this post was submitted on 10 Jul 2023
92 points (96.9% liked)

Lemmy.ca's Main Community

3037 readers
9 users here now


Welcome to the lemmy.ca/c/main community!

All new users on lemmy.ca are automatically subscribed to this community, so this is the place to read announcements, make suggestions, and chat about the goings-on of lemmy.ca.

For support requests specific to lemmy.ca, you can use !lemmy_ca_support@lemmy.ca.


founded 4 years ago
MODERATORS
92
Lemmy.world is compromised (talk.kururin.tech)
submitted 2 years ago* (last edited 2 years ago) by Kururin@talk.kururin.tech to c/main@lemmy.ca
 

They been redirecting to lemon party and some weird video. Do not go to the website. This is the admin that been hacked:

EDIT: lemmy.blahaj.zone also compromised!

top 34 comments
sorted by: hot top controversial new old
[–] TruckBC@lemmy.ca 53 points 2 years ago* (last edited 2 years ago) (5 children)

Out of precaution we will defederate from lemmy.world until this is resolved.

Edit: Lemmy.world has resolved the issue

[–] durablenapkin@lemmy.ca 3 points 2 years ago

I appreciate the proactivity/precaution!

[–] hawkwind@lemmy.management 2 points 2 years ago

It's unresolved.

[–] remotedev@lemmy.ca 2 points 2 years ago (1 children)

Have they resolved it? I can't comment there, or is that from this instance defederating from them? I don't have my lemmy.world account on this app

[–] TruckBC@lemmy.ca 3 points 2 years ago

We believe they have resolved it but we will remain defederated overnight.

[–] Roggie@lemmy.zip 2 points 2 years ago

It is once again comprised

[–] bioemerl@kbin.social 10 points 2 years ago

And this is why you use a password manager whenever you make new accounts on the internet.

If you had an account on the Lemmy.world website you need to change your password.

[–] Tugboater203@kbin.social 9 points 2 years ago (1 children)

It's still compromised, right now it's showing text that says site seized by reddit for copyright infringement. Lol. Jerboa is just showing Lemmy World heads

[–] Vampiric_Luma@lemmy.ca -2 points 2 years ago

*infringment

[–] Anon819450514@lemmy.ca 8 points 2 years ago

The page redirects is named Israel and it redirects to blank page with "This site was seized by Reddit for copyright infringement". So no, they don't have control yet.

[–] AnonymousLlama@kbin.social 8 points 2 years ago

Lemonparty! Now that's a name I haven't heard in ages 🍋🍋🍋👴

[–] solarzones@kbin.social 7 points 2 years ago

I am glad I’m on programming.dev for lemmy, but this could’ve happened to anyone. Hope nothing catastrophic happens

[–] thundercunt@lemm.ee 6 points 2 years ago (1 children)

First vlemmy now this? what the fuck is going on?

[–] thundercunt@lemm.ee 11 points 2 years ago* (last edited 2 years ago) (1 children)

this feels too intentional with two big servers in this short time frame icl

[–] zephyreks@lemmy.ca 2 points 2 years ago

Reddit gotta do what Reddit gotta do to keep their IPO alive

[–] sykccc@lemmy.ca 3 points 2 years ago

Looks like it’s gonna be a bit really put a lid on this, but I guess another sign why this is a good system?

[–] Izzy@lemmy.one 3 points 2 years ago

I was about to make a thread. Quite the bummer.

[–] ihavenopeopleskills@kbin.social 2 points 2 years ago* (last edited 2 years ago)

Thanks for the heads-up. Password changed.

[–] V699@kbin.social 2 points 2 years ago

I logged on and was like wtf because the site still works. Thought my phone was hacked heh

[–] mintiefresh@lemmy.ca 2 points 2 years ago

Yeah... I caught all that. Glad to see that they fixed it already though. Rough day for Rudd.

[–] PenguinTD@lemmy.ca 2 points 2 years ago (2 children)

Is there a way to not do email verification but still using 2FA? That way, even if a user's account is somehow phished/compromised, it won't compromise their other accounts.

[–] TruckBC@lemmy.ca 3 points 2 years ago

I just successfully set up 2FA for an account on another instance that doesn't have a verified email without any issues, so there's no need to have done email verification to use 2FA.

[–] elscallr@kbin.social 1 points 2 years ago

Absolutely you can do no phone/email and MFA. It's a TOTP thing like Google or Microsoft authenticator. The service doing the authentication has no idea how it's done on the other side, it just makes sure the codes match.

[–] FARTYSHARTBLAST@sh.itjust.works 1 points 2 years ago
[–] takina_soldpairtm@kbin.social 1 points 2 years ago

Man, after all that commenting and stuff I did... :(

[–] hawkwind@lemmy.management -4 points 2 years ago (1 children)

Guys, the new Israel lemmy instance has a lot of content I like, but some images I don't agree with. should we defederate?

[–] elscallr@kbin.social 2 points 2 years ago (1 children)

I don't think you realize what happened. The entire instance got fucked, it wasn't just some posts someone didn't like.

[–] hawkwind@lemmy.management 1 points 2 years ago

I was trying to by funny. :(

load more comments
view more: next ›