GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Wary Jerry (jerry@infosec.exchange)'s status on Tuesday, 15-Nov-2022 23:42:23 JST Wary Jerry Wary Jerry

    This message for everyone on the fediverse:

    First, please ensure you go into your account settings and enable two/multi factor authentication. No, I mean do it right now. I’ll wait till you’re done.

    …

    …

    Ok, thank you.

    Now, if you are the admin of a mastodon instance, please go upgrade to 4.0.2 ASAP.

    Background: https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp

    In conversation Tuesday, 15-Nov-2022 23:42:23 JST from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: portswigger.net
      Stealing passwords from infosec Mastodon - without bypassing CSP
      The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP. Everybody on our Twitter feed seemed to be jumping ship to the infose
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Wednesday, 16-Nov-2022 04:25:16 JST Alex Gleason Alex Gleason
      in reply to
      @jerry The real vulnerability is that Chrome autofills passwords into iframes. What the hell? Is that for real?
      In conversation Wednesday, 16-Nov-2022 04:25:16 JST permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Wednesday, 16-Nov-2022 04:29:44 JST Alex Gleason Alex Gleason
      in reply to
      • Alex Gleason

      @jerry Okay, the reason it’s not an issue for other types of embeds is because we use the sandbox attribute and disallow form submissions. https://developer.mozilla.org/en-US/docs/Web/HTML/Element/iframe#attr-sandbox

      In conversation Wednesday, 16-Nov-2022 04:29:44 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: developer.mozilla.org
        : The Inline Frame element - HTML: HyperText Markup Language | MDN
        The HTML element represents a nested browsing context, embedding another HTML page into the current one.
    • Embed this notice
      Ren ? (rogueren@vt.social)'s status on Wednesday, 16-Nov-2022 11:42:06 JST Ren ? Ren ?
      in reply to
      • Asahi Linya (朝日りにゃ〜)
      • Luna ??? //nullptr::live

      @jerry @lina @LunaFoxgirlVT I assume you're aware of this?

      In conversation Wednesday, 16-Nov-2022 11:42:06 JST permalink
    • Embed this notice
      Asahi Linya (朝日りにゃ〜) (lina@vt.social)'s status on Wednesday, 16-Nov-2022 11:42:06 JST Asahi Linya (朝日りにゃ〜) Asahi Linya (朝日りにゃ〜)
      in reply to
      • Luna ??? //nullptr::live
      • Ren ?

      @rogueren @jerry @LunaFoxgirlVT I just woke up and updated it ^^

      In conversation Wednesday, 16-Nov-2022 11:42:06 JST permalink
    • Embed this notice
      Ren ? (rogueren@vt.social)'s status on Wednesday, 16-Nov-2022 14:20:10 JST Ren ? Ren ?
      in reply to
      • Asahi Linya (朝日りにゃ〜)
      • Luna ??? //nullptr::live

      @lina @jerry @LunaFoxgirlVT awesome!

      In conversation Wednesday, 16-Nov-2022 14:20:10 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.