G’day all,

I’ve come to realize my shotgun approach to updating whenever it’s convenient isn’t really working. To that end, I’ve deployed an instance of Uptime Kuma, a free and open source uptime monitor, which you can access at status.apollo.town.

I’ll add a maintenance window here if we’re going down for updates, as well as I’ve added a few other major instances so if you’re getting federation problems, you can check if they’re reachable by this server. Finally, it also monitors Lemmy source so if my Docker fails to build or something, maybe they changed the image name, etc.

As always, hit me up on Mastodon if you have any questions, or email me at admin at apollo.town. Please let me know if you have any other major instances you’d like monitored and I’ll see about adding them.

Cheers!

-Nico

  • Vale@apollo.town
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    @nico@apollo.town anything we should worry about in regards to the lemmy exploit reported a couple of hours ago?

    • Nico@apollo.townOPM
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      I am following the Git issue closely and will update the site as soon as a fix is released.

      There was first an exploit where you could launch JavaScript in the link of a post, which was resolved in the 0.18.1 release. Links only allow http(s) right now.

      Then, an admin account was hacked at lemmy.world and went rogue. I suspect several other instances had this problem.

      A second exploit was reported hours ago using custom emoji, and seems to be unpatched. I removed our custom emoji per their mitigation instructions and will terminate everyone’s sessions when I’m back at my computer for good measure. As soon as an update comes out for this it will be applied.