Updated to 0.18.2, which includes fixes for the recently found vulnerabilities. Also updated with Ansible this time to get the Nginx config updates, which I think fixes some federation issues with kbin and Mastadon.
While I was asleep, apparently the site was hacked. Luckily, (big) part of the
lemmy.world team is in US, and some early birds in EU also helped mitigate this.
As I am told, this was the issue: - There is an vulnerability which was
exploited - Several people had their JWT cookies leaked, including a...
Link Actions
For those that are aware, some Lemmy.world admin accounts were hacked using a known Lemmy vulnerability based on custom emojis. There are NO custom emojis configured for this instance, so no concerns regarding this vulnerability for this instance.
I noticed posts from other instances saying there has been massive account creation activity. Checking the stats here, it seems to be reporting almost 6k users. Not sure what can be done, but it’s likely not for legitimate purposes.
This instance is currently being hosted using Vultr on a server located in Dallas. Specifically, it's using a cloud compute server with the following specs:
AMD High Performance
Ubuntu 22.04 LTS x64
1 vCPU
1 GB of memory
2 TB of bandwidth
25 GB of NVMe storage
Attached storage: None
Auto backups are enabled and configured for every other day at 2AM Mountain Time. Total monthly for hosting is currently $7.20 a month. I chose Vultr for its combination of price, ease of use, and ease of upgrading. With a couple of clicks I can upgrade the server up to 12 vCPUs and 24 GB memory.
Domain
I currently have the domain centennialstate.social registered with Google Domains at a cost of $30 a year. Unfortunately, the same day I purchased this domain Google announced they were selling off their Domains service to Square Space. I have to wait 60 days from purchasing before I can transfer it, at which point I will be transferring it to CloudFlare at an unknown cost. If i