this post was submitted on 10 Jul 2023
19 points (95.2% liked)

sh.itjust.works Main Community

7733 readers
1 users here now

Home of the sh.itjust.works instance.

Matrix

founded 2 years ago
MODERATORS
19
Comment Exploit (lemmy.world)
submitted 1 year ago* (last edited 1 year ago) by [email protected] to c/main
 

Is there a write up for the Lemmy exploit that happened? Or can someone give me any specific? I’m a cybersecurity student and would like to learn a bit more.

EDIT: Awesome, thanks for the links guys!

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 11 points 1 year ago* (last edited 1 year ago) (1 children)

https://lemmy.world/post/1293336

Seems to be a pretty good summary? Feel free to ping me back if you need help understanding it.

Its a pretty straight forward XSS vulnerability. That basically means that the attacker got Javascript code execution upon the population, including the administrators. When you get Javascript execution, you almost always just steal cookies. Once the cookies to an administrator were stolen, then the admin-actions could be executed (such as changing the sidebar, making false posts / misinformation, etc. etc.)

[–] [email protected] 7 points 1 year ago* (last edited 1 year ago)

https://lemmy.world/post/1299831

This link, too. Both the prior comment and this link post say the same thing for the most part with some variations.