Jump in the discussion.

No email address required.

looks like it's an exploit in the emojis or something. you know how in markdown image :marseymissing2: links you can provide alt text? well apparently the lemmy code just smacked the text into the HTML without doing any sort of check.

so you could do something like

![alt text" onload="evil();"](https://rdrama.net/e/marseyscared.webp)

and it'd essentially render :marseyraytraced: the HTML as

<img src="https://rdrama.net/e/marseyscared.webp" alt="alt text" onload="evil();">

this was used to send multiple requests to some website that is bitching about Ukraine :marseyukrainerentfree: (I'm not even joking :marseybeanwink: here, screenshot below) with your cookies.

https://i.imgur.com/lRYWRyD_d.webp?maxwidth=9999&fidelity=grand

it also apprently checks for a specific element in the page that would :marseymid: indicate the user is an admin. apparently they don't set HttpOnly on their cookies, so this script was able to just raid the user's cookie :marseygingerbread3: jar. all and all, seems pretty :marseyglam: bad.

Jump in the discussion.

No email address required.

lol of course emojis in lemmy need to have alt text

god forbid all the disabled blind lgbtqia+ members browsing lemmy in a text based browser can't understand a meme

Jump in the discussion.

No email address required.

so two lemmy instances were hacked, do we know if it was some sort of lemmy vuln or just bad passwords?

EDIT: looks like simple XSS

https://lemmy.ml/post/1896249

Jump in the discussion.

No email address required.

devs will use rust to prevent memory issues but can't prevent simple xss :marseylaughpoundfist:

Jump in the discussion.

No email address required.

Hmm today I will interpret unsanitized inputs :marseyclueless:

Jump in the discussion.

No email address required.

Wouldn't have happened if they'd used rust for the frontend :marseyravegigaspeed:

Jump in the discussion.

No email address required.

rust frontend with webassembly :marseyflushzoom:

Jump in the discussion.

No email address required.

controversial opinion but if your program is meant to run natively and on the web then a rust frontend is the only good choice from a technical standpoint

sure rust is dogshit for writing ui but a frontend library which can run natively on wasm and raw hardware is objectively superior to electron cancer

Jump in the discussion.

No email address required.

I know it's considered a meme language especially around here for all the :marseytrain: shit but I still think Rust is a really solid programming language, and I'd love to be able to program in Rust rather than C++ for my day job.

Jump in the discussion.

No email address required.

:#marseystare:

:#marseyropeyourself:

but also, https://tauri.app/

Jump in the discussion.

No email address required.

tauri is better but still inefficient compared to native performance

a language that's memory safe and isn't ugly would unironically be better than javascript for writing frontend cross platform, fight me

Jump in the discussion.

No email address required.

tbh Lemmy could reimplement itself in python and still get better performance

Jump in the discussion.

No email address required.

sorry but python isn't 🚀 blazing fast 🚀

Jump in the discussion.

No email address required.

They forgot not everybody is moral, and that you shouldn't let your users decide where to look for a butthole emoji

Jump in the discussion.

No email address required.

>looks like simple XSS

Do rustBIPOCs really:marseylaugh:

Jump in the discussion.

No email address required.

This is what happens when you don't have Egyptians

:#capylove:

Jump in the discussion.

No email address required.

https://media.giphy.com/media/S3J6h7dVlM76/giphy.webp

:!#capywalking:

Jump in the discussion.

No email address required.

Or a CIA honeypot

Jump in the discussion.

No email address required.

isn't lemmings that british game where you dig around with those little guys :#boomermonster:

https://i.rdrama.net/images/16889673200602074.webp

Jump in the discussion.

No email address required.

Want to be sad? Here's what modern Lemmings looks like

https://play.google.com/store/apps/details?id=com.sadpuppy.lemmings&hl=en_US&gl=US

Jump in the discussion.

No email address required.

:#brookslaugh:

Jump in the discussion.

No email address required.

Soulless mobile game art

Jump in the discussion.

No email address required.

Actually looks dope thanks friend

Jump in the discussion.

No email address required.

People complained about All New World as well

Although it was pretty easy, I thought it was underrated

Not touching the mobile game tho

Jump in the discussion.

No email address required.

that was a good game

Jump in the discussion.

No email address required.

