this post was submitted on 10 Jul 2023
11 points (73.9% liked)
Lemmy.world Support
3227 readers
30 users here now
Lemmy.world Support
Welcome to the official Lemmy.world Support community! Post your issues or questions about Lemmy.world here.
This community is for issues related to the Lemmy World instance only. For Lemmy software requests or bug reports, please go to the Lemmy github page.
This community is subject to the rules defined here for lemmy.world.
You can also DM https://lemmy.world/u/lwreport or email [email protected] (PGP Supported) if you need to reach our directly to the admin team.
Follow us for server news ๐
Outages ๐ฅ
https://status.lemmy.world
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Bug in Lemmy-UI's custom emoji code that allowed for Javascript XSS to be run.
All of it. The end is nigh (!)
More realistically, account authentication tokens were scraped, by using that Javascript XSS to bounce through a site. It's also how they were redirected.
Since the server is hosted in Finland, I'd guess either European or American time zones, it tends to be either one of the two.
Literally nothing. Not much they can do about a bug inside of the web UI that causes an operator account to be compromised by using XSS to redirect to other sites, where the authentication token can be scraped.
You want to check with Lemmy developers for that, but I imagine that fixing the bug tends to be the best way of prevention.
Thanks for the snark-free reply. Myself and other visitors of this community appreciate you!