What is Nostr?
julian /
npub1uq5…z8a5
2024-05-21 15:28:53

julian on Nostr: We've noticed in the past week that fairly innocuous looking posts are coming in from ...

We've noticed in the past week that fairly innocuous looking posts are coming in from brand-new users **containing spam links with no anchor text**. They're caught by the post queue but at face value, they could be accepted by a moderator as the link themselves were hidden from view.


It was only once you inspected the raw post content that the hidden link was revealed (e.g. innocuous text [](//malicious.org).


To combat this, NodeBB will now explicitly expose hidden links so that they can be easily seen and caught.


This is what it looks like: [](https://community.nodebb.org//community.nodebb.org )


If you are viewing this post from outside of NodeBB, you might not see anything! That means your software might be vulnerable to this kind of spam backlink injection. Best case, your software detects the empty link text and removes it completely. Worst case, you're allowing them in unknowingly.


Last thing, it's possible this has been around for ages and I only just noticed (thanks also to PitaJ (npub1hxp…n4ux) for pointing out the hidden links from an earlier post!) If you browse around the forum and see some of these hidden links scattered around some posts, flag it immediately so we can take a look.


Thank you!


Author Public Key
npub1uq5lznmk9ax9r07mhs0lrv4qaafyguepj2spfjlw54acwkxrds3sppz8a5