this post was submitted on 09 Jul 2023
3 points (100.0% liked)

Café

779 readers
1 users here now

Welcome to our virtual third place, The Café.

Come on in and make a new human connection over a cup of coffee (or Teh Tarik). This is a casual community, do whatever you want, share your oyen pics, your frustrations, and even organize a weekend picnic with the community. The world is your oyster.

Rules are simple, be kind and civil with each other. As with any other café, rude patrons will be kicked out.

founded 2 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 3 points 2 years ago (1 children)

Downloaded a mobile version and now it sits next to my Reddit.

Also tried Threads. Immediately got a bunch of Muslim accounts on For You. I don't follow any on Instagram neither am I Muslim.

Will wait till my feed stabilizes back to my usual diet of left wing shitposts and music memes.

[–] [email protected] 2 points 2 years ago

You are lucky. I got half naked thirsty bros

[–] [email protected] 3 points 2 years ago

I wanna share my latest poem I made 2 weeks ago

King of Dirt

I eat myself full of dirt

Of the Dirt I thought I conquered

The dirt I thought I won over but in truth

It was nothing but an obvious case of denial and an overinflated ego

It is dirt borne of half baked resolve and clown juice

When will I learn to take things seriously

When will this dirt be the true works of my labour

Here I lay, reigning over these piles of dirt I've convinced myself I have

My magnum opus, the greatest king of all

My king of dirt

[–] [email protected] 3 points 2 years ago (1 children)

Shiet, sad that i have to work, reading the saucy stuff of lemmyworld hack is entertaining and educational.

[–] [email protected] 1 points 2 years ago

Anyone got saucy summary?

[–] [email protected] 2 points 2 years ago (1 children)

Did not expect my post to promote the Kdrama community to provoke anti-Lemmy posts, but this is Mastodon 🤣

[–] [email protected] 1 points 2 years ago

Keep promoting anyway. The more the merrier I say, any engagement is a good engagement when we're this small.

[–] [email protected] 2 points 2 years ago* (last edited 2 years ago)
[–] [email protected] 2 points 2 years ago (1 children)

looks like today's theme for me is search engines, already found:

  1. https://search-lemmy.com/ for searching lemmy
  2. https://searchengine.party/ for the usual web search engines
[–] esty 1 points 2 years ago (1 children)
[–] [email protected] 2 points 2 years ago (2 children)

hi, welcome to our humble community.

just curious, how did you find my post? was it through the lemmy search engine?

[–] esty 2 points 2 years ago

i found this community on browse.feddit.de and just happened to see this post c:

[–] [email protected] 1 points 2 years ago

welcome to all contents being federated everywhere!! :D

[–] [email protected] 1 points 2 years ago (10 children)

I'm still contemplating whether to buy a yukata for bon odori. But I don't think I will wear it much 😞

[–] [email protected] 3 points 2 years ago (1 children)

I saw a bunch of really nice ones in JJJ! If you're not against thrifting, do consider it!

[–] [email protected] 1 points 2 years ago (1 children)

What's JJJ? Sorry I never heard of that before 😂

[–] [email protected] 1 points 2 years ago (1 children)
[–] [email protected] 1 points 2 years ago

Thanks, let me check it out after work... Assuming I don't K.O.

[–] [email protected] 1 points 2 years ago (1 children)
[–] [email protected] 2 points 2 years ago

I found one on shopee for 50+, but only one colour choice. I like the design tho. Most yukatas on shopee Lazada average about RM70 from what I see

load more comments (7 replies)
[–] [email protected] 1 points 2 years ago* (last edited 2 years ago) (9 children)

Shit, lemmy world got hacked, click on that Israel will lead you to explicit picture of a bunch of naked old man sucking each other, and also pop's up lead to porn site.

Avoid at all cost.

[–] [email protected] 4 points 2 years ago* (last edited 2 years ago) (1 children)

this is bad. rumour has it this is due to an admin's json web token being leaked.

so I would advise all admins here not to log into 3rd party web apps (mobile apps should be okay) with their admin accounts, as the web apps usually proxy your requests (hence, they have your token), and they proxy not due to nefarious purposes, but due to some problem with cors (in other words, being forced to proxy your request isn't really their fault, and once the cors problem is fixed in the lemmy backend, they can stop doing that).

[–] [email protected] 1 points 2 years ago

Thanks Zen, you're a lifesaver. Brb pressing the emergency button

[–] [email protected] 2 points 2 years ago (1 children)

is it the lemon party picture?...........feels old.

welcome to pre-rickroll internet.

[–] [email protected] 1 points 2 years ago (1 children)

Ahh, that's what it called, no wonder it's somehow familiar.

[–] [email protected] 3 points 2 years ago* (last edited 2 years ago) (1 children)

now I'm hearing that the hack is being spread through direct messages as well.

as this seems to be a javascript hack, all admins logged on through any web ui (even the official one) are advised to not open dm's from unknown users.

as mobile apps differ from browsers, and shouldn't execute javascript directly, they should be less affected, but please take caution anyway for the time being.

edit: it seems lemmy.blahaj.zone has been hacked too. the malicious javascript has been detected in custom emojis and community description sidebars, so admins must watch out for new users who signup and immediately start posting custom emojis or opening new communities.

[–] [email protected] 1 points 2 years ago (1 children)

Merely open the dm? Or do we have to click the link for it to happen?

[–] [email protected] 1 points 2 years ago* (last edited 2 years ago) (2 children)

I think it is better to not open it at all (at least in the web browser, mobile apps seem to be okay, but nothing is really certain atm), as the malicious javascript seem to be connected to custom emojis and community descriptions in the sidebar (see my latest edit), so no clicking required.

[–] [email protected] 1 points 2 years ago

damn, i feel like we can check off one success criteria: suddenly so attractive for hacks.

[–] [email protected] 1 points 2 years ago

Alright, got it. Thanks!

[–] [email protected] 1 points 2 years ago (1 children)

https://github.com/LemmyNet/lemmy-ui/issues/1895 has more information on mitigations, which may not be necessary if no custom emojis were added.

it also has something for invalidating all json web tokens by changing the signing key (all users will need to re-login after doing that), which may be necessary depending on whether the tech team believes any of them (especially any of the admin's) have been compromised (there is currently no expiry date on the tokens).

#lemmyworldhacked #fediversedrama

[–] [email protected] 1 points 2 years ago

Thanks, i'm giving it a read but i'm not coding literate so may need some time to parse 😂

load more comments (5 replies)
[–] [email protected] 1 points 2 years ago

In "Aladdin" (1992), Jaafar has a great nugget of wisdom:

"You've heard of the Golden Rule, haven't you? Whoever has the gold, makes the rules."

He also has a misogynistic but witty quote:

"You are speechless I see. A fine quality in a wife!"

load more comments
view more: next ›