this post was submitted on 10 Jul 2023
10 points (72.7% liked)

Lemmy.world Support

3216 readers
2 users here now

Lemmy.world Support

Welcome to the official Lemmy.world Support community! Post your issues or questions about Lemmy.world here.

This community is for issues related to the Lemmy World instance only. For Lemmy software requests or bug reports, please go to the Lemmy github page.

This community is subject to the rules defined here for lemmy.world.

To open a support ticket Static Badge


You can also DM https://lemmy.world/u/lwreport or email report@lemmy.world (PGP Supported) if you need to reach our directly to the admin team.


Follow us for server news ๐Ÿ˜

Outages ๐Ÿ”ฅ

https://status.lemmy.world



founded 1 year ago
MODERATORS
 

How did this breach happen?

What information was compromised?

Are admins present 24/7, or are they lumped into specific time zones?

What steps will be taken in the future to prevent breaches such as this?

top 3 comments
sorted by: hot top controversial new old
[โ€“] T156@lemmy.world 2 points 1 year ago (1 children)

How did this breach happen?

Bug in Lemmy-UI's custom emoji code that allowed for Javascript XSS to be run.

What information was compromised?

All of it. The end is nigh (!)

More realistically, account authentication tokens were scraped, by using that Javascript XSS to bounce through a site. It's also how they were redirected.

Are admins present 24/7, or are they lumped into specific time zones?

Since the server is hosted in Finland, I'd guess either European or American time zones, it tends to be either one of the two.

What steps will be taken in the future to prevent breaches such as this?

Literally nothing. Not much they can do about a bug inside of the web UI that causes an operator account to be compromised by using XSS to redirect to other sites, where the authentication token can be scraped.

You want to check with Lemmy developers for that, but I imagine that fixing the bug tends to be the best way of prevention.

[โ€“] Vupperware@lemmy.world 1 points 1 year ago

Thanks for the snark-free reply. Myself and other visitors of this community appreciate you!

[โ€“] a887dcd7a@lemmy.world 1 points 1 year ago

And why is OP unable to ask in a decent manner.. so many questions.