this post was submitted on 10 Jul 2023
96 points (100.0% liked)

Lemmy NSFW

11890 readers
9 users here now

Updates about lemmynsfw.com

founded 1 year ago
MODERATORS
 

We quietly defederated temporarily earlier because lemmy.world seemed to be compromised earlier in some way, but then it was fixed. Now it's happened again. Unsure what is going on over there but there isn't much use speculating. They have been dealing with weird redirects to shock sites like lemonparty (throwback). Whoever has compromised them seems to have some early 2010s internet sense of humor I guess.

Anyway, once they have things under control and an announcement is made we will refederate ASAP. For the time being, please avoid going to their homepage for the time being as we have no idea what the nature of the compromise of their site is and to what extent.

EDIT: seems lemmy.blahaj.zone just was as well. :(

top 11 comments
sorted by: hot top controversial new old
[–] Rengoku@lemmynsfw.com 10 points 1 year ago (1 children)

Lemmy.world has been timeouting like crazy for me as well. Sigh.

[–] gavi@lemmynsfw.com 7 points 1 year ago

I am hopeful their site admins will get it under control and be transparent about what happened when they are able to. It's unfortunate though that it's happening in the first place.

[–] OreganoChampion@sh.itjust.works 9 points 1 year ago (1 children)

Admin alt of one of the mods of Mildly Infuriating.

It may have something to do with this message I got:

If I could hazard a guess. Maybe a login token theft, so the hacker has access to an admins account or multiple.

[–] gavi@lemmynsfw.com 3 points 1 year ago (1 children)

It seems to have spread to lemmy.blahaj.zone. Will add them if more come :( This sucks man.

[–] jack@lemmynsfw.com 2 points 1 year ago

I was on blahaj and didn't notice the redirects? What are you seeing or hearing?

[–] DelvianSeek@lemmynsfw.com 4 points 1 year ago

Thanks for the info!

[–] th3dogcowNSFW@lemmynsfw.com 4 points 1 year ago

It looks like they’ve got things under control now. see rudd's post here

[–] Evoke3626@lemmy.fmhy.ml 3 points 1 year ago

Wait really? Aren’t they one of the biggest instances?! Shocking and very concerning

[–] Candelestine@lemmy.ca 1 points 1 year ago

XSS vulnerability on the sidebar. There's some threads starting to pop up about it.

[–] eros90@lemmynsfw.com 1 points 1 year ago (1 children)

I have an account signed up there. Should I be worried? How does it affect the user?

[–] wowow@lemmynsfw.com 2 points 1 year ago

The attackers would've been able to get the token used to login but not your password from a vulnerability with custom emoji. Lemmy.world rotated their JWT secret so all logins are invalidated and the vulnerability has been patched. Should be just fine.