this post was submitted on 10 Jul 2023
52 points (100.0% liked)

Sopuli's Default Community

1258 readers
1 users here now

Community for all jibber-jabber. As this is a hard-coded community for every instance, we may get this doing something useful.

Simple test posts to [email protected]

Meta-discussion regarding the instance and support in problem situations [email protected]


Yhteisö kaikenlaiselle pälätykselle. Koska tämä on kovakoodattu yhteisö jokaiselle instanssille, voimme tehdä tällä ehkä jotain hyödyllistä.

Yksinkertaiset testiviestit mielellään [email protected]

Instanssia koskeva metakeskustelu ja tuki ongelmatilanteissa [email protected]

founded 3 years ago
MODERATORS
 

lemmy.world and lemmy.blahaj.zone got hacked, admins in sopuli.xyz should enforce 2fa for admins and possibly disable/ look into possible injections from the community sidebar

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 19 points 1 year ago* (last edited 1 year ago) (2 children)

I just enabled 2-factor authentication because of this. Script-kiddies are not gonna capture this instance!

[–] [email protected] 9 points 1 year ago* (last edited 1 year ago) (1 children)

It's highly unlikely 2FA is enough to mitigate this kind of an attack. It's a security vulnerability in lemmy itself, and they are stealing your access token instead of trying to log in as you.

edit: People, please, no reason to downvote admin ACKs. Just means they've at least read the message, after that, it's their instance and they'll do as they see fit.

[–] [email protected] 6 points 1 year ago (1 children)
[–] [email protected] 3 points 1 year ago (1 children)

Did Sopuli have any custom emojis enabled? Based on what I read about the hack the vulnerability was linked with those as detailed here.

[–] [email protected] 3 points 1 year ago (1 children)

Nope, there are no custom emojis.

[–] [email protected] 3 points 1 year ago (1 children)
[–] [email protected] 1 points 1 year ago

Once this vulnerability gets fixed, I could make a thread to [email protected] about suggesting custom emojis for Sopuli.

[–] [email protected] 7 points 1 year ago (1 children)

If they're stealing sessions that might not be enough. I saw some other mitigations discussed elsewhere.

[–] [email protected] 2 points 1 year ago* (last edited 1 year ago)

Create new accounts & make them instance admin instead (they have to make a local comment to be made admin). Then remove your "browsing" accounts from admin group until patched.