#spam

80 posts · Last used 1d

Boosted by @fedicat@pc.cafe

⚠️ Hinweis an andere #Fediverse-Admins: Wir sehen gerade eine auffällige Welle automatisierter Fake-Anmeldungen.

Muster:

  • Zufallsnamen wie FadRuwir, IpybVoxem, FaquCorar
  • Wegwerf-Maildomains wie qaoloty.com, 2mail.co, onionmail.org
  • auffällig viele Tor-/Proxy-Verbindungen
  • 0 Beiträge, 0 Follower
  • generische Bewerbungstexte wie „Ich möchte Teil der deutschsprachigen Community werden …“

Besonders perfide: Teilweise werden offenbar echte Bios anderer Fediverse-/Bluesky-Nutzer.innen kopiert. So wirkt die Anmeldung auf den ersten Blick erstaunlich glaubwürdig.

Ein einzelnes Merkmal beweist natürlich nichts. In dieser Kombination sieht es aber sehr nach automatisierter Account-Erstellung aus.

Schaut euch neue Registrierungen derzeit besser etwas genauer an und tauscht Beobachtungen gern unter den Instanzen aus.

#Mastodon #FediverseAdmin #Spam #Bots #Moderation

27
0
45
0
IFTAS is observing an uptick in PortalKombat activity. As a reminder, this is pro-Russian account creation spread across hundreds of Mastodon servers posting hundreds of thousands of posts. Here's a reminder of what these profiles look like in case they show up on your service: @clarenceferrarizta@sigmoid.social@sigmoid.social @YkoraIdy@social.roadfm.fr@social.roadfm.fr @pyjo@truthsocial.co.in@truthsocial.co.in To learn more, see https://about.iftas.org/2025/10/05/coordinated-pro-russian-propaganda-network-targeting-activitypub-and-atproto-services/ #BotSpotting #FIMI #Spam
Quoting

You’ll notice we’ve given the project a fresh name this year. We’ve shifted from “Moderator Needs Assessment” to the Social Web Operations Survey because the roles across our independent spaces have grown so much. If you’re managing server infrastructure, handling legal and compliance tasks, dealing with industrialised spam waves, or doing the heavy lifting of frontline content moderation, this survey is built for you.

We run this survey every year for a very simple reason: to gather the hard numbers and real-world feedback we need to support the people building community on the open social web. Your experiences tell us exactly how to structure our guidance, where to prioritise our safety tool development, and how to advocate for resources that keep independent spaces sustainable.

We’re completely network-agnostic. Whether your community lives on ActivityPub (Mastodon, Lemmy, Pixelfed), ATProto (Bluesky), Nostr, Matrix, or independent spaces on Discord and Reddit, your feedback is essential. Any platform, any protocol.

We want to hear from the entire spectrum of people keeping these communities and services ticking, from single user instances to major service providers.

We know everyone is stretched for time, so we’ve rebuilt the survey on Tally this year. It’s lightweight, fully mobile-responsive, EU-based, and takes under ten minutes to complete. Every single question is completely optional, and all responses are processed anonymously.

We’ll be running the survey for a full month, so there’s plenty of time to get your thoughts in and pass the link along to your peers.

Take the survey: https://tally.so/r/81MW6k

See the 2025 report: https://about.iftas.org/wp-content/uploads/2026/01/Social-Web-Trust-Safety-Needs-Assessment-Report-2025.pdf

Media Briefing & Fast Facts

The Social Web Operations Survey (historically the Moderator Needs Assessment) is an annual survey conducted by IFTAS to track the technical workloads, safety pressures, and operational resource gaps across decentral, independent networks (including ActivityPub, ATProto, Nostr, as well as volunteer-driven networks like Reddit and Discord).

Key Benchmarks (From our 2025 Survey)

  • 45% of independent platform administrators concurrently juggle three or more major operational responsibilities, acting as systems engineers, community policy creators, and frontline moderators all at once.
  • The ecosystem is facing a clear attrition of practitioners with a significant retention drop among administrators and safety team members who hit three to six years of activity without formal structural support.
  • Mass-automated spam waves and coordinated disinformation campaigns have officially overtaken individual user report processing as the number one daily time and infrastructure drain on platform operators.
  • The average ratio of active moderators to hosted accounts widened significantly over the past data cycle, shifting from 1 per 1,200 accounts to roughly 1 per 3,500 accounts.

