Why Nostr? What is Njump?
2024-06-03 02:19:48
in reply to

​ on Nostr: silverpill I think so, after fetching an actor it performs webfinger lookup on the ...

I think so, after fetching an actor it performs webfinger lookup on the same domain, but due to faulty webfinger pipeline rewrite it accepted any arbitrary domain in response. I recall Mastodon had a similar vulnerability.
Author Public Key
npub1ajw6axeack23437kedc8pkwghneenrkh9ljfxxgxumr6t6k4rtvqecaj8d