FYI!!! In case you start getting re-directed to porn sites.

Maybe the admin got hacked?


edit: lemmy.blahaj.zone has also been hacked. beehaw.org is also down, possibly intentionally by their admins until the issue is fixed.

Post discussing the point of vulnerability: https://lemmy.ml/post/1896249

Github Issue created here: https://github.com/LemmyNet/lemmy-ui/issues/1895

64 points

How did it happen and what does this mean for me as a user of lemmy.ml who also follows people on lemmy.world?

permalink
report
reply
78 points

One of the admin accounts appears to have been compromised. The owner/other admins appear to be aware now because that account had its admin access revoked and offending posts are being removed.

Definitely opens up a big question about the security of Lemmy instances that I am sure will be discussed over the next few days.

permalink
report
parent
reply
33 points

I wouldn’t assume reasons why or that it’s fixed until that consensus has been more widely reached.

permalink
report
parent
reply
7 points
*

More time will definitely be needed. I’m glad they caught it and acted quickly enough to prevent more vandalism from occurring, but until we know how the account was compromised and what else they may have gotten in the process, it’s still a situation to keep an eye on.

permalink
report
parent
reply
8 points

Thanks for the context

permalink
report
parent
reply
18 points

Definitely opens up a big question about the security of Lemmy instances that I am sure will be discussed over the next few days.

They added 2FA login to lemmy in one of the newer updates. Probably pretty pertinent for any admins to use it…

permalink
report
parent
reply
13 points
*

It’s buggy and missing some key checks to make sure it’s working when you set it up.

Real risk of locking yourself out of your account.

permalink
report
parent
reply
1 point

Too bad it doesn’t work with several 2FA apps and right now…

permalink
report
parent
reply
3 points

Also I believe this was achieved through cookie stealing, which 2FA would not have helped

permalink
report
parent
reply
6 points

They really need to improve their 2fa implementation

permalink
report
parent
reply
25 points

Not a whole lot - you might see some spam being federated from lemmy.world but I’d expect the lemmy.ml and lemmy.world admins will fix it, and them clean it up.

That’s probably good stress test to figure out how to handle that.

permalink
report
parent
reply
7 points

Thanks for the response very helpful.

permalink
report
parent
reply
10 points

Compromised in what way? Can you post proof?

permalink
report
reply
8 points
*

Just go to lemmy.world and see for yourself. (Or don’t actually, might give you a virus or something idk)

permalink
report
parent
reply
8 points

Yeah I would like someone to post a screenshot i dont want to leak my ip

permalink
report
parent
reply
9 points

One of their admins (MichelleG) began posting messages about federation with only Threads. The site is redirecting users to Lemonparty (now there’s a throwback). Site information has been vandalized with racist slurs.

permalink
report
parent
reply
7 points

Well, that escalated quickly.

permalink
report
parent
reply
19 points

Just go to https://lemmy.world and see for yourself, although be careful it’s nasty.

As of now it looks like this:

And then it randomly redirects to gore sites like lemonparty or chaturbate or some pedo shit. It’s pretty bad.

permalink
report
parent
reply
10 points

Alright thanks

permalink
report
parent
reply
7 points
*
9 points

Could you spoiler that weirdo image

permalink
report
parent
reply
5 points

How do you spoiler an image in Lemmy markdown?

permalink
report
parent
reply
56 points

God damn, spez-funded hacker groups already is trying to disrupt the resistance.

permalink
report
reply
18 points

Fuck spez

permalink
report
parent
reply
8 points

This is going to turn into some obligatory response.

“Thank you everyone for coming together to discuss the planned future for the news community.” Everyone: “Fuck spez.”

permalink
report
parent
reply
7 points

F

permalink
report
reply
20 points

Just went there and didn’t immediately see anything out of the ordinary, but then was redirected to Chatroulette, lol yikes

permalink
report
reply
15 points

Really hoping it’s “only” redirecting to offensive sites, and not to malware. I got redirected a few times, before I closed my browser.

permalink
report
parent
reply
14 points
*

TBF modern browsers are remarkably secure from being a vector to pwn your computer these days.

EDIT: I don’t endorse hanging out on a compromised lemmy.world. Focus on the implication for the bigger lemmyverse though. A hack coming through to you is unlikely.

permalink
report
parent
reply
19 points

I sure hope so

~ Sent via Internet Explorer 6 on Windows XP

permalink
report
parent
reply
2 points

You can’t get malware or viruses just by visiting a site

permalink
report
parent
reply

Fediverse

!fediverse@lemmy.ml

Create post

A community dedicated to fediverse news and discussion.

Fediverse is a portmanteau of “federation” and “universe”.

Getting started on Fediverse;

Community stats

  • 359

    Monthly active users

  • 806

    Posts

  • 12K

    Comments