If you are a lemmy.world user, log out and log back in to clear cookies!

Last night, lemmy.world was compromised via an XSS vulnerability with custom emoji. Using this vulnerability, attackers took control of an admin account. The site redirected to mp4 files when logged in, and porn sites when not logged in. The issue was resolved by lemmy.world admins soon after it started, but the attacker regained control of the compromised admin account around ten minutes after resolution, redirecting users to the same mp4 files and sites. Soon after that, the site became inaccessable. The issue is currently resolved, and lemmy dev team has been notified of this vulnerability. sh.itjust.works will not be affected, as we do not have any custom emojis. If you own an instance with custom emojis, it is advised to remove these emojis and clear your cookies.

The following is the original post:

PSA: DO NOT ATTEMPT TO ACCESS LEMMY.WORLD, THERE MIGHT BE MALWARE

Lemmy.world member here. I created this account after .world started redirecting me to porn sites and odd mp4 files. We might want to defederate to limit the potential impact. Also, SJW might be affected by the same vulnerabilities as .world, so maybe the admins here should look at that.

Edit: Situation seems to have stabilized. Some site icons aren’t loading, but otherwise everything seems stable. Read Edit2

Edit2: HOLY SHIT ITS BACK Read Edit3

Edit3: lemmy.world is now down as of 10:56 PM CST (USA) Read Edit4

Edit4: lemmy.world is now up, but serving an error as of 11:03 CST (USA) See a screenshot of this error. I also got logged out, hopefully it doesn’t mean they just wiped the databases lol.

Edit5: Edit4 still applies, but I can now access lemmy.world via Memmy on my phone. Wefwef (Voyager now) does not work, however. Timestamp: 11:34 PM CST (USA)

Edit6: lemmy.world restored. Compromised admin account said something in a weird post. I’m going to bed now, my brain is play-dough rn. Will update you guys tomorrow morning.

  • @[email protected]
    link
    fedilink
    English
    52 years ago

    Definitely need to bleach my eyes after that ‘attack’… saw it unfold and unfortunately saw too much.

    • @[email protected]
      link
      fedilink
      English
      32 years ago

      There are times when it pays to not be updated of what’s going on. This is one of those times. Sorry your eyes had to be subjected to that torture. My first experience with those sites were similar years ago. At work. Lmao fml

  • @[email protected]
    link
    fedilink
    English
    562 years ago

    What impact?

    As long as you dont go on lemmy.world, it’s not going to redirect you to all the stupid websites.

    And I doubt whatever they’re posting (if they’re posting anything) is getting upvoted, so you won’t see it anywhere else.

    And where are you getting “malware” from?

    People are acting like it’s some crazy hack, and not the 4chan rejects from exploding heads finally guessing an admins password a week after they got defederated. And after all that time chasing the mailman, they had no idea what to do when they guessed it

    But this does highlight an issue with instances. I doubt the handful of admins know each other. Like, maybe an email, but for the most part if shit like this happens during “off hours” it might be a while before the top admin even knows there’s an issue

    • bestdude
      link
      fedilink
      4
      edit-2
      2 years ago

      Could I get hacked or compromised or something just by lurking the website? I didn’t notice the Israel stuff until a bit late
      Password was randomly generated like 5f.4_0@3j&j so no common passwords

      • @[email protected]
        link
        fedilink
        English
        132 years ago

        And how many people answer that on Sunday night?

        What I’m getting at is a major website has at least a skeleton staff that can do something, even if that’s just pulling the plug.

        I don’t even reply to most work texts after hours unless it’s someone saying they have to use sick leave. I don’t expect people hosting Lemmy as a hobby to be on call 24/7.

        But I hope afterwards they’re transparent about what happened and how they’re going to stop it from happening again. If not, it’s easy to hop instances

    • @[email protected]OP
      link
      fedilink
      English
      112 years ago

      Did you read my post? -I said there might be malware. -I said not to visit lemmy.world -The entire site may be fucking compromised. If you have control the servers, you can change database values to make your post any amount of upvotes you want.

          • @[email protected]
            link
            fedilink
            English
            52 years ago

            Out of nowhere the instance went down. I believe it was late Saturday morning or so? It was my main instance and nobody has heard from the admin. He was always very enthusiastic and transparent, actively looking for more admins.

            A day or so before it went down, he made a post about having to defederate with another instance due to current violation laws in his server’s country of origin. VLemmy is known for not banning many (if any) instances in favor of moderation, so they take defederation very seriously.

            It looks like he got caught up with some bad content and had to shutdown. Not sure how long but all his tip and donation links have been closed including I believe his GitHub.

    • @[email protected]
      link
      fedilink
      English
      182 years ago

      Seems like there’s an active cookie-scraping attack going on. Lots of compromised accounts are going around different instances posting links with drive-by JavaScript. The JS tries to grab your current login token, which would give hackers access to your current login session.

      They don’t need your password because they’re just grabbing that cookie that your browser gets when you check the “Keep me logged in” checkbox on login. That’s what allows you to verify your account across multiple sessions, and it allows them to do the exact same thing. They can simply send that authorized token, and “log in” as you. This would (likely) work across instances, because if they grab your cookie then it will give them access to whatever instance your account is logged in on.

