I hope they’ll finally give the player career mode some love. Pleaseeeeeee.
𝙚𝙧𝙧𝙚
- 3 Posts
- 46 Comments
𝙚𝙧𝙧𝙚@feddit.winto Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ@lemmy.dbzer0.com•Was piracy affected by the hijack?English9·2 years agoLooks like the instance is on the latest RC which includes the fix for the vulnerability.
𝙚𝙧𝙧𝙚@feddit.winto Selfhosted@lemmy.world•What hostname do you use for server? home.box or home.local?English11·2 years agoThe one reserved for residential usage is
home.arpa
.
𝙚𝙧𝙧𝙚@feddit.winto Lemmy.World Announcements@lemmy.world•Lemmy.world (and some others) were hacked3·2 years agoI think the lemmy.world admin posted on his official Mastodon.
𝙚𝙧𝙧𝙚@feddit.winto Lemmy.World Announcements@lemmy.world•Lemmy.world (and some others) were hacked7·2 years agoIf you run the instance only for yourself then I’d say it makes you an unattractive target. Why do a lot of work to hack an instance with one user?
But yeah, since Lemmy’s code is not super mature there’ll be some pains in the short term.
𝙚𝙧𝙧𝙚@feddit.winto Android@lemdro.id•Lemmy.world and another instance have been compromisedEnglish4·2 years agoOops indeed. Lemmy needs a security audit 😬
Looks like lemmy.blahaj.zone is back
𝙚𝙧𝙧𝙚@feddit.winto Football (migrated to football@sopuli.xyz) @lemmy.world•USA 0 - 0 Canada - Linesman takes ball to the face 1'English5·2 years agoThanks for sharing! Forgot to look this up, tuned into the match late. That was a brutal hit. First time I see a ref injured.
𝙚𝙧𝙧𝙚@feddit.winto Asklemmy@lemmy.ml•What are some interesting accounts to follow on Mastodon?11·2 years agoRealizing this blew my mind. Definitely more interesting than following people.
𝙚𝙧𝙧𝙚@feddit.winto Android@lemdro.id•Lemmy.world and another instance have been compromisedEnglish15·2 years agoI’d wager you’re likely fine if you’re using a mobile app when the affected image loads. Also, it appears they’re stealing auth tokens… not passwords or anything. At worst they could impersonate you until your token expires… but you’re not a high value target unless you’re an admin of an instance.
𝙚𝙧𝙧𝙚@feddit.winto Android@lemdro.id•Lemmy.world and another instance have been compromisedEnglish30·2 years agoWhat kind of terrible markdown editor allows adding onload scripts to images though… it’s insane.
𝙚𝙧𝙧𝙚@feddit.winto Android@lemdro.id•Lemmy.world and another instance have been compromisedEnglish19·2 years agoIf it’s
onload
then simply viewing the image runs that script. Yikes.
This is hilariously timed considering the current panic at the hacked instances.
𝙚𝙧𝙧𝙚@feddit.winto Fediverse@lemmy.ml•Beehaw is also down, but they elected to do itEnglish8·2 years agoTough call, probably for the best. Hopefully it’s resolved soon.
I think that’s right on the money.
The sophistication is impressive, using emojis. Are people getting paid to find the vulnerabilities or are they just bored??
𝙚𝙧𝙧𝙚@feddit.wintolemmy.ml meta@lemmy.ml•I'm going to assume the admins here all have 2FA on their accounts, right?32·2 years agoI think they’re stealing auth tokens, not sure if 2fa would help. It looks like there may be a vulnerability in the markdown editor and being able to insert JavaScript. The JS being able to access your cookies to share them is the second issue.
Curl didn’t return anything. They’re likely just using it to log requests since the request path contains the data they need.
I like that imgur removes exif data, any recommendations that do that too?
I took a look at a few posted and they don’t appear to do so.