Well at least Eugene has stated that the vulnerability doesn’t seem to be related to mastodon’s codebase, and that GAB wouldn’t even install the security patches.
There’s basically no details on the SQL injection attack, so it’s hard to tell. SQL injection attacks in general can occur independent of the database, but yeah, we don’t even know if it even applies to Mastodon.
deleted by creator
Well at least Eugene has stated that the vulnerability doesn’t seem to be related to mastodon’s codebase, and that GAB wouldn’t even install the security patches.
Does this also apply to postgresql? That’s the default recommended for vanilla masto.
There’s basically no details on the SQL injection attack, so it’s hard to tell. SQL injection attacks in general can occur independent of the database, but yeah, we don’t even know if it even applies to Mastodon.
FWIW, some of the people involved have suggested that Gab introduced vulnerabilities while modifying the Mastodon code.
See here.
Arstechnica has some more details. https://arstechnica.com/gadgets/2021/03/rookie-coding-mistake-prior-to-gab-hack-came-from-sites-cto/
Oh boy, that’s a lot of hand-written SQL, and they even just commented out the old code.
deleted by creator
deleted by creator