this post was submitted on 12 Jul 2023
125 points (91.9% liked)

Fediverse

29576 readers
4366 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to [email protected]!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy

founded 2 years ago
MODERATORS
125
wtf is happening? (self.fediverse)
submitted 2 years ago* (last edited 2 years ago) by Rockfury to c/fediverse
 

Why am I signed out every time I open this? Why can I hardly post anything anywhere? It's like a dice roll.

you are viewing a single comment's thread
view the rest of the comments
[–] fubo 14 points 2 years ago (2 children)

Server-side authentication bug; maybe fallout from the recent attack? I'd expect instability for the next day or so as auth & related problems shake out.

[–] Rockfury 1 points 2 years ago (1 children)

Attack? I am outta the loop. What happened?

[–] fubo 3 points 2 years ago* (last edited 2 years ago) (1 children)

https://lemmy.world/post/1290412

Summary: Attacker found a way to inject JavaScript into the sidebar, letting them steal auth tokens ("JWTs"), including from an admin account. They then used the stolen admin access to vandalize the site. At one point, the attacker used the stolen admin account to falsely announce that the attack had been remediated. Later that day, the attack actually was remediated by the site owner (Ruud) and the vulnerability was patched in the Lemmy code.

[–] Rockfury 1 points 2 years ago

Appreciate the info.