GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
     (mint@ryona.agency)'s status on Thursday, 02-Mar-2023 18:00:45 JST  
    bitch
    Husky_1677747305158_7DV9YHXIJ9.…
    In conversation Thursday, 02-Mar-2023 18:00:45 JST from ryona.agency permalink

    Attachments


    1. https://ryona.agency/media/d3af7dddb0c4778ef143eb1df750577df06997f918f271a4f3972f14222abe5a.png?name=Husky_1677747305158_7DV9YHXIJ9.png
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 02-Mar-2023 18:00:44 JST Fediverse Contractor Fediverse Contractor
      in reply to
      What happened?
      In conversation Thursday, 02-Mar-2023 18:00:44 JST permalink
    • Embed this notice
       (mint@ryona.agency)'s status on Thursday, 02-Mar-2023 18:13:57 JST  
      in reply to
      • Fediverse Contractor
      @bot Critical security changes in pleromer that I can't quickly merge through ssh on my phone due to the fact those fags updated mix.exs/lock and bundled frontend as well.
      In conversation Thursday, 02-Mar-2023 18:13:57 JST permalink
      Fediverse Contractor likes this.
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 02-Mar-2023 18:15:23 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • :SOGG: ing
      What is this capable of doing exactly?
      In conversation Thursday, 02-Mar-2023 18:15:23 JST permalink
    • Embed this notice
       (mint@ryona.agency)'s status on Thursday, 02-Mar-2023 18:15:24 JST  
      in reply to
      • Fediverse Contractor
      • :SOGG: ing
      @pedophilesoftwareinc @bot I have no fucking idea how this shit went unnoticed for six years. At least it shouldn't be able to escape from /var/lib/pleroma due to the user/group permissions.
      In conversation Thursday, 02-Mar-2023 18:15:24 JST permalink
    • Embed this notice
      :SOGG: ing (pedophilesoftwareinc@cum.salon)'s status on Thursday, 02-Mar-2023 18:15:25 JST :SOGG: ing :SOGG: ing
      in reply to
      • Fediverse Contractor
      @mint @bot LOL
      In conversation Thursday, 02-Mar-2023 18:15:25 JST permalink

      Attachments


      1. https://cum.salon/media/cde0563777e2f1dfd0f4686864d4912b167111006f4cef01574ef96fb91b6537.png
    • Embed this notice
      ew (e@masochi.st)'s status on Thursday, 02-Mar-2023 18:21:43 JST ew ew
      in reply to
      • Fediverse Contractor
      • :SOGG: ing
      @mint @pedophilesoftwareinc @bot close registrations immediately
      In conversation Thursday, 02-Mar-2023 18:21:43 JST permalink
    • Embed this notice
      :SOGG: ing (pedophilesoftwareinc@cum.salon)'s status on Thursday, 02-Mar-2023 18:26:38 JST :SOGG: ing :SOGG: ing
      in reply to
      • tusooa :Cat_girls_Emoji_004: 西风
      • Fediverse Contractor
      @bot @mint read/write arbitrary files via the pleroma user most likely

      this was authored two months ago and only now merged
      unless @tusooa can clarify and calm some FUD down

      >Security: uploading HTTP endpoint can no longer create directories in the upload dir
      In conversation Thursday, 02-Mar-2023 18:26:38 JST permalink
      Fediverse Contractor likes this.
    • Embed this notice
       (mint@ryona.agency)'s status on Thursday, 02-Mar-2023 18:51:20 JST  
      in reply to
      • ew
      • Fediverse Contractor
      • :SOGG: ing
      @e @pedophilesoftwareinc @bot Just came back home and updated it.
      In conversation Thursday, 02-Mar-2023 18:51:20 JST permalink
      Fediverse Contractor likes this.
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 02-Mar-2023 19:01:46 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • pomstan
      • meso
      • :SOGG: ing
      It’s too late, I already hacked your server nerd.
      In conversation Thursday, 02-Mar-2023 19:01:46 JST permalink
    • Embed this notice
      meso (meso@asbestos.cafe)'s status on Thursday, 02-Mar-2023 19:01:47 JST meso meso
      in reply to
      • pomstan
      • Fediverse Contractor
      • :SOGG: ing
      @mint @pedophilesoftwareinc @bot @pomstan wait what's the issue how to fix it
      In conversation Thursday, 02-Mar-2023 19:01:47 JST permalink
    • Embed this notice
       (mint@ryona.agency)'s status on Thursday, 02-Mar-2023 19:01:48 JST  
      in reply to
      • pomstan
      • Fediverse Contractor
      • :SOGG: ing
      @pomstan @pedophilesoftwareinc @bot No screening for ../ paths in uploader, apparently. Still not sure how it can be exploited since pleromer saves images with their hash instead of filename by default.
      In conversation Thursday, 02-Mar-2023 19:01:48 JST permalink
    • Embed this notice
       (mint@ryona.agency)'s status on Thursday, 02-Mar-2023 19:01:48 JST  
      in reply to
      • pomstan
      • Fediverse Contractor
      • :SOGG: ing
      @pomstan @bot @pedophilesoftwareinc Apparently, Pleb managed to exploit in on poast and got IP banned.
      In conversation Thursday, 02-Mar-2023 19:01:48 JST permalink
    • Embed this notice
      pomstan (pomstan@xn--p1abe3d.xn--80asehdb)'s status on Thursday, 02-Mar-2023 19:01:49 JST pomstan pomstan
      in reply to
      • Fediverse Contractor
      • :SOGG: ing

      @mint @pedophilesoftwareinc @bot what’s the exact issue

      In conversation Thursday, 02-Mar-2023 19:01:49 JST permalink
    • Embed this notice
      :SOGG: ing (pedophilesoftwareinc@cum.salon)'s status on Thursday, 02-Mar-2023 19:01:55 JST :SOGG: ing :SOGG: ing
      in reply to
      • pomstan
      • Fediverse Contractor
      • meso
      @meso @mint @bot @pomstan 2.5.1 pleroma update

      relative file names, might be a non issue, but god knows
      In conversation Thursday, 02-Mar-2023 19:01:55 JST permalink
      Fediverse Contractor likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.