      So Lemmy.world will likely need to be completely defederated (to stop any compromised accounts from posting on other instances) and your specific instance will likely need to deauthorize all current login tokens (which will forcibly log everyone on your instance out) to stop any local accounts that got hit.

    • @[email protected]
      link
      fedilink
      English
      82 years ago

      That’s exactly what happened. And anyone complaining about vote rigging is probably from exploding-heads too.

  • randon31415
    link
    fedilink
    92 years ago

    Still getting the redirect at 3:30 AM UTC. Also, first post from my kbin backup.

    • minnieo
      link
      fedilink
      22 years ago

      welcome to kbin, sorry to hear about the happenings at your homebase

    • 567PrimeMover
      link
      fedilink
      182 years ago

      Yup, I got “this website has been seized by reddit for copyright infringment”. Very mature

    • @[email protected]OP
      link
      fedilink
      English
      82 years ago

      Damn. SJW and .world share the same lemmy source code. Could what is happening to .world happen to SJW? I’d take a dig into the lemmy code, but my brain is literal mush right now, its 11:16 PM here.

      • TWeaK
        link
        fedilink
        English
        92 years ago

        Potentially. Apparently it’s spreading through comments, not just the sidebar.

  • 🍹Early to RISA 🧉
    link
    fedilink
    English
    662 years ago

    Talk about feeling like the old internet. I was wondering how I would get tricked into seeing something gross by some shock-humor edgelord.

    Time to just grab a pint and wait this out. Lol

  • BitingChaos
    link
    fedilink
    252 years ago

    Well, on the bright side of things, I’m able to find out about my main server going down from the dozens of other active instances.

  • Sami
    link
    fedilink
    English
    5
    edit-2
    2 years ago

    I’m not seeing anything different with lemmy.world on my end. Can anyone else confirm what OP is seeing?

    Edit: Reading that it was resolved in another thread.

    Second edit: Nope, not resolved

    • Arotrios
      link
      fedilink
      14
      edit-2
      2 years ago

      Confirmed - fucked on my end too. Looks like the 18.1 update had some sort of major vulnerability.

    • randon31415
      link
      fedilink
      122 years ago

      I have a backup account on a backup instance. Still able to access 90% of the lemmyverse. When reddit’s main admin account was hacked by that hacker /u/spez, all of reddit went down, and they still haven’t fixed it.

      • minnieo
        link
        fedilink
        32 years ago

        that guy’s entire account is dedicated to sucking spez and reddit’s asshole, dont mind him

        • @[email protected]
          link
          fedilink
          English
          22 years ago

          What’s the end game? Bragging about being an “epic troll”? Laughing at “making socialists mad”?

          There’s no real benefit that doesn’t border on pathetic. What an interesting way to live life.

    • XiELEd
      link
      fedilink
      32 years ago

      Spez was the problem, not the reddit community.

        • XiELEd
          link
          fedilink
          7
          edit-2
          2 years ago

          Spez is free to do whatever, but he was such an asshole about it. Especially when he lied about Christian Selig blackmailing him, and when Christian Selig gave the call as proof that he didn’t, Spez tried to make him look the bad guy by accusing him of “leaking calls”… he even said before that he wouldn’t charge for API in 2023 but then he made an abrupt announcement that he would in ONE MONTH, with high fees. Developers would need time to readjust their app to optimise the use of API calls and one month is not enough. Why can’t Spez just be DIRECT that he wants to discontinue 3rd party apps? Why was he so wishy washy and vague instead of actually telling others what the hell he wants? Then he had some sort of fantasy where we are his “serfs”… which is kinda disgusting. Look man, I’ve only used 3rd party apps for a few months and could return to the official app with no difficulty, but I seriously don’t like being under that person. At least on the Fediverse I can choose who my admin is. (Kbin btw)

  • @[email protected]
    cake
    link
    fedilink
    English
    22 years ago

    Suddenly got kicked off the server and stuff. Was a panicky moment cause I’m on the work computer…is there any indication that malware etc. was involved?

    • @[email protected]OP
      link
      fedilink
      English
      22 years ago

      I don’t know. I’m running the latest version of Firefox, which does not have any publicly known severe vulnerabilities. I also happen to be running the latest version of macOS, and most malware target Windows. I have not seen any suspicious activity, so I think I’m good. I did harden my OS and browser a bit when I set things up, so that might have made a difference. I would run a scan with Malwarebytes if I were you. Good luck. Hopefully its just a troll.

  • @[email protected]
    link
    fedilink
    English
    162 years ago

    What’s the impact for other instance users ?

    None ? lemmy.world was down during the night and is fixed this morning that’s it ?

    is there a risk that interaction with lemmy.world are leaked including potential “personal data” ?

    is there a risk that smarter hackers could use the breach to access the DB behind some lemmy instances without anybody noticing it ?

    • @[email protected]OP
      link
      fedilink
      English
      42 years ago

      Lemmy.world was defaced last night. As far as I know, there is no DB breach. An XSS vulnerability was abused to steal the cookies of an admin account.

  • AndreTelevise
    link
    fedilink
    62 years ago

    And I have nowhere to go but Kbin because Beehaw is unstable and I don’t want to open up a fourth account. Accumulating fediverse accounts should be the last thing you do