this post was submitted on 10 Jul 2023
3303 points (99.3% liked)

Lemmy.World Announcements

29165 readers
173 users here now

This Community is intended for posts about the Lemmy.world server by the admins.

Follow us for server news ๐Ÿ˜

Outages ๐Ÿ”ฅ

https://status.lemmy.world

For support with issues at Lemmy.world, go to the Lemmy.world Support community.

Support e-mail

Any support requests are best sent to [email protected] e-mail.

Report contact

Donations ๐Ÿ’—

If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.

If you can, please use / switch to Ko-Fi, it has the lowest fees for us

Ko-Fi (Donate)

Bunq (Donate)

Open Collective backers and sponsors

Patreon

Join the team

founded 2 years ago
MODERATORS
3303
submitted 1 year ago* (last edited 1 year ago) by ruud to c/lemmyworld
 

While I was asleep, apparently the site was hacked. Luckily, (big) part of the lemmy.world team is in US, and some early birds in EU also helped mitigate this.

As I am told, this was the issue:

  • There is an vulnerability which was exploited
  • Several people had their JWT cookies leaked, including at least one admin
  • Attackers started changing site settings and posting fake announcements etc

Our mitigations:

  • We removed the vulnerability
  • Deleted all comments and private messages that contained the exploit
  • Rotated JWT secret which invalidated all existing cookies

The vulnerability will be fixed by the Lemmy devs.

Details of the vulnerability are here

Many thanks for all that helped, and sorry for any inconvenience caused!

Update While we believe the admins accounts were what they were after, it could be that other users accounts were compromised. Your cookie could have been 'stolen' and the hacker could have had access to your account, creating posts and comments under your name, and accessing/changing your settings (which shows your e-mail).

For this, you would have had to be using lemmy.world at that time, and load a page that had the vulnerability in it.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] MarekKnapek 1 points 1 year ago (1 children)

mobile devices change IP addresses all the time

I never noticed this. Yes, switch between mobile and WiFi, but this is only two addresses. In case of IPv4 this seems not problem. In case of IPv6, use /64 or /48 (or whatever is now recommended for residential end users) prefix instead of the entire 128bits. I'm not proposing to log-out the suer after IP change, I'm proposing multiple sessions to be accessible at the same time.

[โ€“] linearchaos 1 points 1 year ago (1 children)

Mobile will often switch ip's on tower handoffs. If you're driving down the road or on a train, it's nothing to change mobile ip addresses every 2 minutes.

[โ€“] MarekKnapek 1 points 1 year ago (1 children)

Not in my experience. But OK, if this is the case, don't use exact IPv4 address, lookup the routing database and use the sub-net. Or whatever. This is belt & suspenders style of defense in depth, just another layer of security if all others fail. Not core functionality.

[โ€“] linearchaos 2 points 1 year ago

I work for a mobile game company. Millions of clients. We deal with this a lot. You can't even predict that they'll stay in the same class A. I wouldn't be surprised if they worked out a way to hand off ipv4 to 6 and vice-versa.

Then you have ISP's and large work networks who send everyone out under the same NAT/PAT, 10's of thousands of users all coming from one address.

IMO Providing a public service then trying to identify individuals by network without screwing someone over is a fools errand.

If you're dipping logs and see one jackass doing something on x IP, you always have to go back and see how many ip's that jackass is coming from and also how much viable traffic is coming from that ip.