Email or username:

Password:

Forgot your password?
Top-level
Eugen Rochko

All of the spam accounts have been suspended, reports queue cleared, IPs and e-mail domains used in the spam wave banned. We're continuing to monitor the situation and analyzing the pattern.

72 comments
DJGummikuh

@Gargron did this attack involve any kind of exploit (for mass-sending or something) or did they just manually register accounts and started spamming with them?

Mer-fOKxTOwl

@DJGummikuh @Gargron as it seems they set up some server that automatically registered ~600 accounts (at least my instance admins wrote they blocked that many) and then let those send the spam.

Stefan Ritter :verified:

@Gargron All the users on my server who reported spam are now banned. It's so easy 😎

Luis Carlos

@Gargron May the force be with you and anniquilate the dark force of the spammers!

gh0sti :pika:

@Gargron what if you limited supported email accounts to only popular ones? I’m wondering if that would help.

Orca🌻 | 🏴🏳️‍⚧️

@gh0sti@mastodon.social @Gargron@mastodon.social Please don't. People has been going through great trouble to not using big companies' services, don't make it even bigger.
Also Mastodon (or fediverse, take your pick) itself is not that "popular", can you imagine you giving your Mastoson account to someone only being replied "Nah that doesn't count, give me a Twitter or Facebook handle"?

Mer-fOKxTOwl

@gh0sti @Gargron that is exactly the opposite of the fedi's idea. :/ limited registrations or some properly designed capcha should do most of the trick.

Huggenknubbel :apache:

@gargron the Spamposts sould be deleted. to minimize the sackgängerheit.

gh0sti :pika:

@Gargron thanks for cleaning up the mess quickly.

Riquiñez :mastodance:

@Gargron Maybe if they don't have a big instance to attack, and instead were 12 medium instances... 🤔

[DATA EXPUNGED]
sazanlip 🍁 #ZИНК

@Gargron Thank you from a neighboring instance, glad you've purged this situation so quickly, they didn't have a chance to knock into my DMs!

Orca🌻 | 🏴🏳️‍⚧️

@Gargron@mastodon.social email domains? They registered their spam accounts using their own email server? 🤔

Andrew David Baron

@Gargron get your Pokémon orbs out and capture those spamming beasts!!! 😆

moomendemol! :unverified:

@Gargron ich kann anhand der weiter eintrudelnden Meldungen nicht bestätigen, dass alle Accounts gesperrt wurden

Chris Williams

@Gargron Thanks for the quick response and all the work!

⚜️Δρakakiς🍁

@Gargron Thanks from all corners of the 'Verse ...
(as if the 'Verse had corners)

Raphael

@Gargron That was quick! Good luck handling the stuff!

Juan Villela

@Gargron Damn, that was fast. Nice job! 💪🏽

Hughster

@Gargron The message I got was only in the inbox for a couple of minutes after I reported—thanks for the quick response.

Dokape

@Gargron ah, thanks, i just saw the notifications on iOS, but didn’t found the toots. Thanks for your hard spam fighting.

Steve Hersey

@Gargron
Thank you for dealing with this. An admin's work is never-ending...

Yann 不停 Heurtaux

@Gargron Thank you and the Moderation & DevOps teams. You all rock 😘

Sam

@Gargron

Thanks, I reported and blocked the ones I got :)

HistoPol (#HP)

First-class Service! ⭐️⭐️⭐️⭐️⭐️

Thanks @Gargron & team.

If everyone reports spammers immediately, they theoretically get but one try. 😀

mastodon.social/@Gargron/11031

FinchHaven

@Gargron

Will you be doing a full, complete and honest postmortem?

What happened that you hadn't anticipated and had clearly not been prepared for?

What was the vector of attack?

And do you still want to auto-signup every user of the Mastodon app to the instance *you* control?

Still think that's a good idea -- even if it's not directly related to this spam attack?

Nicole Parsons

@Gargron

You know you're on the right track when you're making billionaires nervous enough to orchestrate & fund a spam attack.

Cyber warfare is funded.

Podsafepilot

@Gargron Nice work, thanks to everyone involved. 👍🏻

Gemini6Ice

@gargron thanks for getting on top of it!

this is the kind of quick community action we NEVER got to see on Twitter

Tim

@Gargron thx, jack never reacted when I reported spam 😉

Mario

@Gargron thank you! I’m glad to be a Patreon supporter!

Covidiocracy

@Gargron Thanks for taking care of that so quickly! I got one and thought, for better or for worse, spammers targeting Mastodon means it’s on more peoples’ radar, which is ultimately a good thing.

DELETED

@Gargron please be very careful regarding IP or even IP-range bans, as I - like many others - completely RELY on working access using VPN services!
Many IPs are used by several people - who not all are necessarily spammer. Same goes regarding bans of whole email domains, just because a spammer had also an account on the same email service.

Lou Reynolds

@Gargron thank you and the team for your work defending the platform.

Manish

@Gargron Thanks the team is doing awesome. I wish to be part of the team.

Go Up