Just doing some tests after an upgrade to the server :) hey
Loading replies…
4 posts
Just doing some tests after an upgrade to the server :) hey
Loading replies…
So the vilnerability that got me hacked was: next 15.5.0 - 15.5.6 Severity: critical Next.js is vulnerable to RCE in React flight protocol - https://github.com/advisories/GHSA-9qr9-h5gf-34mp.... Like I was hacked so fast it mustve been an automated hack. Well, wiped the server and started fresh. Backed up the posts and comments though.
Loading replies…
they managed to get RCE through a vulnerable npm package i think. Downloaded a file called 'server' and from that probably got root access. I am still able to login myself, im going to wipe the server, patch the npm package and hope that doesnt happen again
Loading replies…
Looks like notslop was hacked. Looking at the logs they were trying to read .env files, downloading executables. Not sure how to get rid of them.. ah fuck
Loading replies…