jrollans.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
These are the voyag... uh, things I post about.
Admin email
jrollans@gmail.com
Admin account
@jrollans@jrollans.com

Search results for tag #mastoadmin

[?]Rimuru » 🌐
@Tempest@burningboard.net

Pro tip of the day:

Do not be the next buddy.social.

Keep your Fedi site relatively up to date.

    [?]Rimuru » 🌐
    @Tempest@burningboard.net

    This is new. 😅

    Messaged @ajroach42 to inform them that their site is using software so old that even the recommended solution is out of date. Made sure my site and their site were connected, and even searched for my username using their site — I found myself, no problem. 😇

    Every admin — 100% — I have ever messaged concerning their software being out of date has been friendly and received my message well. 😎

    This is the first time someone blocked me. I guess there is a first for everything, lmao. 🤣

    Welcome retro.social to security_risk_domains.csv. You're site number 23 added to the list. 🤷 🤡

    github.com/Fediverse-Express/F

    A screenshot of a message which reads:  @ajroach42@retro.social 

I noticed your site is using Mastodon 4.2.20, which was released on April 2, 2025, and is now discontinued.

That branch (4.2.x) of Mastodon has several known security issues. In fact, it is so old that the final 4.2.x build was 4.2.29, and developers recommend upgrading to 4.3.x. However, that branch is also discontinued and contains security issues (with the last release being 4.3.23).

All of this to say, your software is quite out of date, and your site is extremely vulnerable.

The current release is 4.7.1.

    Alt...A screenshot of a message which reads: @ajroach42@retro.social I noticed your site is using Mastodon 4.2.20, which was released on April 2, 2025, and is now discontinued. That branch (4.2.x) of Mastodon has several known security issues. In fact, it is so old that the final 4.2.x build was 4.2.29, and developers recommend upgrading to 4.3.x. However, that branch is also discontinued and contains security issues (with the last release being 4.3.23). All of this to say, your software is quite out of date, and your site is extremely vulnerable. The current release is 4.7.1.

    A screenshot showing the admin how now suspended access between my account and their site, so neither the admin or anyone else can see my post.

    Alt...A screenshot showing the admin how now suspended access between my account and their site, so neither the admin or anyone else can see my post.

      [?]Rimuru » 🌐
      @Tempest@burningboard.net

      This is new. 😅

      Messaged @ajroach42 to inform them that their site is using software so old that even the recommended solution is out of date. Made sure my site and their site were connected, and even searched for my username using their site—I found myself, no problem. 😇

      Every admin—100%—I have ever messaged concerning their software being out of date has been friendly and received my message well. 😎

      This is the first time someone blocked me. I guess there is a first for everything, lmao. 🤣

      Welcome retro.social to security_risk_domains.csv. You're site number 23 added to the list. 🤷 🤡

      github.com/Fediverse-Express/F

      A screenshot of a message which reads:  @ajroach42@retro.social 

I noticed your site is using Mastodon 4.2.20, which was released on April 2, 2025, and is now discontinued.

That branch (4.2.x) of Mastodon has several known security issues. In fact, it is so old that the final 4.2.x build was 4.2.29, and developers recommend upgrading to 4.3.x. However, that branch is also discontinued and contains security issues (with the last release being 4.3.23).

All of this to say, your software is quite out of date, and your site is extremely vulnerable.

The current release is 4.7.1.

      Alt...A screenshot of a message which reads: @ajroach42@retro.social I noticed your site is using Mastodon 4.2.20, which was released on April 2, 2025, and is now discontinued. That branch (4.2.x) of Mastodon has several known security issues. In fact, it is so old that the final 4.2.x build was 4.2.29, and developers recommend upgrading to 4.3.x. However, that branch is also discontinued and contains security issues (with the last release being 4.3.23). All of this to say, your software is quite out of date, and your site is extremely vulnerable. The current release is 4.7.1.

      A screenshot showing the admin how now suspended access between my account and their site, so neither the admin or anyone else can see my post.

      Alt...A screenshot showing the admin how now suspended access between my account and their site, so neither the admin or anyone else can see my post.

        AodeRelay boosted

        [?]Rimuru » 🌐
        @Tempest@burningboard.net

        1,112 accounts spreading spam or participating in scams, along with the people who promote, defend, or otherwise amplify their existence on the Fediverse.

        You'd be amazed at how much more user-friendly and cleaner Mastodon or Misskey feels once you take out the trash.

        Save as a CSV file, for example, block.csv, import (upload) the file, and merge it with your current block list.

        github.com/Fediverse-Express/F

          [?]don Elías (como los buses) 🥨 » 🌐
          @donelias@mastodon.cr

          RE: lsbt.me/@christin/117248376636

          We're receiving Spam registrations too.

          Reason for joining:

          Automated protocol deliverability probe

          Example of username chosen:

          bp7db8296eb763dff7

          Example of entry in web server log:

          180.4.59.44 - - [10/Sep/2026:16:40:02 -0600] "POST /auth/confirmation HTTP/1.1" 302 5493 "-" "Python/3.10 aiohttp/3.14.3"

            [?]Meerjungfrauengrotte.de » 🌐
            @admina@meerjungfrauengrotte.de

            Irgendwer (Bot oder KI offenbar) torpediert gerade Mastodon-Instanzen (möglicherweise auch andere Plattformen im Fediverse) mit Registrierungsanfragen.

            Gemeinsame Merkmale:

            • Usernane bp + 16 hex Zeichen
            • Begründung "Automated protocol deliverability probe"
            • Verschiedene IP-Adressen
            • Verschiedene Mail-Provider
            • nicht existierende Mail-Adresss
            • deswegen bounct die automatisch versendete Bestätigungsmail
            • Admins werden nicht über neu registrierte Konten benachrichtigt

            Hintergrund ist unklar.

            Die betroffenen Instanzen torpedieren ungewollt mehrere Mailserver mit nicht zustellbaren Mails, was womöglich zu Blacklisting führt.

            Ich habe vorübergehend Registrierungen auf meiner Instanz deaktiviert.

              [?]Michael » 🌐
              @pfitzer@social.main-angler.de

              If your are facing lots of registration attempts in the last hours, you can configure to allow only n calls of the sign up page for an IP.

              The example is for 3 calls/min and then 404 for 10 min

                [?]Tech Field Day Admin » 🤖 🌐
                @admin@techfieldday.net

                @ben OMG I am getting a TON of these suddenly! They're definitely not legit (as in new users) and despite the "automated protocol deliverability probe" description I don't think they're "legit" bots. I think it's just spammers.

                  [?]Ben Hardill » 🌐
                  @ben@bluetoot.hardill.me.uk

                  This looks ominous.

                  Anybody else seeing lots of new sign up attempts?

                  (I need to get it passing the correct IP address from the upstream proxy)

                  Screenshot of Mastodon Admin showing list of new account requests all with reason listed as "Automated protocol deliverability probe". They appear to be using a mix of gmail and hotmail email addresses

                  Alt...Screenshot of Mastodon Admin showing list of new account requests all with reason listed as "Automated protocol deliverability probe". They appear to be using a mix of gmail and hotmail email addresses

                    [?]Michael » 🌐
                    @pfitzer@social.main-angler.de

                    Hatte die letzten Tage ein Spamwelle an Bot Registrierungen mit Email Domain docomo.ne.jp
                    Was ein Fun

                      [?]Ilkka Tengvall » 🌐
                      @ikkeT@mementomori.social

                      Hooray! We have successfully got mastodon database live replica streaming! Size of db is btw ~220GB in mementomori case. Replica is in other DC.

                      @ry

                        [?]Veera Laukkarinen » 🌐
                        @mustikkasoppa@mementomori.social

                        Minä eilen ja tänään.

                        Mementomori.socialiin iski bottitsunami rekisteröinnin kautta.

                        Alt...Whac a Mole cat box GIF

                          [?]Ilkka Tengvall » 🌐
                          @ikkeT@mementomori.social

                          What is this nuicanse bot that creates constantly members to instances?

                          "Automated protocol deliverability probe"

                            [?]Paul Chambers🚧 » 🌐
                            @paul@oldfriends.live

                            @mookie Something else I have noticed is, since the v4.5.17 upgrade, my SideKiq has no dead jobs, which I find very odd, almost impossible. oldfriends.live/@paul/11723910

                            [?]Paul Chambers🚧 » 🌐
                            @paul@oldfriends.live

                            Since Mastodon v4.5.17, the only news that trends are news links that originate on my self-hosted instance... Anyone else having that issue?

                                [?]Rolle Laukkarinen » 🌐
                                @rolle@mementomori.social

                                RE: mastodon.bsd.cafe/@stefano/117

                                We are affected with the same spam wave, even with Turnstile enabled. They must be using Flaresolverr and similar methods.

                                This might not be a coincidence, bots pass CAPTCHAs now: mnews.sbs.co.kr/english/articl

                                [?]Stefano Marinelli » 🌐
                                @stefano@mastodon.bsd.cafe

                                I had to temporarily close the possibility to join the BSD Cafe Mastodon instance. A huge spam attack is in process.

                                For people wanting a new account, please contact me.

                                Tons of spam registration requests

                                Alt...Tons of spam registration requests

                                    [?]Paul Chambers🚧 » 🌐
                                    @paul@oldfriends.live

                                    Since Mastodon v4.5.17, the only news that trends are news links that originate on my self-hosted instance... Anyone else having that issue?

                                      [?]Rimuru » 🌐
                                      @Tempest@burningboard.net

                                      1,085 accounts identified as participating in spam and scam activity — along with accounts that actively promote, defend, or amplify them.

                                      github.com/Fediverse-Express/F

                                        [?]🌈 Barbapulpe 😇 ᴹᵃˢᵗᵒᵈᵒⁿ » 🌐
                                        @barbapulpe@gayfr.social

                                        RE: gayfr.social/@barbapulpe/11720

                                        Bumping this, am I really the only one?

                                        Sidekiq processes are multiplying as hell, and I didn't find any issues in the github. Really surprised nobody else is affected? Do I need to open an issue?

                                        Nothing else changed on my side, happening since upgrade to 4.7.0 (still there in 4.7.1).

                                          [?]Rimuru » 🌐
                                          @Tempest@burningboard.net

                                          Just sent 61 messages to admins running very outdated copies of either Mastodon or Misskey.

                                          No one should be using, for example, Mastodon 3.x. There is a vulnerability that allows someone to obtain limited access to the owner account.

                                          A few people were using 4.2.x, which is so old and discontinued that the final release at the time suggested upgrading to 4.3.x — which is also now discontinued and has several known security vulnerabilities.

                                          If you're using Mastodon 4.4.0, as legacy, know that 4.4.24 already recommends you upgrade to at minimum 4.6. or newer, The current release is 4.7.1.

                                          No one is saying you need to always run the bleeding-edge release. But if you're going to host other people, you should attempt to keep your site relatively current. The older the site, the harder it can be to upgrade, so not falling too far behind is good planning. If you cannot do that, you really should consider joining someone else's site as opposed to running your own.

                                            AodeRelay boosted

                                            [?]fury » 🌐
                                            @fury@darkwitch.net

                                            【站长提醒|大范围撞库盗号】
                                            最近联邦宇宙出现一轮大规模撞库盗号:9 月 6 日 12:05–12:41 UTC 短短一小时内,至少 82 个实例、142+ 个账号被同一套脚本改名为「HACKED - Join t[.]me/HomeFucker5」并置顶垃圾帖。我站也有两个账号中招。

                                            这是撞库(拿其他网站泄露的邮箱+密码来登录),不是 Mastodon 或站点的安全漏洞:从 4.1 到 4.8-nightly、已打满补丁的实例都被命中。攻击者先用密码悄悄"验号",几周后再集中变现,所以现在没发帖不代表没被盗。

                                            建议各位站长排查:
                                            • 登录记录(login_activities)中 UA 为 Go-http-client/1.1 的成功登录,尤其来自这三个 IP:193.202.84.104、45.134.142.231、81.92.219.205
                                            • 昵称含「HACKED」的账号;近期新建的、名为「boost」的 OAuth 应用
                                            • 命中的账号:重置密码、吊销全部会话与应用授权、通知本人
                                            • 提前在 管理 → 审核 → IP 规则 把上述 IP 设为「禁止访问」

                                            也请提醒所有用户:换一个只在本站使用的新密码,开启两步验证,密码不要和其他网站重复。

                                            —————

                                            [Admin alert | Mass credential-stuffing account takeovers]
                                            A large credential-stuffing wave hit the fediverse on 6 Sep 2026, 12:05–12:41 UTC: 142+ accounts on 82+ instances were renamed "HACKED - Join t[.]me/HomeFucker5" with pinned spam. Two accounts on my instance were hit.

                                            This is credential stuffing (leaked email+password pairs from other sites), NOT a Mastodon or server vulnerability: victims run everything from 4.1 to 4.8-nightly, including fully patched servers. The bot quietly validates passwords weeks in advance and monetizes in one wave, so "no spam yet" does not mean "not compromised".

