26262nd poster gets a cookie (cookie thread (Part 7)) (Part 9)

ill follow up

2 Likes

The Discourse version is 2.8.14. Version 3.0 released in Jan 2023. That’s probably the issue. Let’s check the known vulns for this version. Ah. Yes. This is likely the issue. 77 known vulnerabilities.

1 Like

yeah I mean that probably doesn’t help :skull:

on the bright side I guess this means we’re finally big enough to be worth going after?

5 Likes

Unfortunately, no. You’re using popular software on a version with known exploits. There are bots just scanning the internet for sites running on exploitable software.

8 Likes

i know that but let me have at least some fun with the situation

6 Likes

anyways Chloe has been notified and we’ve forcibly enabled 2FA for all moderator accounts as a precaution (although, imo, it is highly unlikely that FoL was the target of any such breach, instead they’re prolly just fishing for password/username combinations)

6 Likes

I’ll send out some announcements to notify people

3 Likes

and will follow up once our provider has let us know if they know anything

3 Likes

Curious if it’s this one.

https://nvd.nist.gov/vuln/detail/CVE-2024-53991

1 Like

took a dig through our logs and I see no signs any admin account was hacked

so it could well be!

2 Likes

holy cope

10 Likes

if i start posting spicy furry art my account was hacked i swear

13 Likes

if i start posting spicy katze art my account was hacked i swear

11 Likes

happy @sulit day! i dedicate this meaningless, cookieless 10k to you

6 Likes

happy @sulit day i stole your password idiot

5 Likes

happy @sulit day i stole your password from katze

3 Likes

is a data breach the only thing that’ll get the muers on this site

13 Likes

Wow. Katze is an MUer now. The anime betrayal.

3 Likes

i mean basically

2 Likes

im not a muer im a mewer

3 Likes