Open quoted post
21
4
55
0

Okay, okay. Now I've officially seen it all. Spam has reached a whole new level of absurd comedy.

I've just received this at my BSD Cafe e-mail address:

Hello,

I recently came across the BSD Cafe website and, after running it through our AI-powered business analysis platform, I noticed several opportunities that could significantly improve your customer experience and revenue.

BSD Cafe already has a strong identity, but we believe there is considerable untapped potential.

Our AI can help you modernize the business by analyzing your current online presence, identifying underperforming areas, and automatically creating a strategy focused on increasing coffee sales, improving customer retention, and bringing more people into the Cafe.

In particular, our analysis suggests that BSD Cafe could benefit from:

  • A complete redesign of the customer journey, from first website visit to coffee purchase

  • AI-powered recommendations to increase the average number of coffees sold per customer

  • Modernization of the premises to create a more attractive, contemporary environment

  • Replacement of older coffee machines with newer, smarter, connected equipment

  • Automated marketing campaigns based on customer behavior

  • Dynamic pricing and personalized coffee recommendations

  • AI-generated content designed to attract new customers and increase foot traffic

  • We can also analyze your current coffee infrastructure and recommend modern alternatives capable of improving efficiency, reducing maintenance costs, and delivering a more consistent product.

Our platform handles most of the process automatically. You don't need marketing expertise, technical skills, or even detailed knowledge of your customers. The AI continuously learns from their behavior and adjusts the strategy accordingly.

Based on businesses with a similar profile, we believe BSD Cafe could substantially increase both coffee sales and customer engagement within the first few months.

I'd be happy to arrange a short 20-minute call and show you what our AI has already discovered about BSD Cafe.

Would Tuesday or Wednesday work better?

