injection attacks on websites means that someone managed to add some unintended part to the website, as if the webserver had sent a different page. So it does allow all things the website could do, no more - no less.
If I type <style>*{display:none}</style>, that is escaped. If this would get inserted into the website as “cleartext”, it would be valid html that would hide the entire page, turning it blank. Ofc a comment should not be able to do that, so a > in text is changed to something like >
![alt text](https://link.to/an/image.png) is a syntax to insert an image into the comment, so it is parsed into an <img src="https://link.to/an/image.png" alt="alt text"> html element. In that insertion the contained text was not properly escaped in some cases, so you could have the image contain valid html which would continue on writing into the website. Basically for the alt text " other attribute="attribute val you would get <img src="https://link.to/an/image.png" alt="" other attribute="attribute val"> instead of <img src="https://link.to/an/image.png" alt="" other attribute="attribute val"> which it should have been. And one of the attributes you can add is javascript that is executed at certain times, so you can inject javascript into the page which can do pretty much everything at that point
It can only ever steal this pages cookies.
Imagine if any random page could read the cookies from your online banking…
fuck redhat and their forum, fuck them
migrate to opensuse if you must, but fuck redhat
Aight, I will not use kill -9 I promise
*Camera pans over keyboard with suspiciously worn down 4 key*
Posting an extremely tall image (https://burggit.moe/post/84517) breaks webUI. the direct link to the image (https://burggit.moe/pictrs/image/186d3b6a-4b5d-4b97-85df-55f2f53f0700.jpeg) works, but webUI seemingly requests a webp conversion (https://burggit.moe/pictrs/image/186d3b6a-4b5d-4b97-85df-55f2f53f0700.jpeg?format=webp) which fails likely due to the dimensions.
I assume this is probably a deeper lemmy issue, but posting here on the offchance therer is something like a setting for a webp conversion size limit you could increase.
This is jpeg specific as far as I can tell
I can sort it for you
https://burggit.moe/c/asiannsfw
https://burggit.moe/c/audio_gonewild
https://burggit.moe/c/beastclub
https://burggit.moe/c/cumfetish
https://burggit.moe/c/cumsluts
https://burggit.moe/c/dildogag
https://burggit.moe/c/dirtypenpals
https://burggit.moe/c/doujinshi
https://burggit.moe/c/femboyhentai
https://burggit.moe/c/gonewild
https://burggit.moe/c/hentaimilfs
https://burggit.moe/c/incest_hentai
https://burggit.moe/c/massivemilkers
https://burggit.moe/c/nsfw_leaks
https://burggit.moe/c/omorashi_art
https://burggit.moe/c/pokeloli
https://burggit.moe/c/pokemon_hentai
https://burggit.moe/c/pokemon_porn (Less restrictive Pokémon community.)
https://burggit.moe/c/predicament_hentai
https://burggit.moe/c/rapehentai
https://burggit.moe/c/straightshota
https://burggit.moe/c/tentacles
https://burggit.moe/c/torturehentai
https://burggit.moe/c/touhou_nsfw
https://burggit.moe/c/watersports_art
https://burggit.moe/c/zoophilia (For Discussion Only)
Here’s some missing ones:
[email protected] :)
[email protected]
[email protected]
[email protected]
And do we wanna add [email protected]?
Could you sort the list alphabetically? It was kinda annoying for me to check whether communities where already on the list or not.
No offense, but how do I block shota in this sub?
Lack of categories makes me whish there where separate rapehentai and shotarapehentai subs.
pornlemmy.com is defederated, fba doesn’t list it properly, likely because the page “pornlemmy.com/instances” still has their age verification popup