If you are a lemmy.world user, log out and log back in to clear cookies!
Last night, lemmy.world was compromised via an XSS vulnerability with custom emoji. Using this vulnerability, attackers took control of an admin account. The site redirected to mp4 files when logged in, and porn sites when not logged in. The issue was resolved by lemmy.world admins soon after it started, but the attacker regained control of the compromised admin account around ten minutes after resolution, redirecting users to the same mp4 files and sites. Soon after that, the site became inaccessable. The issue is currently resolved, and lemmy dev team has been notified of this vulnerability. sh.itjust.works will not be affected, as we do not have any custom emojis. If you own an instance with custom emojis, it is advised to remove these emojis and clear your cookies.
The following is the original post:
PSA: DO NOT ATTEMPT TO ACCESS LEMMY.WORLD, THERE MIGHT BE MALWARE
Lemmy.world member here. I created this account after .world started redirecting me to porn sites and odd mp4 files. We might want to defederate to limit the potential impact. Also, SJW might be affected by the same vulnerabilities as .world, so maybe the admins here should look at that.
Edit: Situation seems to have stabilized. Some site icons aren't loading, but otherwise everything seems stable. Read Edit2
Edit2: HOLY SHIT ITS BACK Read Edit3
Edit3: lemmy.world is now down as of 10:56 PM CST (USA) Read Edit4
Edit4: lemmy.world is now up, but serving an error as of 11:03 CST (USA) See a screenshot of this error. I also got logged out, hopefully it doesn't mean they just wiped the databases lol.
Edit5: Edit4 still applies, but I can now access lemmy.world via Memmy on my phone. Wefwef (Voyager now) does not work, however. Timestamp: 11:34 PM CST (USA)
Edit6: lemmy.world restored. Compromised admin account said something in a weird post. I'm going to bed now, my brain is play-dough rn. Will update you guys tomorrow morning.
The vulnerability appeared to be from a custom emoji that they were running. SJW does not use any custom emoji so we should not be affected. In either case lemmy.world has now been restored and is back online. I’ll keep an extra eye on this instance until the patch gets released shortly.
As long as you dont go on lemmy.world, it's not going to redirect you to all the stupid websites.
And I doubt whatever they're posting (if they're posting anything) is getting upvoted, so you won't see it anywhere else.
And where are you getting "malware" from?
People are acting like it's some crazy hack, and not the 4chan rejects from exploding heads finally guessing an admins password a week after they got defederated. And after all that time chasing the mailman, they had no idea what to do when they guessed it
But this does highlight an issue with instances. I doubt the handful of admins know each other. Like, maybe an email, but for the most part if shit like this happens during "off hours" it might be a while before the top admin even knows there's an issue
Seems like there’s an active cookie-scraping attack going on. Lots of compromised accounts are going around different instances posting links with drive-by JavaScript. The JS tries to grab your current login token, which would give hackers access to your current login session.
They don’t need your password because they’re just grabbing that cookie that your browser gets when you check the “Keep me logged in” checkbox on login. That’s what allows you to verify your account across multiple sessions, and it allows them to do the exact same thing. They can simply send that authorized token, and “log in” as you. This would (likely) work across instances, because if they grab your cookie then it will give them access to whatever instance your account is logged in on.
So Lemmy.world will likely need to be completely defederated (to stop any compromised accounts from posting on other instances) and your specific instance will likely need to deauthorize all current login tokens (which will forcibly log everyone on your instance out) to stop any local accounts that got hit.
Did you read my post?
-I said there might be malware.
-I said not to visit lemmy.world
-The entire site may be fucking compromised. If you have control the servers, you can change database values to make your post any amount of upvotes you want.
https://sh.itjust.works/post/923025 The comments in this post explain it better than I can, but this seems like a much bigger issue than an admin account being compromised.
What I'm getting at is a major website has at least a skeleton staff that can do something, even if that's just pulling the plug.
I don't even reply to most work texts after hours unless it's someone saying they have to use sick leave. I don't expect people hosting Lemmy as a hobby to be on call 24/7.
But I hope afterwards they're transparent about what happened and how they're going to stop it from happening again. If not, it's easy to hop instances
Could I get hacked or compromised or something just by lurking the website? I didn't notice the Israel stuff until a bit late
Password was randomly generated like 5f.4_0@3j&j so no common passwords
Damn. SJW and .world share the same lemmy source code. Could what is happening to .world happen to SJW? I'd take a dig into the lemmy code, but my brain is literal mush right now, its 11:16 PM here.
About 10:38 pm CST I had just opened it on my browser and it flashed a "Reddit has taken over this site for copyright infringement". And the icon at the top was changed for Israel with the words about raping a child on it. Definitely something wonky going on, but I haven't seen any redirects to anything off site. Definitely not going back from my computer (sounds like the app is safe, but only will check for an update).
Yeah, I get that too, minus the Reddit part. However, during the ten minute span where the attack was resolved (then restarted), a mod/admin account reported that it was caused by a compromised admin account, so not Reddit taking over the site via copyright law. They removed the account, but the issue seems to be back now.
And I have nowhere to go but Kbin because Beehaw is unstable and I don't want to open up a fourth account. Accumulating fediverse accounts should be the last thing you do
There are times when it pays to not be updated of what's going on. This is one of those times. Sorry your eyes had to be subjected to that torture. My first experience with those sites were similar years ago. At work. Lmao fml
Single 🔧 vs Federated ActivityPub instance, who wins
😂😂
Side note: glad the lemmy devs and mods able to figure it out and all while doing this part time. Great community yall. Hope to contribute my time as well.
An admin had their account compromised. The other admins have since fixed the account and everything should be operational again.
EDIT: Well the site's still down while they clean up the mess that was left behind. But I think the root problem is fixed now. Should be just a matter of time before they flip the switch again.
A .world mod/admin mentioned a compromised admin account. They removed the account, but the issue returned soon after I made the first edit to the post.
Suddenly got kicked off the server and stuff. Was a panicky moment cause I'm on the work computer...is there any indication that malware etc. was involved?
I don't know. I'm running the latest version of Firefox, which does not have any publicly known severe vulnerabilities. I also happen to be running the latest version of macOS, and most malware target Windows. I have not seen any suspicious activity, so I think I'm good. I did harden my OS and browser a bit when I set things up, so that might have made a difference. I would run a scan with Malwarebytes if I were you. Good luck. Hopefully its just a troll.
I doubt 2FA would've helped in this situation since those assholes had access to the admin accounts and there server. I don't know. Good thing I'm signed up to another instance.
I have a backup account on a backup instance. Still able to access 90% of the lemmyverse. When reddit's main admin account was hacked by that hacker /u/spez, all of reddit went down, and they still haven't fixed it.
a small but loud, delusional, and entitled subsection of the reddit community was the problem. they are the ones that shut down the subreddits and inserted nsfw content which ruined reddit for the other 97% of users
spez has the authority to make changes to the reddit terms of use, but i suppose feces-smearing toddlers wouldn't understand that