ErikUden, (edited ) to random
@ErikUden@mastodon.de avatar

To all Fedi Admins Currently Being hit with a Spam Wave:

This kind of spam is now over! Unmute all the instances no longer on my list!

I've just released v4.0.0 of The UNmute List! I'd be very happy about a small donation because I have very little time and I cannot really justify working on this list with my current schedule :mycomputer:​

There is a new type of spam, the same instances are affected as before. Those responsible in Japan are said to have been arrested.

Without further ado...

Limit these instances:

[Full List of Affected Instances Here]

Just get the list to download and import here.

Simply import this list and you'll mute the 47 worst spam instances currently known to me! I've worked on it for multiple weeks, sometimes ~9 hours at a time verifying all lists sent to me manually.

Limit first, defederate only in worst situations!

Consider re-federating with and un-silencing any of the mentioned instances once the spam is mitigated. The admins of some of these may have just been asleep when this all started.

Ban Spam Accounts via their E-Mail Domain

Block the following E-Mail Domain and whatever temp Mail provider it resolves to: chitthi.in

Just to be safe, block these ones too (same provider)

  • mailto.plus
  • fexpost.com
  • fexbox.org
  • mailbox.in.ua
  • any.pink

All our spam accounts came from these E-mails.

Since you probably have some of these accounts sleeping:

https://[your-instance.tld]/admin/accounts?email=%25%40chitthi.in there just select all and press “Ban”.

Find Remaining Spammers

I've seen instances that fixed the spam issue but began being hit later again. The spammers might use new E-Mails, so here is a way to find and block them anyway:

https://mamot.fr/@vincib/111946701929274350

IP Bans and TOR

These spammers seem to be using the TOR Network as all of their IPs are TOR Exit Node IPs, hence an idea (with some collateral damage if executed) would be to ban all TOR exit node IPs for sign ups. I am personally against this idea as you'd also prevent users who simply wish to stay anonymous online (political refugees, leakers of important documents, etc.) from using your platform. For now, simply banning every user using a particular Spammer IP will not help and will merely ban users that try to stay anonymous! Not necessarily the spammers.

How To Block All Temp E-Mails in the Future

If you want to prevent this from ever happening again, you should block E-Mails from Temporary Mail providers all together:

Because of this, hessen.social, for example, was not affected by the spam attack! They had already banned the email domain the spammers used ages ago.

In future updates on Mastodon, maybe Admins can simply click a button that says “Ban Temp E-Mail Providers” Automagically from the E-Mail Menu? There could be E-Mail categories that can be banned, such as temporary mails.

Why did this happen?

The real reason hundreds of us spent hours of our days during the spam on mitigating it is the following:

Cyberbullying Gone Global: Fediverse Spam and Operation Beleaguer

This is the full exposé @cappy has been working on regarding the February 15th Spam Attacks!

Thank you @BrodieOnLinux for mentioning this post in a video!

Good luck, everyone!
Thanks for participating in the Fediverse Experiment!

#FediBlock #FediAdmin

aral, to threads
@aral@mastodon.ar.al avatar

Dear @Gargron,

A fediverse server called Threads is violating mastodon.social’s second server rule:

“2. No racism, sexism, homophobia, transphobia…
Transphobic behavior such as intentional misgendering and deadnaming is strictly prohibited.”

https://glaad.org/smsi/report-meta-fails-to-moderate-extreme-anti-trans-hate-across-facebook-instagram-and-threads/

Can you please defederate from this server to protect the trans people on mastodon.social?

Thank you.

PS. It’s run by these guys: https://techcrunch.com/2024/03/26/facebook-secret-project-snooped-snapchat-user-traffic/

ada, (edited ) to random
@ada@blahaj.zone avatar

Well, that didn't take long. Though threads.net is not yet federating with the wider fediverse, they are currently home to several hate groups such as Libs of Tik Tok and their ilk. We will not federate with any instance that knowingly chooses to house hate speech, so a full defederation of threads.net has been made by blahaj.zone

michael, (edited ) to random
@michael@thms.uk avatar

PSA: It looks like mastodon.social has implemented hCAPTCHA on their signups yesterday.

So, if you have limited / suspended mastodon.social because of the spam issue, you may wish to reconsider this.

This will also likely mean that spammers will move to different instances (already seeing them targeting mastodon.world).

