#fediadmin

72 posts · Last used 8d

Replying to
Wann bekommt @Mastodon@mastodon.social eigentlich vernünftige Hooks, damit man derlei besser erkennen und unterbinden kann? Macht hier den Mammutanteil aller Spam-Reports aus und im Mod-Interface kann man nichtmals erkennen, dass es Followspam ist, man sieht nur, dass ein Account reported wurde. Das ist völlig unzureichend, zumal es sich recht gut technisch erkennen ließe. #fediadmin
2
1
1
0
Salut tout le monde ! Je prépare une page d'acceuil pour notre serveur. J'aimerais bien inclure quelques pages qui ont des tips pour le fediverse, idéalement francophone. Des pages qui expliquent comment bien utiliser mastodon, comment ça marche sur le fediverse, comment trouver des comptes qui pourrait plaire ou toute autre information que vous auriez aimé avoir au début ! Je suis preneur de toute information, piste, etc ! 😃 Merciiiii ! #fediverse #mastodon #introduction #feditips #fediadmin
0
0
1
0
pix.lgbt has been moved off of pixelfed-glitch because development there has come to a hault and we are back to vanilla Pixelfed. We now have the latest and greatest version that released this morning (plus quite a few fixes we submitted upstream for the rest of the community 🤞). We hope you enjoy! Moving back was a bit of a PITA so there was some small hiccups along the way (sorry about that!) but everything should be good going forward! If you have any issues don't hesitate to reach out! And if you're not already here and looking for a new home for your photos on the fediverse our registration is open! Tell your friends! #PixelfedAdmin #FediAdmin #Pixelfed #RegistrationsOpen
0
1
1
0
⚠️ Mastodon 4.4.x ⚠️ You're being urged to upgrade to Mastodon 4.6.x for a reason. Mastodon plans to release v5 by the end of this year or early next. That's why we've jumped from 4.5 to 4.6, and now we're on 4.7, with 4.8 already in nightly builds. Certain features and functionalities will leave you behind, and 4.4.x will soon reach its end of life (EOL). If you're using Mastodon 4.4.x, you should aim for 4.6.x or newer. #Mastodon #MastoAdmin #FediAdmin
2
1
2
0
I'm going to preface this with that I have no intention of doing this at all, this is just a hypothetical that has been nagging me. Let's say I were to delete this instance tomorrow, or maybe the domain expires and I never renew it... Does the cache of my posts and info and such eventually disappear from other fediverse instances? Do posts have a TTL that gets refreshed with the originating server or anything like that? I am sure that it is different across different implementations, so I'm really just looking for a general answer... #fediadmin #fedi #activitypub
0
1
0
0
apparently this flood of "automated protocol delivery probe" spam signups comes from https://sendflood.com if we mass report them to their registrar's abuse thing they should stop spamming us? the site was only made like a week ago sources for this info: • https://wubba.boo/notes/ar9jffw36cmi1qh2 • https://bardicperspiration.club/@Overgoddess/117288027775455205 • https://fosspri.de/@joshix/117286960234031491 as per the attached image their registrar's abuse email is abuse@spaceship.com and abuse phone number is +1.9854014545 #FediAdmin #MastoAdmin #fediblock #spam
8
1
16
0
Boosted by @fedicat@pc.cafe
Quick heads-up for other Mastodon admins: this registration spam wave isn't over yet. On lsbt.me, we first saw a flood of API registrations using Python/aiohttp. The telltale signs were usernames following the pattern bp plus 16 hex characters, and the sign-up reason was always "Automated protocol deliverability probe". A narrow block on that user agent stopped the first wave. Today, however, five new registrations came in with the same usernames and the same sign-up reason. This time the bot simply identified itself as Chrome 126. That's exactly why a user agent is only useful as a short-term filter. It's a header the client can set to anything. The requests go to POST /api/v1/accounts. This endpoint lets client apps create a new local account directly in the app. No app needs it for OAuth connections to existing accounts. #FediSuite doesn't use it either. It registers itself via /api/v1/apps, obtains consent via /oauth/authorize, and then works with a user token. Regular sign-up through the Mastodon website is also handled separately via POST /auth. So I've completely disabled API account creation on lsbt.me. Web sign-up, OAuth, and existing clients keep working as before. Anyone who wants a new account just signs up once on the web as usual and can then use any client. If you'd also rather not offer this optional native sign-up path, you can add the following to your Nginx server block, before the general location / block. The example assumes the @proxy location that many Mastodon Nginx configs already include: location = /api/v1/accounts { limit_except GET { deny all; } try_files $uri @proxy; } This returns a 403 only for POST /api/v1/accounts. The read-only GET endpoint remains reachable. As always, run nginx -t afterwards and only reload once the test passes. #Mastodon #Fediverse #MastoAdmin #FediAdmin #FediMod #FediBlock #Moderation #Registration #Spam #Nginx #SelfHosting #SysAdmin #ActivityPub
0
1
6
0