I still have an early 90s monochromatic brick laptop with Lemmings installed. Sadly it did not work last time I tried to play it.

It was a fun game, seems pretty inventive for the time it was created.

Jump in the discussion.

No email address required.

https://playclassic.games/games/puzzle-solving-dos-games-online/play-lemmings-online/play/

:marseyretro:

Jump in the discussion.

No email address required.

For a moment I thought it was a glowie Marsey, and the link was meant to steal my Ip.

But it's legit, and the game is even in colour, nice.

Jump in the discussion.

No email address required.

Well that was quick.

Jump in the discussion.

No email address required.

Why is everyone on redditalternatives such strags :marseyeyeroll:

Jump in the discussion.

No email address required.

They're all the cute twink :marseyhomosupremacist: mods who think :marseynooticeglow: they can coral their imaginary userbase onto a new site to strag out on them since they can't do it on reddit :marseychristmasbeheadsnoo: anymore

Unlike rdrama, they literally :marseyme: have nothing :marseynothingburger: to offer :marseyholdingcoin: except for an exponentially increased amount of soy cute twinkry squared

Jump in the discussion.

No email address required.

That sub wasn't too active until this past month when all the seething :marseyoverseether: redditors :marseysoypoint2: invaded it.

Jump in the discussion.

No email address required.

LOL I can imagine that, it was quite chuddy when I used it a couple of years ago and might be how I found rdrama

Jump in the discussion.

No email address required.

The first hack is a rite of passage for every site that gets big. It means we’ve been recognized!

Yeah, it wasn't the shit-ton of redditors in every thread on the front page for the past 6 weeks who mentioned lemmy that makes you feel noticed, it's being ddosed :#marseyeyeroll:

https://media.giphy.com/media/l3q2K5jinAlChoCLS/giphy.webp

Edit: the redditstrags on redditalternatives couldn't even type "neighbor" without censoring omfg what is happening in the internet 🤣

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

The entire internet is gonna be fricked for a decade before we experience another period of stability like we just had.

Lol they think anyone at all noticed Reddit had an issue

More people noticed Twitter but everyone whining about it seems to be still on Twitter just as much. I’m skeptical of threads myself.

Jump in the discussion.

No email address required.

REDDIT HAS FALLEN, BILLIONS TRILLIONS QUADRILLIONS MUST DIE

TRANS LIVES MATTER

Jump in the discussion.

No email address required.

Lemmy fricking sucks nuts

Jump in the discussion.

No email address required.

Unironically this

Jump in the discussion.

No email address required.

it must take a real genius to create a good alternative to reddit :marseyhmm#:

Jump in the discussion.

No email address required.

https://i.rdrama.net/images/16889733263696063.webp

Heres a spicy meme about how they got hacked through a xss attack on the back end

Jump in the discussion.

No email address required.

Right now, lemmy.world seems to be switching between "Site has been seized by Reddit for copyright infringment" and a tasteless mp4

what was the mp4? :marseyhmm:

Jump in the discussion.

No email address required.

carp aevann pls pin

Jump in the discussion.

No email address required.

:car#phug:

Jump in the discussion.

No email address required.

"Lemmy.blahaj.zone"?

🎵 :marseytrain: shark, do do do do do do, :marseytrain: shark, do do do do 🎵

Jump in the discussion.

No email address required.

I heard it was hacked by the folks that killed ruqqus :#marseygossipsmug:

Jump in the discussion.

No email address required.

Right now, lemmy.world seems to be switching between "Site has been seized by Reddit for copyright infringment" and a tasteless mp4

what was the tasteless mp4?

Jump in the discussion.

No email address required.

Dancingswede perhaps?

Jump in the discussion.

No email address required.

I don't know what this entails but if redditors dislike it then I approve

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

Lmao you could load arbitrary code via the custom emoji feature?

Looks like JS devs are just as retarded as our snek devs. They're even using attrs as a prop name so they've definitely been writing shit python code too

Jump in the discussion.

No email address required.

Shut up,I am more important than this stupid post.. ....

Jump in the discussion.

No email address required.

I'm sure all the jannies that took their ball from reddit and went to lemmy totaly dont regret their decision to stay in that shithole.

Jump in the discussion.

No email address required.

Wtf this has nothing to do with Motorhead

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.