You may wish to consider implementing hCAPTCHA yourself to protect your own instance, and here is the relevant PR:

https://github.com/mastodon/mastodon/pull/25019

The reason I'm suggesting this, is because if you are a small/medium instance with open registrations, and spammers find and abuse your instance, I imagine that other instances will limit/suspend your instance without hesitation, given how willing some were to limit/suspend the much larger mastodon.social.

But do note this comment on the PR:

“To give some context to people seeing this: this is an emergency feature backport from Glitch SOC to help mitigating an ongoing spam wave, this feature may not make it in a next release, or with significative changes.”

Edited to add: multiple people have rightly commented on the accessibility concerns with hCaptcha: hCaptcha is really really really bad for blind and visually impaired people.

Please have a look at this excellent reply for more details:

https://dragonscave.space/@Mayana/110383119877022255

Gazimoff, to random
@Gazimoff@gamepad.club avatar

If you run a Mastodon server, especially if it's small and only lightly moderated, I would STRONGLY suggest enabling 'Approval required for sign up'. It means that your server is MUCH less likely to become the next source of spam in this wave we're seeing.

sam, to random
@sam@urbanists.social avatar

Introducing Citadel! Citadel makes it quick and easy to suspend spammers and send reports to their admins - in one click!

Eventually Citadel will have more tools, but I wanted to get this out ASAP to help server admins.

Give it a shot: https://citadel.samw.dev

(also note that after you log in you will ned to reload the page)

video/mp4

paul, to random
@paul@oldfriends.live avatar

Users and friends, filtering hashtag 診断メーカー works to keep the current wave of spam out of your timeline, mentions, etc, as this example shows.

Over 4.4K in the last 24-hours. I know many admins have been combating it all night to keep it out of your timeline.

Might not be a bad idea to set the filter up while #MastoAdmin's combat the problems.

If you're not curious, hide completely instead of just a warning as shown in the red circle..

#Spam #FediBlock

timeline showing spam behind a hidden
timeline with a hidden post exposed

atomicpoet, to internet

Yet another question people are asking me: "How can I, a common person, help hasten the demise of through ?"

Again, I want to re-emphasize this. is not an all-purpose tool. It's useful as a hammer. But in this scenario, we don't just need a hammer. We need drills, pliers, saws, and blowtorches.

That said, we must protect communities that choose to defederate from Meta. Which means that if those servers don't want to receive messages from any Meta-owned services, we must not only be respectful of that, we should make damn sure that those servers are quarantined from Meta. So much of the success of fighting Meta will require safe spaces from Meta.

The next thing we need is lots and lots of nodes. Currently, we only have ~25,000 nodes on the Fediverse but we need more. Preferably, these nodes should be small, agile, and well-moderated. If you have the finances and/or skill to run a node, it's important that you do so. To compete with Meta, we need to build scale -- and the easiest way to build scale is by adding more nodes to the Fediverse.

What will also be key is lobby servers. These will be servers specifically set up for migrants from Meta-owned services to help onboard them towards the rest of the Fediverse. To run such a lobby server, they need to be welcoming, moderated well, and free of the elitists and gatekeepers that poison so much of the Fediverse currently.

How to get people from Meta to try out the rest of the Fediverse? We need people willing to be ambassadors on who are ready and willing to evangelize the rest of the Fediverse. Folks like @tchambers are very good at this on Twitter, and I have no doubt that we can do the same with P92. Except this time we'll have the benefit of federation already happening 😉

Now if there's one thing I've learned about the growth of the Fediverse it's that bad corporate decisions pay dividends. We've already experienced waves of migration from Tumblr, Twitter, and Reddit. And I have no doubt that it's only a matter of time before Meta makes another corporate mistake -- as they tend to do.

In which case, we need to strike fast. When another Cambridge Analytica happens, we need to remind everyone on Meta about the lobby servers that are on standby, and ready to take them on. Unlike previous migrations, let's not be unprepared for this. Let's be especially prepared since Meta plans to join the Fediverse.

Finally, we need more devs. Specifically, we need devs willing to build innovative server and client software that takes aim at Meta. And to do that, we need to support the devs that currently exist -- show evergreen devs pondering whether they should invest here that we, as a community, are appreciative of our current devs.

If you like , , , , etc., it's important that you open up your hearts as well as your wallets and fund the next stage of Fediverse development.

