Timeline
Post
Remote status
Context
8
Not spinster.club still being up tho
@subnetter separate box
@pwm but he is he the sysadmin confirmed?
@subnetter yeah it's a btrf.ly site (one of several)
@pwm rebased + soapbox combo wombo
@subnetter they are off rebased, this looks like an ssh vuln in ubuntu
https://nvd.nist.gov/vuln/detail/cve-2024-6387
https://nvd.nist.gov/vuln/detail/cve-2024-6387
@pwm @subnetter the only problem is this doesn't totally explain why grafs account was migrated off to a burner account and blank/invalid profiles. judging by what graf has said publicly the attackers could've hopped between a few hosts before getting to the pleroma box? that's my best guess
@kirby @pwm @subnetter you can't use 2FA with adminFE so with shell access they can request a password reset via a mix task and log in on my account.
@graf @pwm @kirby @subnetter Or alternatively just MitM and grab the token if that's the reverse proxy that got pwned and not the main server.
Replies
4@mint @pwm @graf @subnetter seems more likely than jacking the pleroma box itself
@kirby @pwm @mint @subnetter they changed the IPMI credentials on the hardware, they had root access to that server
@mint @pwm @kirby @subnetter pleroma's main box. they likely got the ssh info from shodan because it has an rDNS entry, it was not running on any IP post was federating to/from or hosting on