Post AW2Mc4XfzvOhryVGaW by sarvo@novoa.nagoya
 (DIR) More posts by sarvo@novoa.nagoya
 (DIR) Post #AW2KYmptAmg4B4KNI8 by pernia@cum.salon
       2023-05-26T05:09:45.908531Z
       
       0 likes, 0 repeats
       
       malboros r overrated
       
 (DIR) Post #AW2Kew3Xnyz4Vke9yK by grumbulon@freecumextremist.com
       2023-05-26T05:10:51.218863Z
       
       2 likes, 0 repeats
       
       @pernia this nigga smokes pall malls
       
 (DIR) Post #AW2KhVnnsBShxGVqeO by sarvo@novoa.nagoya
       2023-05-26T05:11:23.621Z
       
       1 likes, 0 repeats
       
       @pernia@cum.salon malboro rojo?
       
 (DIR) Post #AW2L9ohnBYRagqCKR6 by pernia@cum.salon
       2023-05-26T05:16:29.248291Z
       
       0 likes, 0 repeats
       
       @sarvo sep
       
 (DIR) Post #AW2LC5z1uv0or8LaNc by sarvo@novoa.nagoya
       2023-05-26T05:16:55.147Z
       
       0 likes, 0 repeats
       
       @pernia@cum.salon no le sabes
       
 (DIR) Post #AW2LL1aNdWTJp74isC by pernia@cum.salon
       2023-05-26T05:18:28.592038Z
       
       0 likes, 0 repeats
       
       @grumbulon the old reliable
       
 (DIR) Post #AW2LPEeezJydVy5KHQ by pernia@cum.salon
       2023-05-26T05:19:16.281187Z
       
       1 likes, 0 repeats
       
       @sarvo son la misma picha que un pall mol y 2 veces mas caro y mas corto
       
 (DIR) Post #AW2LT8P6AfJzHmfJce by nukie@freecumextremist.com
       2023-05-26T05:19:58.275880Z
       
       1 likes, 0 repeats
       
       @pernia @graf @graf the blue ones are pretty good
       
 (DIR) Post #AW2LWEkh1ag5qMFGwC by pernia@cum.salon
       2023-05-26T05:20:32.325314Z
       
       0 likes, 0 repeats
       
       @nukie @graf @graf havent tried those
       
 (DIR) Post #AW2LvOAp8IuWIrSebw by sarvo@novoa.nagoya
       2023-05-26T05:25:04.470Z
       
       1 likes, 0 repeats
       
       @pernia@cum.salon forma rara de decir que te gustan largos pero bueno
       
 (DIR) Post #AW2M09PDT0htwvSoV6 by grumbulon@freecumextremist.com
       2023-05-26T05:25:53.374195Z
       
       1 likes, 1 repeats
       
       @pernia thats what you call your boyfriend's dick
       
 (DIR) Post #AW2MES3av1S3qjAZRg by kirby@mstdn.starnix.network
       2023-05-26T05:26:20Z
       
       1 likes, 0 repeats
       
       @pernia you can see this I think... have you heard about that new pleroma exploit yet?
       
 (DIR) Post #AW2MEuH20epxMVfhHE by pernia@cum.salon
       2023-05-26T05:28:35.983859Z
       
       0 likes, 0 repeats
       
       @kirby ye
       
 (DIR) Post #AW2MJP8VCon8EqpKDY by pernia@cum.salon
       2023-05-26T05:29:25.698904Z
       
       3 likes, 1 repeats
       
       @grumbulon my boyfriends dick is like a malboro, short, dainty, and too expensive
       
 (DIR) Post #AW2MMQHrNoOAg1dwGW by pernia@cum.salon
       2023-05-26T05:29:58.201436Z
       
       0 likes, 0 repeats
       
       @sarvo largos para los largos
       
 (DIR) Post #AW2MMqvoJtnJJSXD96 by kirby@mstdn.starnix.network
       2023-05-26T05:29:41Z
       
       1 likes, 0 repeats
       
       @pernia plz remain safe. Unless I'm not talking to the real pernia!!!!!
       