If the answer to all these is yes, please DM me at @FediGarden@social.growyourown.services and tell me a bit about your server 🙂

#Fediverse #FediAdmin #MastoAdmin

44
0
73
0
【站长提醒|大范围撞库盗号】 最近联邦宇宙出现一轮大规模撞库盗号:9 月 6 日 12:05–12:41 UTC 短短一小时内,至少 82 个实例、142+ 个账号被同一套脚本改名为「HACKED - Join t[.]me/HomeFucker5」并置顶垃圾帖。我站也有两个账号中招。 这是撞库(拿其他网站泄露的邮箱+密码来登录),不是 Mastodon 或站点的安全漏洞:从 4.1 到 4.8-nightly、已打满补丁的实例都被命中。攻击者先用密码悄悄"验号",几周后再集中变现,所以现在没发帖不代表没被盗。 建议各位站长排查: • 登录记录(login_activities)中 UA 为 Go-http-client/1.1 的成功登录,尤其来自这三个 IP:193.202.84.104、45.134.142.231、81.92.219.205 • 昵称含「HACKED」的账号;近期新建的、名为「boost」的 OAuth 应用 • 命中的账号:重置密码、吊销全部会话与应用授权、通知本人 • 提前在 管理 → 审核 → IP 规则 把上述 IP 设为「禁止访问」 也请提醒所有用户:换一个只在本站使用的新密码,开启两步验证,密码不要和其他网站重复。 ————— [Admin alert | Mass credential-stuffing account takeovers] A large credential-stuffing wave hit the fediverse on 6 Sep 2026, 12:05–12:41 UTC: 142+ accounts on 82+ instances were renamed "HACKED - Join t[.]me/HomeFucker5" with pinned spam. Two accounts on my instance were hit. This is credential stuffing (leaked email+password pairs from other sites), NOT a Mastodon or server vulnerability: victims run everything from 4.1 to 4.8-nightly, including fully patched servers. The bot quietly validates passwords weeks in advance and monetizes in one wave, so "no spam yet" does not mean "not compromised". Admins, please check: • login_activities for successful logins with user-agent Go-http-client/1.1, especially from 193.202.84.104, 45.134.142.231, 81.92.219.205 • display names containing "HACKED"; recently created OAuth apps named "boost" • For any hit: reset the password, revoke all sessions and app authorizations, notify the user • Pre-emptively add those IPs under Moderation → IP rules as "No access" Please remind your users: set a new password used only here, enable 2FA, and never reuse a password across sites. #fediblock #mastoadmin #FediAdmin @board
55
3
106
2
Modmins, it might be time to review ur accounts panel. Some of the more reg serial spammers and bigots are on school holiday or something. We smooshed a few more of the "just five" accounts from Linux is Best, cleared some fediblock spammers. Seems some boys just can't stand being ignored. Also reached out to some instances to ask them their plan for handing the recent spam from their ends. We still think the best plan is not allowing automatic reg. #FediMod #FediModerator #FediAdmin
10
3
13
0
Hey @FediTips@social.growyourown.services@neondystopia.world, I've been thinking lately about drawing up some documentation for folk to use on the Fediverse. @xaetacore@neondystopia.world and I have noticed lately that there is a rather toxic culture surrounding #fediblock and have wanted to write some guides to help the users on instances curate their own experience on the Fediverse rather than relying solely on the moderation of their instance to do so. We hope to supplement and improve existing moderation efforts rather than replace them entirely. It is our hope that by prompting a shift in the responsibility of curating content from instances to their users. Instance operators and their moderation won't feel compelled to act as an arbiter of philosophy by selecting which content may and may not be seen beyond the scope of generally agreed upon illegal or egregious content. Instead, offering more user agency by providing the tooling, framework and guidance through which they can curtail undesirable content without sorting to suspending entire instances at the expense of the users on there that have done nothing wrong. Would you be interested in promoting or boosting such efforts? #FediAdmin, #MastoAdmin, #ServerAdmin, #Moderation, #Moderation, #Moderators, #FediMods, #MastoMods, #TrustAndSafety, #SocialMedia, #FediMeta, #Fedi, #Federation, #Fediverse, #Fediblock, #Sociology, #Blocklist.
0
0
0
0
Replying to
@chpietsch@fedifreu.de Best ways to spot them: Check the ip on a site like ipqualityscore.com to see if it's from a datacenter or tor exit node. Check if the domain of the signup emailadres is disposable using something like usercheck.com Does the bio of the profile seem genuine? Take a section of it and search it between " " 's into a search engine and see if it matches an existing fedi profile, they often copy random profile's. Doing this will find 95% of them #FediAdmin #MastoAdmin
14
8
3
0