Email or username:

Password:

Forgot your password?
Top-level
Eugen Rochko

We're talking about an account that was created through normal means, that is not really distinguishable from just any random account, but contains something like "hello 1.2.3.4|" in its bio. The way they seem to be used is that some botnet software checks the profile to get its commands that way. It is not a Mastodon vulnerability and I don't think its specific to Mastodon either.

3 comments
🍵 wizard

@Gargron definitely sounds like it could be implemented with any platform such as Facebook or Twitter

gh0stph1sh3r

@Gargron I've seen this often on Instagram, but in the comments section. It's an established TTP for C&C

Richard jasmin

@Gargron api automation issue. stop the bots? mandate gplish human accounts.

Go Up