

I hope theyβll finally give the player career mode some love. Pleaseeeeeee.


I hope theyβll finally give the player career mode some love. Pleaseeeeeee.


Looks like the instance is on the latest RC which includes the fix for the vulnerability.


The one reserved for residential usage is home.arpa.


I think the lemmy.world admin posted on his official Mastodon.


If you run the instance only for yourself then Iβd say it makes you an unattractive target. Why do a lot of work to hack an instance with one user?
But yeah, since Lemmyβs code is not super mature thereβll be some pains in the short term.


Oops indeed. Lemmy needs a security audit π¬
Looks like lemmy.blahaj.zone is back


Thanks for sharing! Forgot to look this up, tuned into the match late. That was a brutal hit. First time I see a ref injured.


Realizing this blew my mind. Definitely more interesting than following people.


Iβd wager youβre likely fine if youβre using a mobile app when the affected image loads. Also, it appears theyβre stealing auth tokensβ¦ not passwords or anything. At worst they could impersonate you until your token expiresβ¦ but youβre not a high value target unless youβre an admin of an instance.


What kind of terrible markdown editor allows adding onload scripts to images thoughβ¦ itβs insane.


If itβs onload then simply viewing the image runs that script. Yikes.
This is hilariously timed considering the current panic at the hacked instances.


Tough call, probably for the best. Hopefully itβs resolved soon.
I think thatβs right on the money.
The sophistication is impressive, using emojis. Are people getting paid to find the vulnerabilities or are they just bored??

I think theyβre stealing auth tokens, not sure if 2fa would help. It looks like there may be a vulnerability in the markdown editor and being able to insert JavaScript. The JS being able to access your cookies to share them is the second issue.


Curl didnβt return anything. Theyβre likely just using it to log requests since the request path contains the data they need.
I like that imgur removes exif data, any recommendations that do that too?
I took a look at a few posted and they donβt appear to do so.