Stammtisch
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
G59@lemmy.ml to Fediverse@lemmy.mlEnglish ·
edit-2
2 years ago

PSA: Lemmy.world has been compromised! (Edit: Multiple Instances are down)

message-square
message-square
32
link
fedilink
104
message-square

PSA: Lemmy.world has been compromised! (Edit: Multiple Instances are down)

G59@lemmy.ml to Fediverse@lemmy.mlEnglish ·
edit-2
2 years ago
message-square
32
link
fedilink

FYI!!! In case you start getting re-directed to porn sites.

Maybe the admin got hacked?


edit: lemmy.blahaj.zone has also been hacked. beehaw.org is also down, possibly intentionally by their admins until the issue is fixed.

Post discussing the point of vulnerability: https://lemmy.ml/post/1896249

Github Issue created here: https://github.com/LemmyNet/lemmy-ui/issues/1895

alert-triangle
You must log in or register to comment.
  • bigben111@lemmy.ml
    link
    fedilink
    English
    arrow-up
    23
    ·
    2 years ago

    How did it happen and what does this mean for me as a user of lemmy.ml who also follows people on lemmy.world?

    • Stovetop@lemmy.ml
      link
      fedilink
      English
      arrow-up
      24
      ·
      2 years ago

      One of the admin accounts appears to have been compromised. The owner/other admins appear to be aware now because that account had its admin access revoked and offending posts are being removed.

      Definitely opens up a big question about the security of Lemmy instances that I am sure will be discussed over the next few days.

      • bigben111@lemmy.ml
        link
        fedilink
        arrow-up
        4
        ·
        2 years ago

        Thanks for the context

  • upt@lemmy.ml
    link
    fedilink
    arrow-up
    21
    ·
    2 years ago

    Being a part of Lemmy in these early days has been kind of interesting, seeing all of the bugs and bits that will be ironed out over time. One day when Lemmy is as old as Reddit it will all be folklore. Maybe.

  • maegul (he/they)@lemmy.ml
    link
    fedilink
    arrow-up
    13
    ·
    edit-2
    2 years ago

    Hmmm. Don’t know what the fall out of this will be. But a lot of lemmy is on that server. Unfortunately. Maybe we’ll learn a lesson in the value of decentralisation.

    Ruud also runs mastodon.world, FYI.

  • RoundSparrow@lemmy.mlBanned
    link
    fedilink
    arrow-up
    12
    arrow-down
    2
    ·
    2 years ago

    • G59@lemmy.mlOP
      link
      fedilink
      arrow-up
      7
      ·
      2 years ago

      we did it Reddit! /s

    • Lenins2ndCat@lemmy.ml
      link
      fedilink
      arrow-up
      6
      ·
      2 years ago

      lmao

    • MrNemobody@lemmy.ml
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      2 years ago

      Twitter taking Threads down and posting this lol

    • klyde@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      2 years ago

      deleted by creator

  • PrivateOnions@lemmy.ml
    link
    fedilink
    arrow-up
    9
    ·
    edit-2
    2 years ago

    deleted by creator

    • Stovetop@lemmy.ml
      link
      fedilink
      arrow-up
      9
      ·
      2 years ago

      It looks like they’re in the process. The compromised account was demoted from admin and I see posts are being removed. There will definitely need to be some sort of investigation into how this happened, though.

      • PrivateOnions@lemmy.ml
        link
        fedilink
        arrow-up
        9
        ·
        edit-2
        2 years ago

        deleted by creator

  • CMahaff@lemmy.ml
    link
    fedilink
    English
    arrow-up
    9
    ·
    2 years ago

    4AM in the Netherlands where the instance owner Ruud lives… hopefully his assistant admins can clean it up, but it might be a bit before he even knows anything is wrong.

  • 𝙚𝙧𝙧𝙚@lemmy.ml
    link
    fedilink
    arrow-up
    6
    ·
    edit-2
    2 years ago

    They’re stealing jwt tokens and noting when they’re admin tokens.

    https://lemmy.sdf.org/post/696053 https://lemmy.sdf.org/comment/850269

  • RoundSparrow@lemmy.mlBanned
    link
    fedilink
    arrow-up
    6
    ·
    2 years ago

    The “Hot” sort topic:

  • RoundSparrow@lemmy.mlBanned
    link
    fedilink
    arrow-up
    5
    ·
    2 years ago

  • RoundSparrow@lemmy.mlBanned
    link
    fedilink
    arrow-up
    5
    ·
    edit-2
    2 years ago

    I’m seeing zero comments come out of Lemmy.world in the past 15 minutes, app users shouldn’t have been redirected… and users commenting from other servers should be going to communities homed there. I wonder if they shut off federation. I normally see over 10 comments a minute: https://lemmyadmin.bulletintree.com/query/comments_ap_id_host_prev?output=table&timeperiod=15

    • maegul (he/they)@lemmy.ml
      link
      fedilink
      arrow-up
      3
      ·
      2 years ago

      Hmm. They seem to have cleaned up a lot of things by now. If federation is an issue that might something the hacker did? Though pausing federation as a precaution makes sense.

  • RoundSparrow@lemmy.mlBanned
    link
    fedilink
    arrow-up
    4
    ·
    2 years ago

    Technical details, is it the sidebar: https://lemmy.ml/post/1896249

  • maegul (he/they)@lemmy.ml
    link
    fedilink
    arrow-up
    4
    ·
    2 years ago

    For those not aware, the beehaw server did intentionally shut their instance down to avoid any issues.

    See announcement here: https://hachyderm.io/@beehaw/110687918465426082

  • RoundSparrow@lemmy.mlBanned
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    2 years ago

    It was cleaned up on the home page, but now back to being defaced as of this comment time.

    Another user on the site confirmed this:

    • G59@lemmy.mlOP
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      2 years ago

      Oh wow again? 10 min ago it was clean! The .world admins are having a productive day lol

      • lemminer@lemmy.ml
        cake
        link
        fedilink
        arrow-up
        3
        ·
        2 years ago

        Now I’m unable to open lemmy.world, even on liftoff. Mods must have taken it down.

  • TotoroTheGreat@lemmy.ml
    link
    fedilink
    arrow-up
    3
    ·
    2 years ago

    I decided to check it and it tells me that ‘The site has been seized by Reddit for copyright infringement’.

  • RoundSparrow@lemmy.mlBanned
    link
    fedilink
    arrow-up
    3
    ·
    edit-2
    2 years ago

    Lemmy.world front page is back up, but I am now logged-out

Fediverse@lemmy.ml

fediverse@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !fediverse@lemmy.ml

A community dedicated to fediverse news and discussion.

Fediverse is a portmanteau of “federation” and “universe”.

Getting started on Fediverse;

  • What is the fediverse?
    • Short ver.
    • Full ver.
  • Fediverse Platforms
  • How to run your own community
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 4 users / day
  • 41 users / week
  • 158 users / month
  • 1.27K users / 6 months
  • 2 local subscribers
  • 20.5K subscribers
  • 721 Posts
  • 1.78K Comments
  • Modlog
  • mods:
  • Sean Tilley@lemmy.ml
  • wakest@lemmy.ml
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org