A number of Lemmy instances have been hacked overnight.

Some may remain inaccessible until they have been secured and restarted.

As a safety precaution logged-on sessions on many servers have been cancelled and you are required to logon again.

Unfortunately, the only way I could find to do this in Liftoff! is by going to Settings > Accounts and deleting each local account by long pressing on it, and then create it again.

All your posts, comments and bookmarks should be preserved during this process.

Please see the linked posts for further details as they emerge.

Thanks all, and please bear with us as this gets resolved.

  • jherazob
    link
    fedilink
    211 year ago

    This seems to be the issue, a code injection using custom emojis. Apparently Lemmy is letting some unsanitized data in, which means that Little Bobby Tables strikes again. Somebody was afraid the attackers had seized control of the whole Lemmy network but federation helps hinder the damage here, only individual instances are affected and they’d have to attack each one independently, a single server service would be fully affected in this case.

    Beehaw has fully taken down the server as a preventive measure, i imagine they won’t be the last ones doing this.

    • dismalnow
      link
      fedilink
      9
      edit-2
      1 year ago

      This makes me shudder from my time running forums.

      OOB vbulletin was notoriously bad at fending off sql injections, and required CONSTANT monitoring, tweaking, or disabling of basic features to keep the Syrian Liberation Army (as one particular example) from pwning an admin account.

      Also, and covered in detail, JWT should not be your default for sessions.

  • @TwinTurbo
    link
    English
    151 year ago

    Unfortunately, the only way I could find to do this in Liftoff! is by going to Settings > Accounts and deleting each local account by long pressing on it, and then create it again.

    Thanks! This is what I did and it worked fine.

    • @Cabeza2000
      link
      English
      11 year ago

      This was driving me crazy. :)

  • Vamp
    link
    English
    91 year ago

    Removed by mod

    • @myklM
      link
      English
      101 year ago

      That’s Team CET hard at work while America sleeps 😀

  • andre3000
    link
    fedilink
    71 year ago

    oh shit, is that what happened? i was so confused about what was going on last night. having just created my lemmy account.

  • @Skellybones
    link
    English
    71 year ago

    I manage to log back in my just by relogging my account. I thought I was banned or something

    • @myklM
      link
      English
      21 year ago

      Heh, I was sitting there for a few minutes this morning going “oh no what have I broken?” before I found out I could blame hackers.

      • @Skellybones
        link
        English
        21 year ago

        We’re in the big leagues now, we got hackers after us. Maybe it was some pissed off reddit user

  • @V4uban
    link
    English
    21 year ago

    Thank you for this!

  • @Lifecoach5000
    link
    English
    21 year ago

    I actually didn’t have to delete my existing lemmy.world account but I had to re-add it like it was a new account and log in and seemed to fixed it.