Hacker News new | past | comments | ask | show | jobs | submit login
Lemmy.world Defaced (lemmy.world)
25 points by k_roy on July 10, 2023 | hide | past | favorite | 6 comments



For anyone wondering, this was the fix for the vulnerability that allowed people to gain access: https://github.com/LemmyNet/lemmy-ui/pull/1897/files


Archived defaced version: https://archive.is/wbQ2f


Right now, lemmy.world seems to be switching between "Site has been seized by Reddit for copyright infringment" and a tasteless mp4


Looks like it was related to https://news.ycombinator.com/item?id=36664097. Absolutely ridiculous that the XSS vulnerability wasn't responsibly disclosed.


XSS vuln apparently: https://lemmy.ml/post/1896249


Its just down for me.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: