jrollans.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
This is new. 😅
Messaged @ajroach42 to inform them that their site is using software so old that even the recommended solution is out of date. Made sure my site and their site were connected, and even searched for my username using their site — I found myself, no problem. 😇
Every admin — 100% — I have ever messaged concerning their software being out of date has been friendly and received my message well. 😎
This is the first time someone blocked me. I guess there is a first for everything, lmao. 🤣
Welcome retro.social to security_risk_domains.csv. You're site number 23 added to the list. 🤷 🤡
https://github.com/Fediverse-Express/Fediverse/blob/main/security_risk_domains.csv
This is new. 😅
Messaged @ajroach42 to inform them that their site is using software so old that even the recommended solution is out of date. Made sure my site and their site were connected, and even searched for my username using their site—I found myself, no problem. 😇
Every admin—100%—I have ever messaged concerning their software being out of date has been friendly and received my message well. 😎
This is the first time someone blocked me. I guess there is a first for everything, lmao. 🤣
Welcome retro.social to security_risk_domains.csv. You're site number 23 added to the list. 🤷 🤡
https://github.com/Fediverse-Express/Fediverse/blob/main/security_risk_domains.csv
1,112 accounts spreading spam or participating in scams, along with the people who promote, defend, or otherwise amplify their existence on the Fediverse.
You'd be amazed at how much more user-friendly and cleaner Mastodon or Misskey feels once you take out the trash.
Save as a CSV file, for example, block.csv, import (upload) the file, and merge it with your current block list.
https://github.com/Fediverse-Express/Fediverse/blob/main/block_spam_scam_users.csv
#Spam #Scam #Fraud #FediBlock #FediAdmin #MastoAdmin #Mastodon #Misskey #Fediverse
RE: https://lsbt.me/@christin/117248376636232175
We're receiving Spam registrations too.
Reason for joining:
Automated protocol deliverability probe
Example of username chosen:
bp7db8296eb763dff7
Example of entry in web server log:
180.4.59.44 - - [10/Sep/2026:16:40:02 -0600] "POST /auth/confirmation HTTP/1.1" 302 5493 "-" "Python/3.10 aiohttp/3.14.3"
Irgendwer (Bot oder KI offenbar) torpediert gerade Mastodon-Instanzen (möglicherweise auch andere Plattformen im Fediverse) mit Registrierungsanfragen.
Gemeinsame Merkmale:
Hintergrund ist unklar.
Die betroffenen Instanzen torpedieren ungewollt mehrere Mailserver mit nicht zustellbaren Mails, was womöglich zu Blacklisting führt.
Ich habe vorübergehend Registrierungen auf meiner Instanz deaktiviert.
If your are facing lots of registration attempts in the last hours, you can configure #nginx to allow only n calls of the sign up page for an IP.
The example is for 3 calls/min and then 404 for 10 min
@ben OMG I am getting a TON of these suddenly! They're definitely not legit (as in new users) and despite the "automated protocol deliverability probe" description I don't think they're "legit" bots. I think it's just spammers. #mastoadmin
This looks ominous.
Anybody else seeing lots of new sign up attempts?
(I need to get it passing the correct IP address from the upstream proxy)
Hatte die letzten Tage ein Spamwelle an Bot Registrierungen mit Email Domain docomo.ne.jp
Was ein Fun
Hooray! We have successfully got mastodon database live replica streaming! Size of db is btw ~220GB in mementomori case. Replica is in other DC.
What is this nuicanse bot that creates constantly members to #mastodon instances?
"Automated protocol deliverability probe"
@mookie Something else I have noticed is, since the v4.5.17 upgrade, my SideKiq has no dead jobs, which I find very odd, almost impossible. #MastoAdmin https://oldfriends.live/@paul/117239102596444682
Since Mastodon v4.5.17, the only news that trends are news links that originate on my self-hosted instance... Anyone else having that issue? #MastoAdmin
RE: https://mastodon.bsd.cafe/@stefano/117237019528096024
We are affected with the same spam wave, even with Turnstile enabled. They must be using Flaresolverr and similar methods.
This might not be a coincidence, bots pass CAPTCHAs now: https://mnews.sbs.co.kr/english/article.do?newsId=N1008743947
#MementomoriSocial #MastoAdmin
Since Mastodon v4.5.17, the only news that trends are news links that originate on my self-hosted instance... Anyone else having that issue? #MastoAdmin
1,085 accounts identified as participating in spam and scam activity — along with accounts that actively promote, defend, or amplify them.
https://github.com/Fediverse-Express/Fediverse/blob/main/block_spam_scam_users.csv
RE: https://gayfr.social/@barbapulpe/117202159000216777
Bumping this, am I really the only one?
Sidekiq processes are multiplying as hell, and I didn't find any issues in the #Mastodon github. Really surprised nobody else is affected? Do I need to open an issue?
Nothing else changed on my side, happening since upgrade to 4.7.0 (still there in 4.7.1).
Just sent 61 messages to admins running very outdated copies of either Mastodon or Misskey.
No one should be using, for example, Mastodon 3.x. There is a vulnerability that allows someone to obtain limited access to the owner account.
A few people were using 4.2.x, which is so old and discontinued that the final release at the time suggested upgrading to 4.3.x — which is also now discontinued and has several known security vulnerabilities.
If you're using Mastodon 4.4.0, as legacy, know that 4.4.24 already recommends you upgrade to at minimum 4.6. or newer, The current release is 4.7.1.
No one is saying you need to always run the bleeding-edge release. But if you're going to host other people, you should attempt to keep your site relatively current. The older the site, the harder it can be to upgrade, so not falling too far behind is good planning. If you cannot do that, you really should consider joining someone else's site as opposed to running your own.
【站长提醒|大范围撞库盗号】
最近联邦宇宙出现一轮大规模撞库盗号:9 月 6 日 12:05–12:41 UTC 短短一小时内,至少 82 个实例、142+ 个账号被同一套脚本改名为「HACKED - Join t[.]me/HomeFucker5」并置顶垃圾帖。我站也有两个账号中招。
这是撞库(拿其他网站泄露的邮箱+密码来登录),不是 Mastodon 或站点的安全漏洞:从 4.1 到 4.8-nightly、已打满补丁的实例都被命中。攻击者先用密码悄悄"验号",几周后再集中变现,所以现在没发帖不代表没被盗。
建议各位站长排查:
• 登录记录(login_activities)中 UA 为 Go-http-client/1.1 的成功登录,尤其来自这三个 IP:193.202.84.104、45.134.142.231、81.92.219.205
• 昵称含「HACKED」的账号;近期新建的、名为「boost」的 OAuth 应用
• 命中的账号:重置密码、吊销全部会话与应用授权、通知本人
• 提前在 管理 → 审核 → IP 规则 把上述 IP 设为「禁止访问」
也请提醒所有用户:换一个只在本站使用的新密码,开启两步验证,密码不要和其他网站重复。
—————
[Admin alert | Mass credential-stuffing account takeovers]
A large credential-stuffing wave hit the fediverse on 6 Sep 2026, 12:05–12:41 UTC: 142+ accounts on 82+ instances were renamed "HACKED - Join t[.]me/HomeFucker5" with pinned spam. Two accounts on my instance were hit.
This is credential stuffing (leaked email+password pairs from other sites), NOT a Mastodon or server vulnerability: victims run everything from 4.1 to 4.8-nightly, including fully patched servers. The bot quietly validates passwords weeks in advance and monetizes in one wave, so "no spam yet" does not mean "not compromised".
Admins, please check:
• login_activities for successful logins with user-agent Go-http-client/1.1, especially from 193.202.84.104, 45.134.142.231, 81.92.219.205
• display names containing "HACKED"; recently created OAuth apps named "boost"
• For any hit: reset the password, revoke all sessions and app authorizations, notify the user
• Pre-emptively add those IPs under Moderation → IP rules as "No access"
Please remind your users: set a new password used only here, enable 2FA, and never reuse a password across sites.
We've upgraded our Mastodon server to v4.8.0-alpha.2+mementomods-2026-09-06. That is 83 new commits from upstream since our build exactly two weeks ago.
This one matters more than the usual weekly round, because Mastodon 4.7.1 was a security release and it is now folded into our build.
🔒 Security
- Fixed a password authentication bypass in two factor auth for LDAP, PAM and SSO accounts (https://github.com/mastodon/mastodon/security/advisories/GHSA-vx32-x96w-qq65).
- Fixed a denial of service when processing malformed JSON-LD activities from other servers (https://github.com/mastodon/mastodon/security/advisories/GHSA-vgm8-frgh-rh2v).
- Fixed disabled staff accounts still having access to the admin API (https://github.com/mastodon/mastodon/security/advisories/GHSA-62j4-hvj7-px3f).
