jrollans.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Due to the ever-growing amount of LLM-generated subscription requests (that have to be moderated manually), I'm considering setting Mapstodon.Space to invite only.
I'm not fond of this at all but it's getting more out of hand everyday. Any suggestion on how to deal with this fake accounts crap flood will be very welcome. (Bonus points if you're on the moderation team of another instance and you are dealing, or have dealt with, a similar situation!)
Oh, so the bot account flood reached #GlitchySocial as well. I just didn't notice it because I got no emails...
We had a big wave of automated Mastodon signups with very predictable usernames.
I first tried the sledgehammer approach and blocked known VPN ranges at the firewall.
It worked.
It also blocked legitimate ProtonVPN users. 😬
So I replaced that with a tiny custom Mastodon validator that rejects the actual abusive username pattern instead.
Much cleaner: block the abuse, not the transport.
How-to + code:
https://gist.github.com/chofstede/a422427570004719196cde948521dd04
#Mastodon #Mastoadmin #Fediverse #SysAdmin #Ruby #Rails #Security @tux @AlienJay @aping
I kept getting a 500 error when I tried to post something using a hashtag. Turns out, I was using a misspelled hashtag that I had blocked from being able to be used in a post on my instance. A brief notice did appear and disappear about the hashtag not being able to be used but it came and went much faster than the blue 500 error that popped up. I missed it the first three times I tried to post. #MastoAdmin .
I've noticed significant amount of requests towards the path /packs/*.js files on my Mastodon instance...
What's that about?
RE: https://mastodon.iftas.org/@iftas/117241028973791986
Wir haben temporär die Registrierung bei uns komplett deaktiviert, weil wir aktuell massive unter Spam-Anmeldungen zu leiden haben.
Services continue to report a wave of automated account creation using the naming pattern "bp" followed by a series of random alphanumerics, eg "bpc7463204e397374e" or "bpde9af0166700f555".
To date almost all accounts are created using an email address at the domains:
docomo.ne.jp
ezweb.ne.jpand to a lesser degree:
yahoo.co.jp
au.comRequiring approval for accounts using these email domains during this attack will severely minimise your spam account review activity.
RE: https://mementomori.social/@rolle/117239751453109028
I looked into the bot issue again today. It turns out the bots aren't cracking Turnstile, they are bypassing it entirely by registering directly through the API (POST /api/v1/apps -> /oauth/token -> /api/v1/accounts). Turnstile, CAPTCHAs, and similar tools only protect web signups.
Because of this, blocking usernames, IPs, or email addresses doesn't help for long, as the bots keep rotating them and they are completely randomized.
I added a quick check to our fork in the Api::V1::AccountsController#check_enabled_registrations method: if API_REGISTRATIONS_REQUIRE_INVITE=true is set in .env.production, API registrations will require a valid invite code and return a 403 error otherwise. This does not affect regular signups.
The invite code cannot be guessed, so this should put an end to the issue. We could also achieve the same result in Nginx by blocking POST /api/v1/accounts, but I am not entirely sure what complications that might cause.
We are in the middle of a server migration, so we're keeping work on this to a minimum right now. We'll look into Anubis or Cloudflare anti-bot protections later.
We'll keep an eye on the situation.
#MementomoriSocial #MastoAdmin #Bots
RE: https://mastodon.bsd.cafe/@stefano/117237019528096024
We are affected with the same spam wave, even with Turnstile enabled. They must be using Flaresolverr and similar methods.
This might not be a coincidence, bots pass CAPTCHAs now: https://mnews.sbs.co.kr/english/article.do?newsId=N1008743947
#MementomoriSocial #MastoAdmin
https://about.iftas.org/2026/09/11/boom-protocol-spam/ will re-post useful tips, tricks, guidance to combat the #bpSpam wave impacting many service providers.
#BoomProtocol #BoomProtocolProbe #Spam #FediAdmin #MastoAdmin #PeerTubeAdmin #FediMods #Mastomods
I have... *1119 accounts* pending registration. Every single one is a "Automated protocol deliverability probe”. I so badly need the ability to just reject everything with the same request reason...
The spam accounts from the last few hours ("Automated protocol deliverability probe") appear to be logging in via their own OAuth app called “BoomProtocolProbe.” So here's an attempt:
To prevent “BoomProtocolProbe” from registering, we created a trigger in the Mastodon database that checks the name BEFORE INSERT and blocks the app if it matches.
Fellow #MastoAdmin people. Have you come across this registration bot with account details like this:
Reason: Automated protocol deliverability probe
And account details like this:
bp3de08dafada0d38a
@bp3de08dafada0d38a
This is new. 😅
Messaged @ajroach42 to inform them that their site is using software so old that even the recommended solution is out of date. Made sure my site and their site were connected, and even searched for my username using their site — I found myself, no problem. 😇
Every admin — 100% — I have ever messaged concerning their software being out of date has been friendly and received my message well. 😎
This is the first time someone blocked me. I guess there is a first for everything, lmao. 🤣
Welcome retro.social to security_risk_domains.csv. You're site number 23 added to the list. 🤷 🤡
https://github.com/Fediverse-Express/Fediverse/blob/main/security_risk_domains.csv
This is new. 😅
Messaged @ajroach42 to inform them that their site is using software so old that even the recommended solution is out of date. Made sure my site and their site were connected, and even searched for my username using their site—I found myself, no problem. 😇
Every admin—100%—I have ever messaged concerning their software being out of date has been friendly and received my message well. 😎
This is the first time someone blocked me. I guess there is a first for everything, lmao. 🤣
Welcome retro.social to security_risk_domains.csv. You're site number 23 added to the list. 🤷 🤡
https://github.com/Fediverse-Express/Fediverse/blob/main/security_risk_domains.csv
1,112 accounts spreading spam or participating in scams, along with the people who promote, defend, or otherwise amplify their existence on the Fediverse.
