this post was submitted on 10 Jul 2023
73 points (95.1% liked)

Meta (lemm.ee)

3565 readers
4 users here now

lemm.ee Meta

This is a community for discussion about this particular Lemmy instance.

News and updates about lemm.ee will be posted here, so if that's something that interests you, make sure to subscribe!


Rules:


If you're a Discord user, you can also join our Discord server: https://discord.gg/XM9nZwUn9K

Discord is only a back-up channel, !meta@lemm.ee will always be the main place for lemm.ee communications.


If you need help with anything, please post in !support instead.

founded 1 year ago
MODERATORS
 

See Here, Here and Here for information about the current situation and the exploits being used.


UPDATE

Lemm.ee Admin @sunarus responded Here, TLDR is that Lemm.ee isn't vulnerable, would advise reading the message if you're still concerned.

top 24 comments
sorted by: hot top controversial new old
[–] sunaurus@lemm.ee 79 points 1 year ago* (last edited 1 year ago) (7 children)

Hey folks! I have spent this morning helping lemmy.world mitigate the issue. I have also sent out mitigation instructions to other admins as well.

For the particular exploit that was used on lemmy.world:

  1. It does not spread through federation
  2. lemm.ee was not vulnerable in the first place
  3. As mentioned above, it has already been mitigated on lemmy.world

So there should not be any reason to defederate. I will continue monitoring and investigating, if further vulnerabilities pop up then I will adjust accordingly.

[–] eee@lemm.ee 12 points 1 year ago

Thank you for being a valuable resource for the lemmyverse as a whole!

[–] aCosmicWave@lemm.ee 8 points 1 year ago (2 children)

You rock! Sorry if this is a stupid question, but if both instances are running the same version of Lemmy, why would lemmy.world be affected but not lemm.ee?

[–] fragmentcity@lemm.ee 9 points 1 year ago (1 children)

Malicious custom emoji contained scripts that sent session cookies to the attackers.

[–] aCosmicWave@lemm.ee 2 points 1 year ago

Makes sense! Thank you.

[–] TWeaK@lemm.ee 2 points 1 year ago

It should be said that the version number is more of an indication than anything specific. I don't think it would be hard for an instance to spoof its version number.

Also, lemm.ee in particular has a few mods and tricks that might not be in the lemmy codebase yet - @sunaurus@lemm.ee has previously included new code he has pushed to the main stack before it has been accepted. This allowed us to have working versions of things before other instances.

Point being, two instances with the same version can have different code and implementations.

[–] Deez@lemm.ee 7 points 1 year ago

Perfect! Thanks for all of your work to keep the Fediverse functioning. We appreciate you!

[–] Navarian@lemm.ee 5 points 1 year ago

Appreciate the response and explanation, I have ammended post and title to reflect that.

[–] kobra@lemm.ee 4 points 1 year ago (1 children)

Thinking about things in the future, if something were to happen to lemm.ee, how could users stay up to date with you and the other admins? do you have a mastodon account to follow or maybe matrix? for things like maintenance, emergencies, etc.

[–] sunaurus@lemm.ee 5 points 1 year ago

I'm thinking about doing some emergency updates on a Discord server - it seems like a huge amount of users have Discord anyway, so it might be the most convenient way. I'll probably make a post about it soon!

[–] dizzy@lemm.ee 3 points 1 year ago

Thank you very much for the explanation.

[–] LexiconDrexicon@lemm.ee 3 points 1 year ago

Can confirm, issue resolved

[–] zoe@lemm.ee 10 points 1 year ago (1 children)

this instance is really reliable. there is no shaking it! really glad to be here.

[–] MyOpinion@lemm.ee 8 points 1 year ago

This is the best instance I have been on so far. It just works.

[–] Deez@lemm.ee 8 points 1 year ago

I don’t know enough to agree/disagree, but upvoted for raising the point, and to give it attention.

[–] eee@lemm.ee 7 points 1 year ago (2 children)

How would a compromised instance affect us? The worst they can do is send spam posts.

[–] Navarian@lemm.ee 5 points 1 year ago

That would generally be something I'd prefer to avoid.

[–] ugh@lemm.ee 4 points 1 year ago

They're posting links that redirect to NSFW sites, and possibly Not Safe For Your Browser sites, as well. There could be phising links sent out next.

[–] BrikoX@lemmy.zip 4 points 1 year ago (2 children)

Both instance are down at the moment.

[–] Navarian@lemm.ee 3 points 1 year ago (1 children)

Indeed though it's still a bit up in the air who exactly has control of the instances, so they may come back online still compromised.

[–] BrikoX@lemmy.zip 7 points 1 year ago (1 children)

Looks to be that admin accounts were compromized by hijacking admin sessions, so the infrastructure is safe.

[–] Navarian@lemm.ee 1 points 1 year ago

Sincerely hope that's the case.

[–] ugh@lemm.ee 2 points 1 year ago

.world has already been down, back up, and down again. It might be smart until everything is resolved.

[–] ugh@lemm.ee 2 points 1 year ago

I agree. The NSFW instance already did this. We don't know the full extent of the breech or when it will end. .world already reopened once while still compromised.

I think defederation until we get an all clear from the admins of those instances would be a good measure to protect our users.

load more comments
view more: next ›