#fediblock

228 posts · Last used 23h

Fediblock, Ukraine, War, Denial
0
34
0
0
Fediblock, Transphobia, Ableism + Inappropriate
4
1
7
0
#Fediblock ieji.de: admins allow for antisemitism and trollish defence of Nazism under the pretext of "free speech". attached: screenshots of the offending posts, CW antisemitism, Nazism, mention of sexual violence, and of conversation with the main admin where they explain they're not gonna take any action. archives of reported posts: https://ghostarchive.org/archive/pHWOU https://ghostarchive.org/archive/8muuL #FediAntisemitism
22
4
32
1
UPDATE: As per 11:45am I have deleted all the statuses below from the mothership instance, what's the point dude is obsessed with hidding his trail and this blog post already copies every single status. Try to censor this dude. Log trail of every toot I posted You cannot silence me without breaking federation mate, I'm like Lucy, I'm everywhere (except in a pendrive). I can keep reposting again and again and again until you explain yourself. All I did was to thank you. ADHDers right, we […]
3
0
4
0
nazi instances, harassment, queerphobia, pedopornography, antisemitism, racism, eugenism.
2
4
16
0
Replying to
JadeChimera - My plea, fediblock
0
13
0
0
apparently this flood of "automated protocol delivery probe" spam signups comes from https://sendflood.com if we mass report them to their registrar's abuse thing they should stop spamming us? the site was only made like a week ago sources for this info: • https://wubba.boo/notes/ar9jffw36cmi1qh2 • https://bardicperspiration.club/@Overgoddess/117288027775455205 • https://fosspri.de/@joshix/117286960234031491 as per the attached image their registrar's abuse email is abuse@spaceship.com and abuse phone number is +1.9854014545 #FediAdmin #MastoAdmin #fediblock #spam
8
2
16
0
Boosted by @fedicat@pc.cafe
Quick heads-up for other Mastodon admins: this registration spam wave isn't over yet. On lsbt.me, we first saw a flood of API registrations using Python/aiohttp. The telltale signs were usernames following the pattern bp plus 16 hex characters, and the sign-up reason was always "Automated protocol deliverability probe". A narrow block on that user agent stopped the first wave. Today, however, five new registrations came in with the same usernames and the same sign-up reason. This time the bot simply identified itself as Chrome 126. That's exactly why a user agent is only useful as a short-term filter. It's a header the client can set to anything. The requests go to POST /api/v1/accounts. This endpoint lets client apps create a new local account directly in the app. No app needs it for OAuth connections to existing accounts. #FediSuite doesn't use it either. It registers itself via /api/v1/apps, obtains consent via /oauth/authorize, and then works with a user token. Regular sign-up through the Mastodon website is also handled separately via POST /auth. So I've completely disabled API account creation on lsbt.me. Web sign-up, OAuth, and existing clients keep working as before. Anyone who wants a new account just signs up once on the web as usual and can then use any client. If you'd also rather not offer this optional native sign-up path, you can add the following to your Nginx server block, before the general location / block. The example assumes the @proxy location that many Mastodon Nginx configs already include: location = /api/v1/accounts { limit_except GET { deny all; } try_files $uri @proxy; } This returns a 403 only for POST /api/v1/accounts. The read-only GET endpoint remains reachable. As always, run nginx -t afterwards and only reload once the test passes. #Mastodon #Fediverse #MastoAdmin #FediAdmin #FediMod #FediBlock #Moderation #Registration #Spam #Nginx #SelfHosting #SysAdmin #ActivityPub
67
6
65
4