User avatar
Alexia makko_bnuuy @alexia@starlightnet.work
3mo
seeing people that haven't updated in so long that they can no longer migrate the database automatically and are as such stuck on probably The Worst Version Ever of sharkey (in terms of security) is frightening

like. holy shit. why has your instance been running like this
neocat_0_0
:neobot_woozy@plasmatrap.com:1:sylveon_shocked@i.use.akkoma.btw.sylveon.social:1
2
1
2
2
User avatar
Alexia makko_bnuuy @alexia@starlightnet.work
3mo
not only are you about to have a gigantanormous vulnerability dropped on your head, you probably also have the last 3 gigantanormous vulns running
:neobot_shocked@plasmatrap.com:1:sylveon_shocked@i.use.akkoma.btw.sylveon.social:1
1
0
1
2
3mo
@alexia wait,,, they have the ap/get vulnerability???????

oh no
sylveon_shocked
:neobot_shocked@plasmatrap.com:1
2
0
2
1
3mo
@alexia oh, wait, fae looked at the ap/get vulnerability, and using that api requires having an account even in older versions (at which point you may as well use the arbitrary code execution vulnerability fae found if you want to exploit the instance, which also requires having an account)

still the situation is really bad, but, at least it's not as bad as fae assumed (ap/get vulnerability is really nasty),,, like, currently the only major issues is people being able to spoof notes to that instance, and,,, a pretty bad vulnerability fae found in the past (that sharkey developers quietly patched without making an announcement about it, not referring to the ace vulnerability here)

,,, and there is whatever vulnerability there will be a patch for soon
:neobot_shocked@plasmatrap.com:1
1
0
2
1
User avatar
Alexia makko_bnuuy @alexia@starlightnet.work
3mo
@sugar

fwiw the upcoming vuln is
BAD.
:sylveon_shocked@i.use.akkoma.btw.sylveon.social:1
1
0
1
1
User avatar
illy [Shrimple-mode] protomoji_orange_flag_lesbian @illyBytes@shrimp.imsofucking.gay
3mo
@alexia @sugar oh god 0_0
doesnt it only affect sharkey or does it spill over to other misskey/misskey-likes?
1
0
1
0
User avatar
Alexia makko_bnuuy @alexia@starlightnet.work
3mo
@illyBytes @sugar

The vulnerability is upstream in Misskey from what I understand

(but not iceshrimp.net.)
1
0
2
0
User avatar
illy [Shrimple-mode] protomoji_orange_flag_lesbian @illyBytes@shrimp.imsofucking.gay
3mo
@alexia @sugar oh alright ๐Ÿ˜ฎโ€๐Ÿ’จ thankfully wbwvwbbw
1
0
2
0
User avatar
Alexia makko_bnuuy @alexia@starlightnet.work
3mo
@illyBytes @sugar always remember that Iceshrimp.NET's codebase is entirely separate
1
0
2
0
User avatar
illy [Shrimple-mode] protomoji_orange_flag_lesbian @illyBytes@shrimp.imsofucking.gay
3mo
@alexia @sugar yeah but i remember being affected by like a misskey bug once iirc?
0
0
1
0