Conversation
Notices
-
(mint@ryona.agency)'s status on Thursday, 02-Mar-2023 17:55:26 JST bitch
Husky_1677747305158_7DV9YHXIJ9.…-
(mint@ryona.agency)'s status on Thursday, 02-Mar-2023 18:08:15 JST @bot Critical security changes in pleromer that I can't quickly merge through ssh on my phone due to the fact those fags updated mix.exs/lock and bundled frontend as well. -
bot :kiwi_dumbbell: (bot@seal.cafe)'s status on Thursday, 02-Mar-2023 18:08:16 JST bot :kiwi_dumbbell: What happened? -
(mint@ryona.agency)'s status on Thursday, 02-Mar-2023 18:11:46 JST @pedophilesoftwareinc @bot I have no fucking idea how this shit went unnoticed for six years. At least it shouldn't be able to escape from /var/lib/pleroma due to the user/group permissions. -
<script> alert("sogg"); </script> (pedophilesoftwareinc@cum.salon)'s status on Thursday, 02-Mar-2023 18:11:47 JST <script> alert("sogg"); </script> @mint @bot LOL -
🌲Number 1 Pleroma Criminal on XBL 🇵🇱|🇺🇸 (phenomx6@fedi.pawlicker.com)'s status on Thursday, 02-Mar-2023 18:16:01 JST 🌲Number 1 Pleroma Criminal on XBL 🇵🇱|🇺🇸 they were too busy finding out how to ban Alex Gleason from the project than they were fixing their shit likes this. -
(mint@ryona.agency)'s status on Thursday, 02-Mar-2023 18:41:08 JST @PhenomX6 @pedophilesoftwareinc @bot To be fair, it isn't fixed in soybox yet.
https://gitlab.com/soapbox-pub/rebased/-/blob/develop/lib/pleroma/web/activity_pub/activity_pub.ex#L1541🌲Number 1 Pleroma Criminal on XBL 🇵🇱|🇺🇸 likes this. -
ew (e@masochi.st)'s status on Thursday, 02-Mar-2023 18:48:47 JST ew @mint @pedophilesoftwareinc @bot close registrations immediately In conversation permalink -
(mint@ryona.agency)'s status on Thursday, 02-Mar-2023 18:48:47 JST @e @pedophilesoftwareinc @bot Just came back home and updated it. In conversation permalink -
(mint@ryona.agency)'s status on Thursday, 02-Mar-2023 18:58:24 JST @pomstan @pedophilesoftwareinc @bot No screening for ../ paths in uploader, apparently. Still not sure how it can be exploited since pleromer saves images with their hash instead of filename by default. In conversation permalink -
pomstan (pomstan@xn--p1abe3d.xn--80asehdb)'s status on Thursday, 02-Mar-2023 18:58:26 JST pomstan @mint @pedophilesoftwareinc @bot what’s the exact issue
In conversation permalink -
(mint@ryona.agency)'s status on Thursday, 02-Mar-2023 18:58:45 JST @pomstan @bot @pedophilesoftwareinc Apparently, Pleb managed to exploit in on poast and got IP banned. In conversation permalink -
<script> alert("sogg"); </script> (pedophilesoftwareinc@cum.salon)'s status on Thursday, 02-Mar-2023 19:00:32 JST <script> alert("sogg"); </script> @mint @bot @pomstan no, it was for this In conversation permalink Attachments
likes this. -
(mint@ryona.agency)'s status on Thursday, 02-Mar-2023 19:01:52 JST @pedophilesoftwareinc @bot @pomstan Ah, okay. The timing between posts was too good to not speculate on that. In conversation permalink -
(mint@ryona.agency)'s status on Thursday, 02-Mar-2023 19:02:29 JST @dc That's because I've replaced the frontend bundle with mine. Nothing critical, it's just something I'm not willing to fix over SSH from my phone. In conversation permalink -
big dog (dc@pl.starnix.network)'s status on Thursday, 02-Mar-2023 19:02:30 JST big dog @mint you were not able to just git check out? i need to update my server to so i want to make sure In conversation permalink -
meso (meso@asbestos.cafe)'s status on Thursday, 02-Mar-2023 19:04:19 JST meso @pedophilesoftwareinc @mint @bot @pomstan did :blackoma: fix it (>it didnt) In conversation permalink likes this. -
<script> alert("sogg"); </script> (pedophilesoftwareinc@cum.salon)'s status on Thursday, 02-Mar-2023 19:04:20 JST <script> alert("sogg"); </script> @meso @mint @bot @pomstan 2.5.1 pleroma update
relative file names, might be a non issue, but god knowsIn conversation permalink -
meso (meso@asbestos.cafe)'s status on Thursday, 02-Mar-2023 19:04:21 JST meso @mint @pedophilesoftwareinc @bot @pomstan wait what's the issue how to fix it In conversation permalink -
<script> alert("sogg"); </script> (pedophilesoftwareinc@cum.salon)'s status on Thursday, 02-Mar-2023 19:04:44 JST <script> alert("sogg"); </script> @meso @mint @bot @pomstan nope, not patched
https://akkoma.dev/AkkomaGang/akkoma/src/branch/develop/lib/pleroma/web/activity_pub/activity_pub.ex#L1505In conversation permalink Attachments
likes this. -
pomstan (pomstan@xn--p1abe3d.xn--80asehdb)'s status on Thursday, 02-Mar-2023 19:13:30 JST pomstan @mint @pedophilesoftwareinc @bot
No screening for ../ paths in uploader, apparently.
jesus christ, that’s an exploit right from the 1995 or something, older than most of pleroma users
In conversation permalink likes this.
-