If you are a lemmy.world user, log out and log back in to clear cookies!

Last night, lemmy.world was compromised via an XSS vulnerability with custom emoji. Using this vulnerability, attackers took control of an admin account. The site redirected to mp4 files when logged in, and porn sites when not logged in. The issue was resolved by lemmy.world admins soon after it started, but the attacker regained control of the compromised admin account around ten minutes after resolution, redirecting users to the same mp4 files and sites. Soon after that, the site became inaccessable. The issue is currently resolved, and lemmy dev team has been notified of this vulnerability. sh.itjust.works will not be affected, as we do not have any custom emojis. If you own an instance with custom emojis, it is advised to remove these emojis and clear your cookies.

The following is the original post:

PSA: DO NOT ATTEMPT TO ACCESS LEMMY.WORLD, THERE MIGHT BE MALWARE

Lemmy.world member here. I created this account after .world started redirecting me to porn sites and odd mp4 files. We might want to defederate to limit the potential impact. Also, SJW might be affected by the same vulnerabilities as .world, so maybe the admins here should look at that.

Edit: Situation seems to have stabilized. Some site icons aren’t loading, but otherwise everything seems stable. Read Edit2

Edit2: HOLY SHIT ITS BACK Read Edit3

Edit3: lemmy.world is now down as of 10:56 PM CST (USA) Read Edit4

Edit4: lemmy.world is now up, but serving an error as of 11:03 CST (USA) See a screenshot of this error. I also got logged out, hopefully it doesn’t mean they just wiped the databases lol.

Edit5: Edit4 still applies, but I can now access lemmy.world via Memmy on my phone. Wefwef (Voyager now) does not work, however. Timestamp: 11:34 PM CST (USA)

Edit6: lemmy.world restored. Compromised admin account said something in a weird post. I’m going to bed now, my brain is play-dough rn. Will update you guys tomorrow morning.

  • @SimplePhysics@sh.itjust.worksOP
    link
    fedilink
    English
    241 year ago

    Did you read my post? -I said there might be malware. -I said not to visit lemmy.world -The entire site may be fucking compromised. If you have control the servers, you can change database values to make your post any amount of upvotes you want.

    • @hemmes
      link
      English
      21 year ago

      Now let’s see if this goes the way VLemmy did this weekend.

        • @hemmes
          link
          English
          71 year ago

          Out of nowhere the instance went down. I believe it was late Saturday morning or so? It was my main instance and nobody has heard from the admin. He was always very enthusiastic and transparent, actively looking for more admins.

          A day or so before it went down, he made a post about having to defederate with another instance due to current violation laws in his server’s country of origin. VLemmy is known for not banning many (if any) instances in favor of moderation, so they take defederation very seriously.

          It looks like he got caught up with some bad content and had to shutdown. Not sure how long but all his tip and donation links have been closed including I believe his GitHub.

          • PixelPassport
            link
            fedilink
            31 year ago

            The donation links closing and silence from the admin definitely makes me think some kind of government shutdown.

            • @hemmes
              link
              English
              11 year ago

              That would be a fair statement