this post was submitted on 10 Jul 2023
356 points (99.2% liked)

Fediverse

17788 readers
3 users here now

A community dedicated to fediverse news and discussion.

Fediverse is a portmanteau of "federation" and "universe".

Getting started on Fediverse;

founded 5 years ago
MODERATORS
 

FYI!!! In case you start getting re-directed to porn sites.

Maybe the admin got hacked?


edit: lemmy.blahaj.zone has also been hacked.

you are viewing a single comment's thread
view the rest of the comments
[–] RoundSparrow@lemmy.ml 12 points 1 year ago (1 children)

The JWT are likely a hot issue, already some Issues on GitHub about them not being revoked properly.

[–] CMahaff@lemmy.ml 7 points 1 year ago (2 children)

Oh man, that would be brutal if they are resetting the password and it isn't kicking the attacker out...

[–] Max_P@lemmy.max-p.me 7 points 1 year ago

That's probably what happened here because they did revoke the admin's access, but it continued.

[–] RoundSparrow@lemmy.ml 5 points 1 year ago (1 children)
[–] CMahaff@lemmy.ml 5 points 1 year ago (1 children)

The issue does say changing the password should kick the user out, but yeah, still not good.

[–] RoundSparrow@lemmy.ml 5 points 1 year ago (1 children)

This issue from 2 weeks ago was the one I was thinking of, it's worse: https://github.com/LemmyNet/lemmy/issues/3364

[–] CMahaff@lemmy.ml 3 points 1 year ago* (last edited 1 year ago)

Oh man this one is SO much worse. If this is what is going on the only way to kick out the hacker will probably be to manually alter the DB. Yikes.

I hope the admin team is aware of this - not sure how one would even contact them.