Avatar
Haelwenn /элвэн/ :triskell: 🔜FOSDEM
24389949b53d16958eae22ba78a4040316903c933a9e8f9d9fd5f10688fc62af
🦊🦄⚧🂡ⓥ :anarchy: 👿🐧 :gentoo: :sun: Pleroma maintainer (mostly backend); BadWolf developer; Gentoo contributor; Eternal upstreamer Opinions are your employer Arch users needs to pacman -R works-for-me arch-btw Make the changes you want to see. Just because computer bad: X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* banner from: https://soc.flyingcube.tech/objects/56f79be2-9013-4559-9826-f7dc392417db Federation-bots: #nobot
Replying to Avatar meso

nostr:npub1ysufjjd485tftr4wy2a83fqyqvtfq0yn820gl8vl6hcsdz8uv2hskx2jyl how do i switch to pleroma upstream repository (git.pleroma.social rather than git.asbestos.cafe) i give up i dont want to run my own fork and have to understand git

@pomstan@xn–p1abe3d.xn–80asehdb /api/v1/pleroma/remote_interaction (public) is a known way.

And I’m not a full-disclosure-on-day0 person so if you want exploit details it’ll have to wait until I can be reasonably sure people have their software fixed.

And it's kind of ironic that one of the reasons Pleroma doesn't adopt JSON-LD is due to the external entities issue among other broken designs of JSON-LD only to get hit via a worse version right in the XML library that's part of Erlang, even though XML doesn't requires the bad design in question.

Low-key wonder if there's a hall of shame for XML, JSON-LD, maybe YAML, … libraries that grab external ressources by default.

yo, nostr:npub1ysufjjd485tftr4wy2a83fqyqvtfq0yn820gl8vl6hcsdz8uv2hskx2jyl you need to do --chown=pleroma in the Dockerfile for the config copy and set more restrictive permissions on confix.exs in the repo

nostr:npub1vseykxgxuz8ver5c7g0ddhcpv8erqy3v9cfvgcuqdygdnnpd488s6av7q2 I know, could you send a patch if you have the fix for this? (I despise docker with passion…)

nostr:npub1532ksva0y353dymx4pd07rkm4jaqp7t5raguq8k27luxl6ajncuqvp5ffy Same thing there I guess, I removed the entire notifications system on my machines, only thing that produces sound here is my shell with quiet and short beeps, and there's no popups.

Last 2 security releases makes me want to do an AppArmor profile for Pleroma so at least on linux machines with it, it can be contained to Pleroma files for sure.

#Pleroma Security Release 2.5.4

Fix XML External Entity (XXE) loading vulnerability allowing to fetch arbitrary files from the server's filesystem.

https://pleroma.social/announcements/2023/08/05/pleroma-security-release-2.5.4/

Love the idea of building 4 binaries on a potato arm machine…

nostr:npub1ysufjjd485tftr4wy2a83fqyqvtfq0yn820gl8vl6hcsdz8uv2hskx2jyl i’ve went to some fancy restaurants where very handsome dapper men address you by name and give very good service; it’s pretty much the same thing but the food is actually good

nostr:npub19evw3m5663gjcg4cnaehfx42uxlq49kj6mxj06an30hz3e5navwq4zs343 I meant one that's about as lewd as a maid cafe.

nostr:npub1srdafpzsnx8lfzyhttuk24tnxwpqhsmxtavs4qvwrpufx8w662wstgg44z Meanwhile I'm pretty sure a bunch of billionaires just work in their fucking mansion without having to leave it all the time.