You'd be amazed at how much more user-friendly and cleaner Mastodon or Misskey feels once you take out the trash.
Save as a CSV file, for example, block.csv, import (upload) the file, and merge it with your current block list.
https://github.com/Fediverse-Express/Fediverse/blob/main/block_spam_scam_users.csv
#Spam #Scam #Fraud #FediBlock #FediAdmin #MastoAdmin #Mastodon #Misskey #Fediverse
RE: https://lsbt.me/@christin/117248376636232175
We're receiving Spam registrations too.
Reason for joining:
Automated protocol deliverability probe
Example of username chosen:
bp7db8296eb763dff7
Example of entry in web server log:
180.4.59.44 - - [10/Sep/2026:16:40:02 -0600] "POST /auth/confirmation HTTP/1.1" 302 5493 "-" "Python/3.10 aiohttp/3.14.3"
Irgendwer (Bot oder KI offenbar) torpediert gerade Mastodon-Instanzen (möglicherweise auch andere Plattformen im Fediverse) mit Registrierungsanfragen.
Gemeinsame Merkmale:
Hintergrund ist unklar.
Die betroffenen Instanzen torpedieren ungewollt mehrere Mailserver mit nicht zustellbaren Mails, was womöglich zu Blacklisting führt.
Ich habe vorübergehend Registrierungen auf meiner Instanz deaktiviert.
If your are facing lots of registration attempts in the last hours, you can configure #nginx to allow only n calls of the sign up page for an IP.
The example is for 3 calls/min and then 404 for 10 min
@ben OMG I am getting a TON of these suddenly! They're definitely not legit (as in new users) and despite the "automated protocol deliverability probe" description I don't think they're "legit" bots. I think it's just spammers. #mastoadmin
This looks ominous.
Anybody else seeing lots of new sign up attempts?
(I need to get it passing the correct IP address from the upstream proxy)
Hatte die letzten Tage ein Spamwelle an Bot Registrierungen mit Email Domain docomo.ne.jp
Was ein Fun
Hooray! We have successfully got mastodon database live replica streaming! Size of db is btw ~220GB in mementomori case. Replica is in other DC.
What is this nuicanse bot that creates constantly members to #mastodon instances?
"Automated protocol deliverability probe"
@mookie Something else I have noticed is, since the v4.5.17 upgrade, my SideKiq has no dead jobs, which I find very odd, almost impossible. #MastoAdmin https://oldfriends.live/@paul/117239102596444682
Since Mastodon v4.5.17, the only news that trends are news links that originate on my self-hosted instance... Anyone else having that issue? #MastoAdmin
RE: https://mastodon.bsd.cafe/@stefano/117237019528096024
We are affected with the same spam wave, even with Turnstile enabled. They must be using Flaresolverr and similar methods.
This might not be a coincidence, bots pass CAPTCHAs now: https://mnews.sbs.co.kr/english/article.do?newsId=N1008743947
#MementomoriSocial #MastoAdmin
Since Mastodon v4.5.17, the only news that trends are news links that originate on my self-hosted instance... Anyone else having that issue? #MastoAdmin
1,085 accounts identified as participating in spam and scam activity — along with accounts that actively promote, defend, or amplify them.
https://github.com/Fediverse-Express/Fediverse/blob/main/block_spam_scam_users.csv
RE: https://gayfr.social/@barbapulpe/117202159000216777
Bumping this, am I really the only one?
Sidekiq processes are multiplying as hell, and I didn't find any issues in the #Mastodon github. Really surprised nobody else is affected? Do I need to open an issue?
Nothing else changed on my side, happening since upgrade to 4.7.0 (still there in 4.7.1).
Just sent 61 messages to admins running very outdated copies of either Mastodon or Misskey.
No one should be using, for example, Mastodon 3.x. There is a vulnerability that allows someone to obtain limited access to the owner account.
A few people were using 4.2.x, which is so old and discontinued that the final release at the time suggested upgrading to 4.3.x — which is also now discontinued and has several known security vulnerabilities.
If you're using Mastodon 4.4.0, as legacy, know that 4.4.24 already recommends you upgrade to at minimum 4.6. or newer, The current release is 4.7.1.
No one is saying you need to always run the bleeding-edge release. But if you're going to host other people, you should attempt to keep your site relatively current. The older the site, the harder it can be to upgrade, so not falling too far behind is good planning. If you cannot do that, you really should consider joining someone else's site as opposed to running your own.