areas and naturally better in others.

[–] hawkwind@lemmy.management 15 points 1 year ago

That's fair. I shouldn't have said "replace reddit."

[–] Philolurker@lemm.ee 9 points 1 year ago (4 children)

This is why I'm glad I made redundant accounts on multiple instances. When there are problems on lemmy.world, I can just hop on over to another. That's never been an option with Reddit.

Now if there was only a way to export or sync user settings like subscriptions, it would be perfect.

load more comments (4 replies)
[–] Menachem@midwest.social 21 points 1 year ago (1 children)

idk, im surprised it took this long. there's a huge variety of admin teams with varying degrees of security awareness and it's been over a month since the first big influx of users started. it'll happen again too and probably not before too long

load more comments (1 replies)
[–] Cyyy@lemmy.ml 9 points 1 year ago

i did switch from reddit to lemmy.world because i expected it to be a safe alternative that would atleast pay a lot of attention to security. so yes, the trust in security is broken a lot with this. especially since it happend so soon after so many people joined. i already think about maybe making my own instance to keep my account safe in the future.

[–] henfredemars@infosec.pub 8 points 1 year ago (2 children)

On the other hand, look at where we are. This is proof that one hack can't take down Lemmy.

load more comments (2 replies)
[–] CMahaff@lemmy.ml 26 points 1 year ago* (last edited 1 year ago) (2 children)

My concern is that configuring the site to automatically redirect users sounds like they have pretty large control over the site - the kind of control that I would assume is usually limited to users with root access on the server.

Obviously hope nothing of value is lost and that there is a proper off-site backup of the content.

Edit: See Max-P's comment, it looks like the site redirection was accomplished in a way that IMO suggests they do NOT have full control over the site. We'll obviously have to wait for the full debrief from the admins.

load more comments (2 replies)
[–] InterestFreeBread@lemmy.srcfiles.zip 7 points 1 year ago (1 children)

I don't see why assistant admins would need access to it.

because it's easier than figuring out what permissions they actually need

[–] RoundSparrow@lemmy.ml 7 points 1 year ago (1 children)

Lemmy permission system is very limited, it's a boolean for admin

load more comments (1 replies)
load more comments (2 replies)
[–] bigben111@lemmy.ml 53 points 1 year ago (2 children)

How did it happen and what does this mean for me as a user of lemmy.ml who also follows people on lemmy.world?

[–] Stovetop@lemmy.ml 67 points 1 year ago (4 children)

One of the admin accounts appears to have been compromised. The owner/other admins appear to be aware now because that account had its admin access revoked and offending posts are being removed.

Definitely opens up a big question about the security of Lemmy instances that I am sure will be discussed over the next few days.

[–] hawkwind@lemmy.management 27 points 1 year ago (3 children)

I wouldn't assume reasons why or that it's fixed until that consensus has been more widely reached.

load more comments (3 replies)
[–] eerongal@ttrpg.network 15 points 1 year ago (1 children)

Definitely opens up a big question about the security of Lemmy instances that I am sure will be discussed over the next few days.

They added 2FA login to lemmy in one of the newer updates. Probably pretty pertinent for any admins to use it....

[–] ebits21@lemmy.ca 8 points 1 year ago* (last edited 1 year ago) (6 children)

It’s buggy and missing some key checks to make sure it’s working when you set it up.

Real risk of locking yourself out of your account.

load more comments (6 replies)
load more comments (2 replies)
[–] Max_P@lemmy.max-p.me 20 points 1 year ago (1 children)

Not a whole lot - you might see some spam being federated from lemmy.world but I'd expect the lemmy.ml and lemmy.world admins will fix it, and them clean it up.

That's probably good stress test to figure out how to handle that.

load more comments (1 replies)
[–] 001100010010@lemmy.dbzer0.com 49 points 1 year ago (1 children)

God damn, spez-funded hacker groups already is trying to disrupt the resistance.

[–] bdawg923@lemmy.ml 12 points 1 year ago (1 children)
load more comments (1 replies)
[–] Max_P@lemmy.max-p.me 43 points 1 year ago (8 children)

I tried to reproduce the exploit on my own instance and it appears that the official Docker for 0.18.1 is not vulnerable to it.

It appears that the malicious code was injected as an onload property in the markdown for taglines. I tried to reproduce in taglines, instance info, in a post with no luck: it always gets escaped properly in the <img alt="exploit here"> property as HTML entity.

lemmy.world appears to be running a git commit that is not public.

[–] CMahaff@lemmy.ml 21 points 1 year ago (1 children)

I actually consider it good news that the redirection is happening this way (something that can be done just by having the lemmy credentials of an admin) vs something indicating they have access to the server itself.

[–] maegul@lemmy.ml 13 points 1 year ago (9 children)

Yep, same. It was also the most likely scenario.

