erre

joined 2 years ago
[–] erre@feddit.win 7 points 2 years ago

Looks like lemmy.blahaj.zone is back

https://lemmy.blahaj.zone/post/766402

[–] erre@feddit.win 3 points 2 years ago

Thanks for sharing! Forgot to look this up, tuned into the match late. That was a brutal hit. First time I see a ref injured.

[–] erre@feddit.win 8 points 2 years ago

Realizing this blew my mind. Definitely more interesting than following people.

[–] erre@feddit.win 9 points 2 years ago* (last edited 2 years ago) (2 children)

I'd wager you're likely fine if you're using a mobile app when the affected image loads. Also, it appears they're stealing auth tokens.. not passwords or anything. At worst they could impersonate you until your token expires.. but you're not a high value target unless you're an admin of an instance.

[–] erre@feddit.win 16 points 2 years ago

What kind of terrible markdown editor allows adding onload scripts to images though.. it's insane.

[–] erre@feddit.win 9 points 2 years ago* (last edited 2 years ago) (4 children)

If it's onload then simply viewing the image runs that script. Yikes.

[–] erre@feddit.win 20 points 2 years ago (3 children)

This is hilariously timed considering the current panic at the hacked instances.

[–] erre@feddit.win 6 points 2 years ago

Tough call, probably for the best. Hopefully it's resolved soon.

[–] erre@feddit.win 7 points 2 years ago
[–] erre@feddit.win 2 points 2 years ago

The sophistication is impressive, using emojis. Are people getting paid to find the vulnerabilities or are they just bored??

[–] erre@feddit.win 24 points 2 years ago* (last edited 2 years ago) (7 children)

I think they're stealing auth tokens, not sure if 2fa would help. It looks like there may be a vulnerability in the markdown editor and being able to insert JavaScript. The JS being able to access your cookies to share them is the second issue.

https://lemmy.sdf.org/comment/850269

[–] erre@feddit.win 6 points 2 years ago

Curl didn't return anything. They're likely just using it to log requests since the request path contains the data they need.

10
submitted 2 years ago* (last edited 2 years ago) by erre@feddit.win to c/lemmyconnect@lemmy.ca
 

When scrolling and reaching the end of the currently-loaded posts, Connect starts loading more posts but there is no visual indication of this. A user must keep trying to scroll down until they're loaded. It would be nice if a loading bar, spinner, etc. would display to inform the user that posts are loading.

TY!

 

Test

11
submitted 2 years ago* (last edited 2 years ago) by erre@feddit.win to c/lemmyconnect@lemmy.ca
 

Tapping the post form submit button results in an error that says to pick one of the ten communities listed which I guess are those that horizontally scroll under the "community name" form field. So I guess I can only post to those.. not sure why it's limited. It's a bug unless I missed a new setting.

I had to create this post using Jerboa 😞

Connect version 1.0.69. Also applies to 1.0.71.

 

My instance restarted while browsing Lemmy. The error message output is raw html rather than a user-friendly message.

Not a huge deal but wanted to point it out.

Version 1.0.69

73
Meet Moira (i.imgur.io)
submitted 2 years ago* (last edited 2 years ago) by erre@feddit.win to c/cat@lemmy.world
 

She's a little sweetheart.

 

I'm getting old and the morning coffee isn't doing anything for the crash after midday. It's also getting hot and I don't want an afternoon hot cup of coffee. I want to try making cold brew and it seems simple enough. Any tips?

So far I've seen 1:8 coffee to water recommended. 24 hours steeped and 2:1 water to concentrate. Sound ok? Any extra steps to make it twice as good?

20
Passion fruit!! (i.imgur.io)
submitted 2 years ago* (last edited 2 years ago) by erre@feddit.win to c/gardening@thegarden.land
 

cross-posted from: https://beehaw.org/post/911506

Turns out my passion flower plant is gonna give me fruit this year 🙂🙃🙂🙃

80
submitted 2 years ago* (last edited 2 years ago) by erre@feddit.win to c/android@lemmy.world
 

For me at least.

Looks like they enforced rate limits an hour before midnight UTC.

 

Thought this might be an interesting read for some.

13
submitted 2 years ago* (last edited 2 years ago) by erre@feddit.win to c/gardening@thegarden.land
 

cross-posted from: https://beehaw.org/post/790495

This is the first year it flowers, hoping to get fruit this year.

 

This is the first year it flowers, hoping to get fruit this year.

 

Not a fan of the change in format but still excited for top teams to be visiting the country.

view more: next ›