This will take a lot of work. But if you want to fight Meta, challenge their dominance of social media, this is what must be done.

Personally, I'm hyped about the future of the Fediverse -- regardless of whether Meta eventually lives to tell the tale.

aral, to fediverse
@aral@mastodon.ar.al avatar

snarfed.org and brid.gy for bridging fediverse folks to Bluesky against their will (and in likely contravention of GDPR in the EU) with typical Silicon Valley techbro sense of entitlement:

“[O]pt in results in far fewer users, and users are critical for a bridge to be useful.”¹

Relevant GitHub issue: https://github.com/snarfed/bridgy-fed/issues/835

¹ https://snarfed.org/2023-11-27_re-introducing-bridgy-fed

HT @homegrown

mastodonmigration, (edited ) to random
@mastodonmigration@mastodon.online avatar

Over the last few hours Mastodon treasure @Teri_Kanefield has been the victim of very vulgar harassment on her server law-and-politics.online.

Mastodon lets users create their own instances, but you need to block bad instances.

Fortunately, Mastodon provides support for this:

New MastoAdmin Guide To Banning Servers >>> https://writer.oliphant.social/oliphant/new-mastoadmin-ban-list-fediblock

Oliphant.Social Mastodon Blocklists >>> https://writer.oliphant.social/oliphant/the-oliphant-social-blocklist

Other recommendations, specific instructions?

pixelfed, to random
@pixelfed@mastodon.social avatar

⚡ Admin Dispute Resolution

We know it's challenging to run an instance, and sometimes disputes and blocks happen between instances.

We are launching a dispute resolution service for (pixelfed) admins to resolve disputes in a transparent and public way.

It will be built-in to the admin dashboard, and very easy to use!

Imagine being able to resolve mentions by proving proper action was taken, and in an auditable fashion!

Let's do better, together ❤️

cappy, to Cybersecurity
@cappy@fedi.fyralabs.com avatar
aurynn, to random

Hello fedi admins

In case you needed yet another reason to block newsie.social, and every other site that Jeff runs, newsie.social has now decided that platforming far-right hate is appropriate:

https://newsie.social/@newsmax

rolle, (edited ) to random
@rolle@mementomori.social avatar

Can't stay quiet about this as much as I don't like namedropping or any kind of blaming even when there is a reason. But there is this one Mastodon admin who refuses to take any responsibility of his server. He literally said on other social site: "I'm not doing anything about it, just writing this comment is too much trouble for that shit."

I confonted him and said: "So you want to give free server capacity to criminals and spammers. Because quite a few vulnerabilities have come out since 4.1.4. So you want to let the spambots continue their work in peace? Good luck with that 🫡"

He answered "Yes" and blocked me. This is disturbing to say the least. Don't know how to react.

You should probably defederate mastodo.fi.

Source (in Finnish): https://www.threads.net/@tero.ojala/post/C3nueFKICzw

Siph, to random

there are nazis raiding the mutualaid gup.pe group and that’s an excellent fodders for instances that slipped through your bans

Here’s the ones I added to my blocklist on my own server:

breastmilk.club
seal.cafe
glee.li
clubcyberia.co
crucible.world

ramin_hal9001, to threads
@ramin_hal9001@emacs.ch avatar

is / using the old 4-E strategy strategy to destroy Mastodon:

  1. Embrace: what they are doing now, launch a competing but compatible service with that of Mastodon. The vast majority of users, most of whom don't care about the privacy and intimacy of the Mastodon network will go with the brand with the most name recognition.
  2. Extend: attract users to their centralized network with features like search, which they have the resources to do but the rest of the Mastodon network does not. But also include features for tracking and advertising, sell this as a good thing, "a better place to grow your perasonal brand, your business."
  3. Extinguish: after attracting a critical mass of users large enough to decimate the user base of the competing Mastodon network, queitly remove compatibility with the Mastodon network, this will effect only 10% of Mastodon users because the other 90% will be on Threads. "Who cares if we lose contact with that tiny minority of old Mastodon users, they should have just joined Threads by now anyways, they still can. It has search, and more people voted for it with their patronage it, and you don't have to think about what instance to join, its easier!"
  4. Enshittification: without any real competition to keep people from leaving for an alternative, start exploiting users for more and more content for ad revenue, exploit advertisers with ever-increasing costs of ad revenue.

