GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    lainy (lain@lain.com)'s status on Saturday, 27-May-2023 01:56:02 JST lainy lainy
    There might be a second attack vector for the exploit, i recommend deactivating rich_media (i.e. website previews)
    in your pleroma config for the time being
    In conversation Saturday, 27-May-2023 01:56:02 JST from lain.com permalink
    • Embed this notice
      lainy (lain@lain.com)'s status on Saturday, 27-May-2023 09:52:52 JST lainy lainy
      in reply to
      • 御園はくい
      @hakui if it says rich media anyway, deactivate. I thinks its deactivated by default. Ifcyou don't see previews for links, its not active.
      In conversation Saturday, 27-May-2023 09:52:52 JST permalink
    • Embed this notice
      御園はくい (hakui@tuusin.misono-ya.info)'s status on Saturday, 27-May-2023 09:52:53 JST 御園はくい 御園はくい
      in reply to
      @lain uhhh how do i do that again i haven't touched the config file for so long i forgot where it was
      In conversation Saturday, 27-May-2023 09:52:53 JST permalink
    • Embed this notice
      lainy (lain@lain.com)'s status on Saturday, 27-May-2023 10:15:41 JST lainy lainy
      in reply to
      • Salastil
      @Salastil update to the new release, that's all
      In conversation Saturday, 27-May-2023 10:15:41 JST permalink
    • Embed this notice
      Salastil (salastil@pleroma.salastil.com)'s status on Saturday, 27-May-2023 10:15:42 JST Salastil Salastil
      in reply to
      At the end of all of this can you write up a news article detailing all of the various changes and other mitigation required? Everything is split across a dozen random posts and replies at all hours of the day, having a detailed news article on the feed explaining what happened, how and why such changes are to done would be highly helpful, not just for the immediate timeframe but for new admins months from now.
      In conversation Saturday, 27-May-2023 10:15:42 JST permalink
    • Embed this notice
      御園はくい (hakui@tuusin.misono-ya.info)'s status on Saturday, 27-May-2023 11:04:43 JST 御園はくい 御園はくい
      in reply to
      @lain nope i see previews all right
      In conversation Saturday, 27-May-2023 11:04:43 JST permalink
    • Embed this notice
      lainy (lain@lain.com)'s status on Saturday, 27-May-2023 11:04:43 JST lainy lainy
      in reply to
      • 御園はくい
      @hakui well then deactivate it
      In conversation Saturday, 27-May-2023 11:04:43 JST permalink
    • Embed this notice
      御園はくい (hakui@tuusin.misono-ya.info)'s status on Saturday, 27-May-2023 11:06:13 JST 御園はくい 御園はくい
      in reply to
      @lain where
      In conversation Saturday, 27-May-2023 11:06:13 JST permalink
      lainy likes this.
    • Embed this notice
      lainy (lain@lain.com)'s status on Saturday, 27-May-2023 11:08:04 JST lainy lainy
      in reply to
      • 御園はくい
      @hakui docs.pleroma.social
      In conversation Saturday, 27-May-2023 11:08:04 JST permalink
    • Embed this notice
      lainy (lain@lain.com)'s status on Saturday, 27-May-2023 21:24:10 JST lainy lainy
      in reply to
      • Oneesan succubus
      • Salastil
      • Luca Sironi
      @luca @Salastil @lain good question, there isn't really a perfect place for this yet. Although it doesn't happen very often, so I'm not sure if something is needed.
      In conversation Saturday, 27-May-2023 21:24:10 JST permalink
    • Embed this notice
      Luca Sironi (luca@sironi.tk)'s status on Saturday, 27-May-2023 21:24:13 JST Luca Sironi Luca Sironi
      in reply to
      • Oneesan succubus
      • Salastil

      @lain @Salastil

      hello @lain thank you for 2.5.2

      is there an official point of reference that pleroma admin should follow for those kind of sudden issues and immediate action to take? I wasn’t, but i could have been attacked if i didn’t saw your suggestions. Yesterday i simply saw in my timeline one message from Alex Gleason and then i started following you on this profile and on @lain with alerts on.

      Does not seems the right place to follow you if i’m just interested in pleroma security…

      In conversation Saturday, 27-May-2023 21:24:13 JST permalink
    • Embed this notice
      lainy (lain@lain.com)'s status on Saturday, 27-May-2023 22:47:15 JST lainy lainy
      in reply to
      • 御園はくい
      @hakui do you have your config in the database?
      In conversation Saturday, 27-May-2023 22:47:15 JST permalink
    • Embed this notice
      御園はくい (hakui@tuusin.misono-ya.info)'s status on Saturday, 27-May-2023 22:47:16 JST 御園はくい 御園はくい
      in reply to
      @lain ehh i don't have rich_media in my config but links still have thumbnails?
      image.png
      In conversation Saturday, 27-May-2023 22:47:16 JST permalink

      Attachments


      1. https://tuusin.misono-ya.info/media/de8e36c6106cdbd938cc33ab6e4b14a5714923a7a2c6936234489f0892707d52.png?name=image.png
    • Embed this notice
      lainy (lain@lain.com)'s status on Saturday, 27-May-2023 22:50:23 JST lainy lainy
      in reply to
      • 御園はくい
      @hakui maybe put config in and explicitly disable it
      In conversation Saturday, 27-May-2023 22:50:23 JST permalink
    • Embed this notice
      lainy (lain@lain.com)'s status on Saturday, 27-May-2023 23:04:14 JST lainy lainy
      in reply to
      • 御園はくい
      @hakui Si
      In conversation Saturday, 27-May-2023 23:04:14 JST permalink
    • Embed this notice
      御園はくい (hakui@tuusin.misono-ya.info)'s status on Saturday, 27-May-2023 23:04:15 JST 御園はくい 御園はくい
      in reply to
      @lain config :pleroma, :rich_media, enabled: false like this?
      In conversation Saturday, 27-May-2023 23:04:15 JST permalink
    • Embed this notice
      御園はくい (hakui@tuusin.misono-ya.info)'s status on Saturday, 27-May-2023 23:06:25 JST 御園はくい 御園はくい
      in reply to
      • 御園はくい
      @lain hmm yep it worked :burd:
      thanks!
      In conversation Saturday, 27-May-2023 23:06:25 JST permalink
      lainy likes this.
    • Embed this notice
      lainy (lain@lain.com)'s status on Saturday, 27-May-2023 23:07:16 JST lainy lainy
      in reply to
      • 御園はくい
      @hakui if you can you should also do this: https://webb.spiderden.org/2023/05/26/pleroma-mitigation/
      In conversation Saturday, 27-May-2023 23:07:16 JST permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Mitigating the recent Pleroma issues
    • Embed this notice
      御園はくい (hakui@tuusin.misono-ya.info)'s status on Saturday, 27-May-2023 23:12:28 JST 御園はくい 御園はくい
      in reply to
      @lain i'm the only one on my instance uploading anything so i think i'll take the risk..
      In conversation Saturday, 27-May-2023 23:12:28 JST permalink
      lainy likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.