 (DIR) Post #AW2MOFaC9VCK3c5g24 by theorytoe@ak.kyaruc.moe
       2023-05-26T05:30:19.161199Z
       
       1 likes, 0 repeats
       
       @kirby @pernia :boing:
       
 (DIR) Post #AW2MOxhU7lAmsxq7VI by pernia@cum.salon
       2023-05-26T05:30:25.741897Z
       
       0 likes, 0 repeats
       
       @kirby im the real dernia :eyeballlick:
       
 (DIR) Post #AW2MXPmDcYJMHO5IdE by kirby@mstdn.starnix.network
       2023-05-26T05:31:31Z
       
       1 likes, 0 repeats
       
       @pernia remove javascript files from the salons media plz!!!!!
       
 (DIR) Post #AW2MXQUswU2YVuyyFk by kirby@mstdn.starnix.network
       2023-05-26T05:31:48Z
       
       1 likes, 0 repeats
       
       @pernia also the funny nginx rule let's you deny javascript files in there so that's good
       
 (DIR) Post #AW2MZH5gszDZv54yRs by pernia@cum.salon
       2023-05-26T05:32:17.445088Z
       
       0 likes, 0 repeats
       
       @kirby what will u give me if i do
       
 (DIR) Post #AW2Mc4XfzvOhryVGaW by sarvo@novoa.nagoya
       2023-05-26T05:32:49.181Z
       
       1 likes, 0 repeats
       
       @pernia@cum.salon @kirby@mstdn.starnix.network cancer
       
 (DIR) Post #AW2MdqleBNvtj9sydU by sarvo@novoa.nagoya
       2023-05-26T05:33:07.196Z
       
       2 likes, 0 repeats
       
       @pernia@cum.salon más joto que has dicho en tu vida
       
 (DIR) Post #AW2MljcKeQ2LrsHwVU by pernia@cum.salon
       2023-05-26T05:34:32.631189Z
       
       1 likes, 0 repeats
       
       @sarvo ni cerca xd
       
 (DIR) Post #AW2Mn4SycUs2otY8wq by kirby@mstdn.starnix.network
       2023-05-26T05:32:48Z
       
       1 likes, 0 repeats
       
       @pernia your account doesn't get hacked by some random dude, wait did you actually hear the news of the exploit
       
 (DIR) Post #AW2Mn6QDLjqisuGxv6 by kirby@mstdn.starnix.network
       2023-05-26T05:33:26Z
       
       1 likes, 0 repeats
       
       @pernia if you didn't hear is the graf lecturehey friends, on may 19, 2023 an unknown user registered the domain name fedirelay.xyz and setup a fake mostr (nostr) relay to listen for requests on the fediverse.on may 20, 2023 at 20:52 (utc) a user uploaded the attached document to poast. it was originally an obfuscated javascript file (unobfuscated and attached it here, renamed to .txt so you can view it in any editor).what this javascript file does is take the viewers oauth token, encode it to make it look like a nostr pubkey and then forced the clandestine mostr relay to look up that user locally giving that server the encoded token all while appearing to be a legitimate mostr (nostr) bridge i have taken steps to completely limit access to the admin api and corrected any CSP or other issues that could possibly have contributed to this, however most of you are still vulnerable to it. the default pleroma install serves media files on your root domain as a local folder (i.e. yourdomain.xyz/media) and the default CSP for any site is to allow executing scripts via the root domain. in order to prevent this you should take steps to either move your media from yourdomain.xyz/media to media.yourdomain.xyz (or any subdomain outside of your root domain) or perhaps by limiting the CSP for that subdirectory via nginx configuration.if you are an instance owner, the obfuscated file hash is `b2977f2d97f598d2ebd6dcf37afd9047b5da2b6dc95a7b2824fb111c906fb117` so you can search yourdomain.xyz/media/b2977f2d97f598d2ebd6dcf37afd9047b5da2b6dc95a7b2824fb111c906fb117.js and see if you have it on your server. sorry to anybody i let down but i could never have foreseen this level of sophistication and i would not have ever expected it. now that we are aware of it, we will be more diligent in the future. thanks for being here with us still friends
       
 (DIR) Post #AW2MvkJguD74vtLKAS by pernia@cum.salon
       2023-05-26T05:36:19.512363Z
       
       0 likes, 0 repeats
       
       @kirby hes trying to social engineer me into downloading exploitfix.jar into my minecraft folder. not falking for that, hope graf gets shot by the atf for being an alcoholic child molestor