• armandtanzarianmusic@monyet.cc
    link
    fedilink
    arrow-up
    0
    ·
    1 year ago

    Downloaded a mobile version and now it sits next to my Reddit.

    Also tried Threads. Immediately got a bunch of Muslim accounts on For You. I don’t follow any on Instagram neither am I Muslim.

    Will wait till my feed stabilizes back to my usual diet of left wing shitposts and music memes.

  • Annoyed_🦀 @monyet.cc
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    1 year ago

    Shit, lemmy world got hacked, click on that Israel will lead you to explicit picture of a bunch of naked old man sucking each other, and also pop’s up lead to porn site.

    Avoid at all cost.

    • zen@monyet.cc
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      1 year ago

      this is bad. rumour has it this is due to an admin’s json web token being leaked.

      so I would advise all admins here not to log into 3rd party web apps (mobile apps should be okay) with their admin accounts, as the web apps usually proxy your requests (hence, they have your token), and they proxy not due to nefarious purposes, but due to some problem with cors (in other words, being forced to proxy your request isn’t really their fault, and once the cors problem is fixed in the lemmy backend, they can stop doing that).

    • ruk_n_rul@monyet.cc
      link
      fedilink
      arrow-up
      0
      arrow-down
      1
      ·
      edit-2
      1 year ago

      Goddammit. The fediverse drama continues.

      Btw admins it’s best that we defederate for the time being.

    • ruk_n_rul@monyet.cc
      link
      fedilink
      arrow-up
      0
      arrow-down
      1
      ·
      edit-2
      1 year ago

      https://kbin.social/m/[email protected]/t/168524/Lemmy-world-and-another-instance-have-been-compromised#entry-comment-661712

      The linked comment suggests that the entire Lemmy platform is currently vulnerable to the cookie stealing exploit that already happened to several instances.

      Now, if only we have automod that could detect code injection in markdown links and tempban offenders…