Skip Navigation
PSA: You can upload images to a Lemmy instance without anyone knowing
  • I'm a pentester and security consultant. From my point of view, this vulnerability has more impact than just a resource leak or DOS. We all know how often CSAM or other illegal material is uploaded to communities here as actual posts (where hundreds of viewers run into it to report it). Now imagine them uploading it and spreading it like this, and only the admin can catch it if they goes out of their way to check it?

    I wouldn't call this a high risk issue for sure. But a significant security risk regardless.

  • Real
  • To be fair, wordpresses own security is pretty decent. It's more that anyone can develop, publish and install any random set of php code as plugins what makes it so vulnerable. (In my experience at least)

  • Linux Best Practices
  • I totally agree. We should be more open and welcoming to new users. Imagine some new people on the steam deck being curious and diving into Linux and running into this. Undoubtedly, we'd lose at least a few users that brick their machines.

    I get that this humor fits and entertains the technically inclined of us, but if we truly want more widespread use of Linux, shouldn't we open our arms to less technical users as well? Besides, even for the more technical of us, this joke is so old and run down 🙃

  • Kan Feddit.nl 'old.feddit.nl' ook implementeren?
    lemmy.world As requested: https://old.lemmy.world (MLMYM) - Lemmy.world

    As requested by some users: ‘old’ style now accessible via https://old.lemmy.world [https://old.lemmy.world] Code can be found here: https://github.com/rystaf/mlmym [https://github.com/rystaf/mlmym] , created by Ryan [https://github.com/rystaf] (Is he here?) (Yes he appears to be! @nnrx@sh.itjust.wo...

    Ziet er echt nice uit. Zweer dat ik geen Reddit refugee ben 👀

    0
    Gast feddit.nl de FediPact joinen tegen Meta/Facebook?

    Vrees een beetje voor de toekomst van de fediverse. Zeker als je naar de geschiedenis kijkt van bijv. XMPP en Google chat 👀

    0
    InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)NE
    newline @feddit.nl
    Posts 2
    Comments 8