And inside hidden is JavaScript code that when executed can take cookie information and send it to a URL address.
Among other things. At this time if you see an image please click the icon circled before clicking the link. DO NOT CLICK THE IMAGE. If you see anything suspicious, please report it immediately.
It is better a false report than a missed one.
I have seen multiple posts by these people during the attack. It is most certainly related to JS.
That's even worse, if Lemmy has a vulnerability like that it needs to get fixed ASAP... Also if that code actually works, I am going to have to secure my account.
I'd wager you're likely fine if you're using a mobile app when the affected image loads. Also, it appears they're stealing auth tokens.. not passwords or anything. At worst they could impersonate you until your token expires.. but you're not a high value target unless you're an admin of an instance.
I used Firefox... So I definitely reset my password. Thing is I do not see an option for Lemmy where you can "sign out everywhere" which is the counter to Auth token stealing.
So I had to change it so that the Auth token would expire.
Whilst I am not an admin I won't take the chance. It could compromise other users and I do not want to take that risk.
the thing is right now lemmy by defaultNEVER expires the tokens... oops. Right now servers are manually expiring all their user's tokens by changing the secret in the database because of this attack.
Clicking the image isn't the issue, scrolling by it will nab your Auth tokens. Resetting your password will reset the Auth tokens protecting your account.
A sign out everywhere button would fix it but that isn't an option yet. It really needs to be.
Wtf how is this even possible? Are the Lemmy devs smoking crack? If you're going to run a reddit alternative, it may be wise to sanitize the fuck out of everything posted on there.
Not really helpful though is it? It's like going to a friend's house and asking why there is a sink hole in the middle of the floor that everyone is walking around, and they say "feel free get a hammer out".
It's more like when everyone is looking at the previously unknown hole and discussing how to patch it up and you start yelling how it is unacceptable as your friend's house is a "bar alternative"