At a minimum they had some hacked web UI mayhem going on along with at least 1 admin account compromised…now they are in an at least partially down state. Might be worth alerting the Powers That Be to see if they want to offer assistance and if any measures should be taken to protect servers federated with it.

  • @darrsil@beehaw.org
    link
    fedilink
    English
    262 years ago

    I’m surprised I haven’t seen more posts yet about this. A rogue or compromised admin put JavaScript redirects on Lemmy.world as well as changed the name and some other things. The other admins removed the compromised admin, but then about 30 minutes later they were reinstated and started wreaking havoc again. The instance eventually went offline completely.

    • Fox
      link
      fedilink
      English
      192 years ago

      Thanks for the explanation. What terrible news…

      Seems we’re still in the early stages for this major happening, so I’m sure there will be more information released very shortly.

      I guess this goes to show why a federated networks are important, and why people shouldn’t flock to the most popular instance. Right now many communities are down because of this, while the ones that were wise enough to set up their own instances are unaffected.

      • db0
        link
        fedilink
        English
        22 years ago

        no that one seems to have abandoned lemmy

  • @astropenguin5@sopuli.xyz
    link
    fedilink
    English
    4
    edit-2
    2 years ago

    well that would explain the problem i had then! the error page redirected me to this community very helpfully. i was meaning to make another account on a smaller instance anyways, so not entirely bad

  • spitz
    link
    fedilink
    English
    02 years ago

    I deleted my .world account yesterday. Sorry if it’s a stupid question, but do I have to do anything about that? If so, what?

      • spitz
        link
        fedilink
        English
        12 years ago

        I got that much, but I don’t understand anything else. JavaScript injection? Is someone going to steal my deleted account or is that not possible?

        • ugh
          link
          fedilink
          English
          42 years ago

          From what I’ve read, links were redirecting to “shock” websites. It’s more of an old-internet Rick roll, but with gore type content instead of a silly music video. I don’t think we have to worry about data, but we’ll learn more in the next hour(s).

            • @TonyTonyChopper@mander.xyz
              link
              fedilink
              English
              12 years ago

              On another post they showed it was stealing browser cookies, so your login information for any site you’re logged into could be compromised. Definitely not a prank

              • spitz
                link
                fedilink
                English
                12 years ago

                So how does that effect a deleted account?