3 ms·
It looks like they didn't learn from what happened to Gab. I will never understand why they don't use a mastodon or pleroma instance instead of trying to mainta
by EccentricBunny 5y ago
It looks like they didn't learn from what happened to Gab.
I will never understand why they don't use a mastodon or pleroma instance instead of trying to maintain yet another centralized social media platform.
- danpalmer 5y agoDo you mean Parler? I think Gab is a Mastodon fork.
- input_sh 5y agoFunny you should mention that, but it's both. Both got hacked. Gab's was a result of a patch they've made on top of Mastodon. Since Mastodon's license required them to share the code, here's a commit that introduced it (https://github.com/d0nk/gab-social/commit/fb3b7545705153022c24bb072fbdb3925b8cbfeb#diff-065f2e5f4a7d47f5d3f93f4de1899416b95aee7809dc6d0d8074c8650c63378f https://github.com/d0nk/gab-social/commit/fb3b7545705153022c...). They've since "fixed" the problem by sharing just an archive of the code, and password protecting it with "JesusChristIsKingTrumpWonTheElection"). I find it quite hilarious.
- the_snooze 5y ago>"JesusChristIsKingTrumpWonTheElection" Very un-Christian of them to be spreading straight up lies.
- umanwizard 5y agoWell, presumably they genuinely believe it to be true.
- kyrra 5y agoWhat was wrong with that change that allowed them to get hacked? Edit, can I guess that this isn't how to do proper sql parameterized input? > s.account_id = #{@id} I don't know ruby at all...
- rsynnott 5y agoSomething along the lines of "https://thewebsite.com/the_url?max_id=); https://thewebsite.com/the_url?max_id=); DROP TABLE orange_face_paint ; [.. make the remainder valid sql here]" I would think. Essentially, it allows user-provided input to do anything; it's the most trivial form of SQL injection vulnerability.