They are scared to death about losing control over the Internet that they had gained over the past 15 years or so, and they are fighting to take that control back for themselves. We built this, but now a corporation like Meta/Facebook feels they have the right to exploit it for all its riches until it is destroyed.

Don't let it happen. is the only way to protect our home-grown community from corporate take-over.

nullagent, to random

Blocking detroiriotcity.com for hate speech and lack of moderation.

PartyOn is a proudly Black run mastodon instance. We don't tolerate hate speech, and we're continuing to build tools to rapidly resolve these types of reports. Another one goes into the training dataset.

You can tip our mod team below, it helps keep the lights on and pisses off the racist.

https://ko-fi.com/dataparty

custodian, to random

We have suspended access to the account associated with Newsmax, a far-right disinformation outlet from the US, and have limited (silenced) the 'newsie.social' instance as a whole for platforming such nonsense, including the rejection of all media from that instance.

https://en.wikipedia.org/wiki/Newsmax

https://newsie.social/@newsmax

If you are a news outlet, we strongly recommend that you move to your own instance, as others, including The Markup and the Texas Observer, have already done.

selzero, to random
@selzero@syzito.xyz avatar

Remember this TERF JK Rowling supporter Dick Morrell?

So many people blocked him for being a giant TERF that his account became useless.

Well, he has a new account and is continuing that BS agenda.

Let people know so they can block early if they need protection from trash like this🙏

https://social.vivaldi.net/@cloudguy/112095941420104781

Dick Morrell @cloudguy she wasn't attacking minorities It was intolerance that caused reaction and a demonstration by many of an inability to deal with the reality of life She didn't do anything for anyone to react to The only thing that happened was a bandwagon arrived for folk to demonstrate vocal intolerance and lack of community perspective Starting with those inane enough to block her

stux, to random
@stux@mstdn.social avatar

This is a real, real bad one. It seems an instance dedicated to CSAM and should be suspended right away!

"pettanko.art"

paul, to OpenAI
@paul@oldfriends.live avatar

IP block ranges if you want to block them from your instance and scraping your content. I saw Mastodon devs added something to block via robots.txt a few days ago. Here are the IP ranges:

20.15.240.64/28
20.15.240.80/28
20.15.240.96/28
20.15.240.176/28
20.15.241.0/28
20.15.242.128/28
20.15.242.144/28
20.15.242.192/28
40.83.2.64/28

https://openai.com/gptbot-ranges.txt

https://www.theverge.com/2023/8/7/23823046/openai-data-scrape-block-ai

https://github.com/mastodon/mastodon/pull/26396

rain, to internet

Admin announcement:
As of today, this instance blocks known domains associated with Meta's , in accordance with the anti-Meta Fedi Pact (https://fedipact.online/)
In effect, this instance does not federate with the domains threads.net or threads.instagram.com. Further associated domains will be blocked, if discovered.

We are not personally against the users of Project 92, we are against Meta. We will not be giving them a chance. Their work is a threat to the Fediverse, as it has been a threat to other social spaces and open communities for years prior. They are not welcome in our homes.

MOULE, (edited ) to internet

CONFIRMED: "Threads" is the name of 's new -enabled social media, also codenamed , , & .

URL: https://threads.net
IPv4: 157.240.22.63
IPv6: 2a03:2880:f231:c5:face:b00c:0:43fe

I recommend everyone block threads.net in their domain blocking lists, and every in the to all Meta's IP addresses at the firewall level before they go live on the on July 6th: read https://mastodon.moule.world/@MOULE/110586556696261405 for more info!

MOULE,

Here's how to threads.net on 4.1.0 and above (I'm unsure about how to do this on other , sorry:

FOR USERS:

  1. Create a txt document
  2. Type "threads.net" (without quote marks)
  3. Save as "blocked_domains.csv"
  4. On Mastodon, go to Preferences > Import and Export > Import.
  5. For input type select "Domain blocking list".
  6. Upload blocked_domains.csv.
  7. Click "Merge" so threads.net is added to your block list. Do NOT click "Overwrite"!
  8. Click "Upload"!
MOULE,

Here's a list of and commands for admins can copy and paste into their server's command line to bulk-block all packets to and from IPv4 and IPv6 addresses owned by :

https://drive.google.com/file/d/16syQy-HMIb__cEBua6y-ZZDYGfXwYf01/view?usp=sharing

Sources:

  1. https://www.asnlookup.com/ipv4/31.13.24.0/ (including other CIDRs listed on the page)
  2. https://datakra.sh/assets/lizard.txt (the 2,024 domains listed here have been found to use either of 26 IPv4 addresses, which I have updated the list on my Google drive with.)