It looks like it was an individual admin getting hacked. Not good but not the worst. Most fallout will probably be whether their security practices were sufficient for an admin and whether lemmy has good enough contingencies for this sort of thing. Lemmy’s 2FA is probably a hot issue now though.

load more comments (7 replies)
[–] maegul@lemmy.ml 36 points 1 year ago* (last edited 1 year ago) (3 children)

Hmmm. Don’t know what the fall out of this will be. But a lot of lemmy is on that server. Unfortunately. Maybe we’ll learn a lesson in the value of decentralisation.

Ruud also runs mastodon.world, FYI.

[–] Lemon@lemmy.blahaj.zone 10 points 1 year ago

This is why it makes sense for communities to not all pile into one instance, it gives one instance admin too much power and responsibility over everything.

load more comments (2 replies)
[–] upt@lemmy.ml 27 points 1 year ago (1 children)

Being a part of Lemmy in these early days has been kind of interesting, seeing all of the bugs and bits that will be ironed out over time. One day when Lemmy is as old as Reddit it will all be folklore. Maybe.

[–] Candelestine@lemmy.ca 8 points 1 year ago

This'll definitely be remembered. It's good for us, we needed the wakeup call.

[–] delendum@lemdit.com 23 points 1 year ago (2 children)

lemmy.world was briefly back to normal and there had been a post saying that everything was fine now - it's not.

The site has just started doing the same thing again.

Please do not try using lemmy.world for the time being.

[–] Cube6392 9 points 1 year ago (3 children)

the post saying everything was fine now was coming from the same account that was originally compromised

load more comments (3 replies)
load more comments (1 replies)
[–] CMahaff@lemmy.ml 21 points 1 year ago

4AM in the Netherlands where the instance owner Ruud lives... hopefully his assistant admins can clean it up, but it might be a bit before he even knows anything is wrong.

[–] RoundSparrow@lemmy.ml 16 points 1 year ago (3 children)
[–] G59@lemmy.ml 9 points 1 year ago

we did it Reddit! /s

[–] luthis@lemmy.nz 8 points 1 year ago

I saw this and laughed. Yes, that's definitely how copyright works.

load more comments (1 replies)
[–] bamboo@lemmy.blahaj.zone 15 points 1 year ago (1 children)

Just went there and didn't immediately see anything out of the ordinary, but then was redirected to Chatroulette, lol yikes

[–] tarjeezy@lemmy.ca 14 points 1 year ago (2 children)

Really hoping it's "only" redirecting to offensive sites, and not to malware. I got redirected a few times, before I closed my browser.

[–] hawkwind@lemmy.management 10 points 1 year ago* (last edited 1 year ago) (1 children)

TBF modern browsers are remarkably secure from being a vector to pwn your computer these days.

EDIT: I don't endorse hanging out on a compromised lemmy.world. Focus on the implication for the bigger lemmyverse though. A hack coming through to you is unlikely.

[–] bamboo@lemmy.blahaj.zone 11 points 1 year ago (1 children)

I sure hope so

~ Sent via Internet Explorer 6 on Windows XP

load more comments (1 replies)
load more comments (1 replies)
[–] Max_P@lemmy.max-p.me 11 points 1 year ago

The admins now appears to have taken down the backend in an effort to stop the defacing.

[–] bootyberrypancakes@lemmywinks.xyz 10 points 1 year ago (4 children)

lemmy.blahaj.zone got hacked too, looks like the same people

[–] Candelestine@lemmy.ca 8 points 1 year ago (1 children)

Huh... so this probably is more sophisticated than a single acct breach then. Lovely.

load more comments (1 replies)
load more comments (3 replies)
[–] JohnSaveourSocks@lemmy.ml 9 points 1 year ago* (last edited 1 year ago)

I literally just made a community over there 20 mins ago fml

[–] TheGreatFox@lemmy.dbzer0.com 9 points 1 year ago

Main instance hacked? Time to use an alt!

The first hack is a rite of passage for every site that gets big. It means we've been recognized!

Luckily, this seems to be a standard troll (with some tech knowledge) - they've defaced the site and put redirects to shock sites, rather than injecting actual malware or quietly collecting everyone's passwords. This could be much worse.

[–] Cube6392 9 points 1 year ago (1 children)

Is @Ruud's mastodon.world instance still okay?

load more comments (1 replies)
[–] RoundSparrow@lemmy.ml 8 points 1 year ago

The "Hot" sort topic:

[–] RoundSparrow@lemmy.ml 7 points 1 year ago* (last edited 1 year ago) (2 children)

I'm seeing zero comments come out of Lemmy.world in the past 15 minutes, app users shouldn't have been redirected... and users commenting from other servers should be going to communities homed there. I wonder if they shut off federation. I normally see over 10 comments a minute: https://lemmyadmin.bulletintree.com/query/comments_ap_id_host_prev?output=table&timeperiod=15

load more comments (2 replies)
load more comments
view more: next ›