                                            Admins, please check:
                                            • login_activities for successful logins with user-agent Go-http-client/1.1, especially from 193.202.84.104, 45.134.142.231, 81.92.219.205
                                            • display names containing "HACKED"; recently created OAuth apps named "boost"
                                            • For any hit: reset the password, revoke all sessions and app authorizations, notify the user
                                            • Pre-emptively add those IPs under Moderation → IP rules as "No access"

                                            Please remind your users: set a new password used only here, enable 2FA, and never reuse a password across sites.


                                            @board

                                              [?]Rolle Laukkarinen » 🌐
                                              @rolle@mementomori.social

                                              :skull360: We've upgraded our Mastodon server to v4.8.0-alpha.2+mementomods-2026-09-06. That is 83 new commits from upstream since our build exactly two weeks ago.

                                              This one matters more than the usual weekly round, because Mastodon 4.7.1 was a security release and it is now folded into our build.

                                              🔒 Security

                                              - Fixed a password authentication bypass in two factor auth for LDAP, PAM and SSO accounts (github.com/mastodon/mastodon/s).
                                              - Fixed a denial of service when processing malformed JSON-LD activities from other servers (github.com/mastodon/mastodon/s).
                                              - Fixed disabled staff accounts still having access to the admin API (github.com/mastodon/mastodon/s).

                                              🔧 Fixes & improvements

                                              - The follows and followers lists now say "Today" instead of showing an hour count (github.com/mastodon/mastodon/p).
                                              - Searching with just "from:me" works without also typing a keyword (github.com/mastodon/mastodon/p).
                                              - The search field no longer steals focus at random (github.com/mastodon/mastodon/p).
                                              - The 404 page now has a link back to the front page (github.com/mastodon/mastodon/p).
                                              - Long descriptions no longer overflow on the Overview landing page (github.com/mastodon/mastodon/p).

                                              🛡️ Moderation

                                              - Moderators and admins can see media reports for suspended accounts again (github.com/mastodon/mastodon/p).
                                              - The invite form asks for a written reason when approval bypass is off (github.com/mastodon/mastodon/p).
                                              - The email block domain filter survives pagination (github.com/mastodon/mastodon/p).

                                              🚀 Under the hood

                                              - The 5.0 redesign continued at a fast pace, 35 of the 83 commits: new column headers across almost every page, the mobile navigation bar and menu, the composer covering the viewport, quote posts in the composer, and a batch of design tokens. All of it stays behind a flag, so nothing changes for you yet.
                                              - Mastodon now keeps local counters of which features lead to a follow, so the developers can see which parts of the interface actually help people find accounts. These are plain daily counts in our own server memory, they expire after six months, they hold no account names or identifiers, and nothing is sent anywhere.
                                              - Some of the 4.7 database migrations were made safe to re-run if an upgrade gets interrupted (github.com/mastodon/mastodon/p).
                                              - Account creation no longer fails on an encryption configuration error during setup (github.com/mastodon/mastodon/p).

                                              📦 Dependency updates

                                              - Routine bumps and translation updates.

                                              Source code: github.com/mementomori-social/

                                              As always, if you notice anything unusual or buggy, please reach out to me or any of the admins. Enjoy your time here, and feel free to message me with any questions or thoughts. :bunhdheart:

                                                [?]El Duvelle » 🌐
                                                @elduvelle@neuromatch.social

                                                [important] Sleeper account registrations on Fedi [SENSITIVE CONTENT]

                                                Post (mostly) for instance admins: spam / sleeper account registrations

                                                Our server, with approved registrations (i.e. mods only accept new people after checking their "reasons to join") is still constantly getting spam account requests. (spam, for lack of a better word... maybe 'sleeper accounts'?)

                                                These are not obviously immediate to the untrained eye, but it's been happening for months now and there are some clear patterns. Here's a list of what I've learned so far in case that's useful to other mods. Any additional advice welcome!