🔧 Fixes & improvements
- The follows and followers lists now say "Today" instead of showing an hour count (https://github.com/mastodon/mastodon/pull/40367).
- Searching with just "from:me" works without also typing a keyword (https://github.com/mastodon/mastodon/pull/40327).
- The search field no longer steals focus at random (https://github.com/mastodon/mastodon/pull/40271).
- The 404 page now has a link back to the front page (https://github.com/mastodon/mastodon/pull/40369).
- Long descriptions no longer overflow on the Overview landing page (https://github.com/mastodon/mastodon/pull/40272).
🛡️ Moderation
- Moderators and admins can see media reports for suspended accounts again (https://github.com/mastodon/mastodon/pull/40274).
- The invite form asks for a written reason when approval bypass is off (https://github.com/mastodon/mastodon/pull/40332).
- The email block domain filter survives pagination (https://github.com/mastodon/mastodon/pull/40254).
🚀 Under the hood
- The 5.0 redesign continued at a fast pace, 35 of the 83 commits: new column headers across almost every page, the mobile navigation bar and menu, the composer covering the viewport, quote posts in the composer, and a batch of design tokens. All of it stays behind a flag, so nothing changes for you yet.
- Mastodon now keeps local counters of which features lead to a follow, so the developers can see which parts of the interface actually help people find accounts. These are plain daily counts in our own server memory, they expire after six months, they hold no account names or identifiers, and nothing is sent anywhere.
- Some of the 4.7 database migrations were made safe to re-run if an upgrade gets interrupted (https://github.com/mastodon/mastodon/pull/40264).
- Account creation no longer fails on an encryption configuration error during setup (https://github.com/mastodon/mastodon/pull/40275).
📦 Dependency updates
- Routine bumps and translation updates.
Source code: https://github.com/mementomori-social/mastodon
As always, if you notice anything unusual or buggy, please reach out to me or any of the admins. Enjoy your time here, and feel free to message me with any questions or thoughts. 
Our server, with approved registrations (i.e. mods only accept new people after checking their "reasons to join") is still constantly getting spam account requests. (spam, for lack of a better word... maybe 'sleeper accounts'?)
These are not obviously immediate to the untrained eye, but it's been happening for months now and there are some clear patterns. Here's a list of what I've learned so far in case that's useful to other mods. Any additional advice welcome!
Of course, some of these measures are bound to also prevent some genuine people from joining. In this case I think it's worth it, and also, if you can't be bothered writing 3 lines of text to explain why you chose a server then maybe you wouldn't be contributing to Fedi much anyway.
We are a very small server (150 active accounts) and are getting about 1-3 such requests per day when our usual rate of genuine requests is about 1-2 per month (well, except when @jonny makes a post that pierces the thin veil with the real world). I can't imagine how many of those must be infiltrating large, open instances like mastodon.social... Have any of you people on other servers noticed it? Please let us know in answers. And if anyone personally knows one of the mastodon.social mods it would be interesting to hear from their point of view.
quoting @johannab:
https://cosocial.ca/@johannab/116856878972351914
quoting @dsalo:
https://digipres.club/@dsalo/117039864558262328
quoting @tante:
https://tldr.nettime.org/@tante/116845372717559528
quoting @jerry who mentioned making a script to auto-block the disposable domains - I don't know if this exists now?
https://infosec.exchange/@jerry/116805164892680867
and
https://infosec.exchange/@jerry/116846097736300539
quoting @futurebird
https://sauropods.win/@futurebird/117161690843829586
PS: If you answer please un-tag all these nice people to avoid spamming them!
#MastoAdmin #MastoAdminTip #FediAdmin #AcountRequests #SleeperAccounts #SpamAccounts
I'm thinking about moving my Object Storage from Hetzner to Backblaze. They seem to have a good rep. Any experiences people willing to share?
Yes chaos.social now has the mastodon default theme. No we do not plan to keep it this way.
Upstream changed a lot again and our old themes don't build, therefore we need time to adapt our themes to the new changes.
This is a work that needs multiple hours and sucks. So you will have to wait a little.
In other news, we are now on the latest version of the 4.6.x branch. 4.7.x has big database migrations that will take hours too so we decided enough work for today. #mastoadmin
Im having a brain-fart.
I seem to recall a #MastoAdmin page I could go to view queued processes? (I.e. Sidekiq) but I can’t for the life of me remember where it is?
There will be some downtime of chaos.social due to maintenance starting in the next few minutes. #mastoadmin