#Spam

20
1
16
0
Hach, diese „verifizierten“ #Gaza-Accounts, die wortreich ihr Leid klagen, dabei die Ressourcen haben, das Ganze mundgerecht zu präsentieren und ganz nebenbei Scripte laufen zu lassen, die irgendwelchen Accounts folgen - natürlich lediglich aus persönlichen Interesse oder um schon einmal deutsch zu lernen. Diese Schmeißfliegen am Arsche des realen Leids. Aber ist ja Gaza, also links, sowas sperrt man nicht. Könnte ja wahr sein, bei #Spam halt Benefit of Doubt. 🤮
4
1
0
0
Seguimos actualizando la lista de IPs que están haciendo un ataque de registros de spam al fediverso, hoy recibimos en lo que va de la mañana, más de 150 intentos de registro que ya fueron bloqueados y agregados a la lista. La cosa se intensificó hoy. Si sigue asi, vamos a tener que deshabilitar los registros hasta nuevo aviso. El tema de las invitaciones todavia no lo tenemos definido, así que si conocen a alguien que estaba queriendose hacer una cuenta, ahora es el momento. Deshabilitar los registros es una medida que debe tomarse como último recurso, porque de esta forma logran que todos cerremos filas y el fediverso no admita nuevas cuentas logitimas y por lo tanto, pare de crecer. https://undernet.uy/blocklist/mastodon-spam.txt #mastodon #spam #blocklist #undernet #registros
13
1
7
0
apparently this flood of "automated protocol delivery probe" spam signups comes from https://sendflood.com if we mass report them to their registrar's abuse thing they should stop spamming us? the site was only made like a week ago sources for this info: • https://wubba.boo/notes/ar9jffw36cmi1qh2 • https://bardicperspiration.club/@Overgoddess/117288027775455205 • https://fosspri.de/@joshix/117286960234031491 as per the attached image their registrar's abuse email is abuse@spaceship.com and abuse phone number is +1.9854014545 #FediAdmin #MastoAdmin #fediblock #spam
8
1
16
0
Boosted by @fedicat@pc.cafe
Quick heads-up for other Mastodon admins: this registration spam wave isn't over yet. On lsbt.me, we first saw a flood of API registrations using Python/aiohttp. The telltale signs were usernames following the pattern bp plus 16 hex characters, and the sign-up reason was always "Automated protocol deliverability probe". A narrow block on that user agent stopped the first wave. Today, however, five new registrations came in with the same usernames and the same sign-up reason. This time the bot simply identified itself as Chrome 126. That's exactly why a user agent is only useful as a short-term filter. It's a header the client can set to anything. The requests go to POST /api/v1/accounts. This endpoint lets client apps create a new local account directly in the app. No app needs it for OAuth connections to existing accounts. #FediSuite doesn't use it either. It registers itself via /api/v1/apps, obtains consent via /oauth/authorize, and then works with a user token. Regular sign-up through the Mastodon website is also handled separately via POST /auth. So I've completely disabled API account creation on lsbt.me. Web sign-up, OAuth, and existing clients keep working as before. Anyone who wants a new account just signs up once on the web as usual and can then use any client. If you'd also rather not offer this optional native sign-up path, you can add the following to your Nginx server block, before the general location / block. The example assumes the @proxy location that many Mastodon Nginx configs already include: location = /api/v1/accounts { limit_except GET { deny all; } try_files $uri @proxy; } This returns a 403 only for POST /api/v1/accounts. The read-only GET endpoint remains reachable. As always, run nginx -t afterwards and only reload once the test passes. #Mastodon #Fediverse #MastoAdmin #FediAdmin #FediMod #FediBlock #Moderation #Registration #Spam #Nginx #SelfHosting #SysAdmin #ActivityPub
0
1
6
0
Boosted by @fedicat@pc.cafe
Dear #Fediverse and #Mastodon admins currently there is a massive wave of spam registrations everywhere in the fediverse. For mastodon, I have a solution that works for me: Create new file /etc/nginx/conf.d/lsbt-registration-spam.conf: map "$request_method:$uri:$http_user_agent" $block_lsbt_registration_spam { default 0; ~^POST:/api/v1/accounts:Python/3\.[0-9]+\ aiohttp/ 1; } Add to the server block in /etc/nginx/sites-available/mastodon: location = /api/v1/accounts { if ($block_lsbt_registration_spam) { return 403; } try_files $uri @proxy; } @michaela@lsbt.me @njakob@lsbt.me @MikeGorden@lsbt.me#fediverse #mastodon #registrationspam #spam #registration #Automatedprotocoldeliverabilityprobe #lsbt
28
3
34
5
⚠️ #SW_ISAC_ADVISORY Numerous services are seeing accounts created by autonomous GenAI agents hosted at ilands.ai with no discernible human control. These accounts declare themselves to be non-human and unattended. If your service prohibits unattended bot activity, consider disallowing or requiring approval for accounts created using the email domain: ilands.app #SyntheticMedia #Spam
50
1
84
1
Returning readers will remember my "Eighteen years of greytrapping" piece (https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html or tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html and may also remember that it has numbers and graphs. It's now been more like 19 years of the activity, and the numbers and graphs are refreshed as of end of July. #spam #antispam #spamd #openbsd #greylisting #greytrapping #security #cybercrime #cybersecurity #smtp #email
1
0
2
0
I tried enabling open registration on pixelfed.social and a slew of spam accounts (3-4 character usernames) were registered. The interesting thing is I removed SEO spam incentives a month ago, hiding bios and website urls from meta tags and the profiles if you are logged out (aka crawlers) I am working on a few solutions to mitigate this, and am considering the ability to leverage AI APIs to score new account risk and auto-moderate them accordingly. Controversial or adversarial? #spam
7
4
3
0
It’s True. We Underreport the Volumes of Resources That Cybercriminals Use We’ve noted in our Interisle landscape studies that our figures underreport the numbers of domain names, IP addresses, and URLs, and free web site user accounts that cybercriminals have misused for phishing, malware and spam. Everyone underreports. Today, I’ll explain what Interisle takes into consideration when we say that our research underreports certain figures. https://interisle.substack.com/p/its-true-we-underreport-the-volumes #cybercrime #dnsabuse #phishing #malware #spam
0
0
0
0