                                                How to spot a sleeper account request (beyond the obvious):

                                                1. Always from a disposable email domain.
                                                2. Otherwise, a lot of them are from "proton.me" domain or "onionmail.org"
                                                3. request reads as if it was an account description, not an account request e.g. "writer, queer, loves cats, profile pic of a lake in front of a mountain, posts a lot about bread, here to share ideas and engage positively with the community, my DMs are open" - yeah it sounds like your average Fedi person, but that's probably because they scrape profiles from Fedi in the first place.
                                                4. The account request will not directly name your server or meaningfully answer the account request text
                                                5. The name of the account and of their email will have nothing to do with each other, e.g, username "colixal" and email "inyfupvtr@proton.me"
                                                6. the email usually looks random (see above), probably because they're all randomly-generated.

                                                Solutions / mitigation (for Admins):

                                                1. Switch on approved registrations on your server! @FediTips has instructions for this.
                                                2. Tell in your server's account request description that you do not accept registration from disposable emails and you want specific reasons for choosing your server.
                                                3. How to spot a disposable email domain: you can check this list, but I don't think it's up to date. you can also search for the domain with quotes "domain.xyz" online and it will usually show up as being disposable.
                                                4. Once you know a domain is disposable, you can block registrations from it (User Preferences menu>Moderation> Blocked email domains > add new)
                                                5. in doubt, email the "person" to ask them more specific info. 50% of the time the email will bounce back, and 40% you will get no answer. That's your cue to reject those (and possibly add their domain to the block list, although you don't want to block non-disposable ones of course)
                                                6. requesting a donation, even minimal (say 10p per account) would probably completely block those.
                                                7. It is possible that we've already accepted a few of the sleeper accounts. We should all probably go back and check everything out (yes, that's easier when you have a small server).
                                                8. Any other suggestions / tips? Let us know!

                                                Of course, some of these measures are bound to also prevent some genuine people from joining. In this case I think it's worth it, and also, if you can't be bothered writing 3 lines of text to explain why you chose a server then maybe you wouldn't be contributing to Fedi much anyway.

                                                Quantification

                                                We are a very small server (150 active accounts) and are getting about 1-3 such requests per day when our usual rate of genuine requests is about 1-2 per month (well, except when @jonny makes a post that pierces the thin veil with the real world). I can't imagine how many of those must be infiltrating large, open instances like mastodon.social... Have any of you people on other servers noticed it? Please let us know in answers. And if anyone personally knows one of the mastodon.social mods it would be interesting to hear from their point of view.

                                                Possible goals and consequences

                                                • wasting our time
                                                • making it harder for genuine people to join
                                                • sudden spamming
                                                • use all the server's storage to block the server
                                                • propaganda
                                                • harassment (possibly in private posts so they can't be reported)
                                                • anything else? In any case, no good can come out of it.

                                                Other posts noticing this

                                                quoting @johannab:
                                                cosocial.ca/@johannab/11685687
                                                quoting @dsalo:
                                                digipres.club/@dsalo/117039864
                                                quoting @tante:
                                                tldr.nettime.org/@tante/116845
                                                quoting @jerry who mentioned making a script to auto-block the disposable domains - I don't know if this exists now?
                                                infosec.exchange/@jerry/116805
                                                and
                                                infosec.exchange/@jerry/116846
                                                quoting @futurebird
                                                sauropods.win/@futurebird/1171

                                                PS: If you answer please un-tag all these nice people to avoid spamming them!

                                                  [?]Emil Jacobs - Collectifission » 🌐
                                                  @collectifission@greennuclear.online

                                                  I'm thinking about moving my Object Storage from Hetzner to Backblaze. They seem to have a good rep. Any experiences people willing to share?

                                                    fedicat boosted

                                                    [?]@ordnung » 🌐
                                                    @ordnung@chaos.social

                                                    Yes chaos.social now has the mastodon default theme. No we do not plan to keep it this way.

                                                    Upstream changed a lot again and our old themes don't build, therefore we need time to adapt our themes to the new changes.

                                                    This is a work that needs multiple hours and sucks. So you will have to wait a little.

                                                    In other news, we are now on the latest version of the 4.6.x branch. 4.7.x has big database migrations that will take hours too so we decided enough work for today.

                                                      [?]*|FNAME|*:canada: (Docked) [they/them] » 🌐
                                                      @crispius@mstdn.fname.ca

                                                      Im having a brain-fart.

                                                      I seem to recall a page I could go to view queued processes? (I.e. Sidekiq) but I can’t for the life of me remember where it is?

                                                        AodeRelay boosted

                                                        [?]@ordnung » 🌐
                                                        @ordnung@chaos.social

                                                        There will be some downtime of chaos.social due to maintenance starting in the next few minutes.