ErikUden, (edited ) to random German
@ErikUden@mastodon.de avatar

Hallo alle Fedi-Admins die Probleme mit Spam haben!

Die Mute-Liste 2.2.2

Ich habe die Spam-Liste aktualisiert und ~104 zusätzliche Instanzen gefunden, die weiterhin spammen! Ich habe, mit viel Hilfe von anderen Fedi Admins, die Instanzen in einer Liste zusammengestellt, die sie stumm schaltet und nicht von ihnen deföderiert!

Ich würde mich sehr über eine kleine Spende hier freuen, da Ich wirklich hart und lange an der Erstellung dieser Liste gearbeitet habe, was Ich angesichts meines aktuellen Zeitplans kaum rechtfertigen kann! Dankeschön!

Es gibt eine neue Art von Spam, die gleichen Instanzen sind betroffen wie vorher. Die Verantwortlichen in Japan sollen verhaftet worden sein.

Downloaded die Liste hier.

Anleitung und Erklärung zur Liste.

Ist diese Liste importiert ist ein Großteil des Spams vorbei. Das ganze ist für euch leicht, geht mit einem klick! Zudem wird keinerlei Instanz für immer geblockt, keinerlei Follower etc. zerstört oder deföderiert, sondern nur stummgeschaltet. Das ist sehr leicht umkehrbar.

Ihr könnet diese Liste einfach importieren, indem ihr auf https://yourinstance.tld/admin/export_domain_blocks/new geht und yourinstance.tld durch die Domain derer Instanz ersetzt, von der ihr der Administrator seid!

Alternativ könnt ihr auch auf Einstellungen => Moderation => Föderation => Importieren drücken, um diese Liste zu importieren.

Beachtet, dass zwar alle Instanzen mit einem Klick importiert werden können, dass aber diese Instanzen einzeln entfernt werden müssen, wenn der Spam vorbei ist.

Beachtet auch, dass es nur Sinn ergibt, diese Liste zu importieren und die Spam-Instanzen stumm zu schalten, wenn ihr euren Spam lokal und nachhaltig blockiert habt, wie hier beschrieben.

Auf ein Spam-Freies Fediverse :apartyblobcat:​ !

FediAdminDE

ErikUden, (edited )
@ErikUden@mastodon.de avatar

Hello all Fedi Admins who have problems with spam!

The Mute List 2.2.2

I have been updating the spam list and found ~104 additional instances that continued spamming! I, with lots of help of other Fedi Admins, have compiled the instances into a list which mutes them, and does not defederate from them!

I'd highly appreciate a small donation here as I've worked really hard and long on creating this, which given my current schedule I can hardly justify! Thanks!

There is a new type of spam, the same instances are affected as before. Those responsible in Japan are said to have been arrested.

Download the list here.

Instructions and Explanation of the List.

Once this list is imported, most of the spam is gone. The whole thing is easy for you, with just one click! In addition, no instance is blocked forever, no followers etc. are destroyed or unfollowed, only muted.

You can simply import this list by going to https://yourinstance.tld/admin/export_domain_blocks/new and replacing yourinstance.tld with the domain of the instance you are the administrator of!

Alternatively, you can also click on Settings => Moderation => Federation => Import to import this list.

Note that although all instances can be imported with one click, these instances must be removed individually when the spam is over.

Also note that it only makes sense to import this list and mute the spam instances if you have blocked your spam locally and permanently, as described here.

Here's to a spam-free Fediverse :apartyblobcat: !

FediAdminEN

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • mdbf
  • magazineikmin
  • InstantRegret
  • hgfsjryuu7
  • Durango
  • Youngstown
  • slotface
  • everett
  • thenastyranch
  • rosin
  • kavyap
  • khanakhh
  • PowerRangers
  • Leos
  • DreamBathrooms
  • vwfavf
  • ethstaker
  • tacticalgear
  • cubers
  • ngwrru68w68
  • modclub
  • cisconetworking
  • osvaldo12
  • GTA5RPClips
  • normalnudes
  • tester
  • provamag3
  • All magazines