XMPP Service Operators - 2023-06-24


  1. paphnoutios

    vagina@5222.de for rtbl please

  2. TheCoffeMaker

    Can confirm

  3. schäfchen726

    +1

  4. dora71

    Does anybody know what's up with hot-chilli.net Support? Pastebins in MUCs are not working but no answer in support chat.

  5. Quinn64

    > Does anybody know what's up with hot-chilli.net Support? Pastebins in MUCs are not working but no answer in support chat. I haven't seen Roi around in a couple of days. I hope he's okay

  6. Projjal

    😕

  7. dora71

    > Quinn64: > 2023-06-24 05:39 (GMT+02:00) > I haven't seen Roi around in a couple of days. I hope he's okay hope so too. Is Roi the only admin?

  8. Quinn64

    I'm not sure, it's been a while since I used Hot-Chilli

  9. Quinn64

    Looks like Beorn is also an admin on there: https://jabber.hot-chilli.net/

  10. pur

    Someone using jabber.de to spam atm. Some of the jids where the spam originates from are: xmpp:4fa1b9dd486a606f78d91eadfcc59c18e94ae3@jabber.de xmpp:47d385813117fb0ced95538e59293325bebb8b@jabber.de xmpp:a17f7d42cd7c7441874647eb@jabber.de xmpp:7cb4e46c8a229eeec21f61957a@jabber.de xmpp:23fb08eb7f35e393ae2687891322d3dd82f8c2@yax.im

  11. gooya

    yep

  12. gooya

    In 404 gemeral chat and my server

  13. gooya

    Please add him to blocklist MattJ

  14. pur

    Lots of spam coming now from many different yax.im jids

  15. techmetx11

    there's a ton of spam coming from yax.im

  16. gooya

    Ge0rG: is aware

  17. techmetx11

    i'm assuming they're abusing the account registration API

  18. Ge0rG

    pur, techmetx11: please give me a lits of JIDs to delete.

  19. pur

    I wish there was an easy way to do so in conversations.

  20. techmetx11

    i don't get why servers have XEP-0077 enabled

  21. pur

    Maybe check the newly created accounts. jid is random letters and numbers

  22. Ge0rG

    pur: I just checked the two JIDs reported to me, found five more from the same IPs and deleted both sets

  23. techmetx11

    Ge0rG: can you ban the IP?

  24. pur

    Ty

  25. Ge0rG

    techmetx11: I can, but if you ban the user from the MUC, all other yax.im users from the same IP will be also banned

  26. Ge0rG

    so I'll only ban one current Tor exit node, probably.

  27. techmetx11

    i really do wonder if these spammers abuse XEP-0077

  28. techmetx11

    since registering with XEP-0077 is as easy as.... sending a form

  29. Ge0rG

    I don't see a large number of user registrations on yax.im with hex user names.

  30. Ge0rG

    sorry, my registration watching code was broken. I now found ~3000 accounts using long hexadecimal JIDs, all registered in the last week, and am proceeding to delete them

  31. paphnoutios

    is it best practice to like block open proxies and tor?

  32. Ge0rG

    I'm using the DroneBL blacklist for registrations, but apparently it didn't match on most of these registrations

  33. paphnoutios

    I use this merged list in nftables and default drop all packets https://iplists.firehol.org/?ipset=firehol_anonymous

  34. raucao

    hi there. may i ask someone to confirm that they can connect tot he kosmos.chat MUC service and write t its MUC rooms? (e,.g. in ops@kosmos.chat)

  35. raucao

    a user from another domain is getting timeouts, and for some reason all our rooms disappeared from https://search.jabber.network too

  36. raucao

    no idea why, i'm basically certain that it wasn't unreachable for a week, and from here everything looks totally fine

  37. Quinn64

    raucao: https://connect.xmpp.net/ is only able to connect on S2S via StartTLS, it fails everything else when I had it check

  38. raucao

    htx

  39. raucao

    thx

  40. raucao

    i found that the ip address that is used for the MUC service (but not the rest) was down

  41. raucao

    so local users were able to connect through their accounts on the same server, but remote ones would get timeouts

  42. raucao

    hmm, that website says

  43. raucao

    > Unable to contact the testing API. It might be unavailable or blocked. > undefined

  44. raucao

    lol, just a coincidence. worked on 2nd try

  45. raucao

    is it normal to define SRV records for MUC domains?

  46. raucao

    because it looks like we only have records for our main domain

  47. Quinn64

    I have SRV records for everything I want accessible by external users, including my MUC component. I don't have an A/AAAA or CNAME record for my MUC component at all, just SRV

  48. techmetx11

    Ge0rG: do you flag JIDs with pure hexadecimal?

  49. techmetx11

    like 0123456789abcdef

  50. Trung

    there might be legit people using hash JID too btw

  51. techmetx11

    yes

  52. techmetx11

    or maybe, depending on context

  53. techmetx11

    too many accounts registered in a minute/hour

  54. techmetx11

    per IP

  55. raucao

    > only able to connect on S2S via StartTLS, it fails everything else when I had it check the ejabberd docs say direct tls is deprecated in favor of starttls

  56. raucao

    is that up to date?

  57. Ellenor Bjornsdottir

    holy sh-

  58. techmetx11

    i'm considering that it was a mistake to make in-band registering way too easy

  59. techmetx11

    i'm considering that maybe it was a mistake to make in-band registering way too easy

  60. MSavoritias (fae,ve)

    > is that up to date? no... at least from a security perspective

  61. Ellenor Bjornsdottir scrapes a line on the clock at 1946z

  62. paphnoutios

    penises@conversations.im for rtbl please

  63. paphnoutios

    and templeos@xmpp.is

  64. paphnoutios

    rape@5222.de for rtbl please

  65. ☭Mike Yellow

    It was a right choice removing public server addresses which support XEP-0077 in the user manual. Nobody ensures they keep supporting it in the future. It seems reports about spammers are many, is that because XMPP is becoming popular? :)

  66. paphnoutios

    the majority of these are the same person

  67. ☭Mike Yellow

    Oops.

  68. ☭Mike Yellow

    What is the way to deal with the accounts? Delete the them or forbid them to login?

  69. nuron

    I guess it doesn't matter. If one account doesn't work, a new one will be created

  70. nuron

    I changed all mucs to moderated a few month ago when they spamed a lot last time. Don't have any problems today :)

  71. nuron

    A couple of mods and it seems to work well

  72. ☭Mike Yellow

    > I guess it doesn't matter. If one account doesn't work, a new one will be created It matters for manual creator. I wonder when an IP address is blocked, what is the feed back information to them? Maybe “policy violation”?

  73. nuron

    Oh I thought you would just change the password of this account to block login

  74. nuron

    If its an IP block that could maybe help

  75. paphnoutios

    you can't block their IP because they don't connect to your server

  76. paphnoutios

    only if their account is on your server

  77. nuron

    Of course

  78. nuron

    You are right

  79. ☭Mike Yellow

    >It matters for manual creator. Sorry. I mean the guide book.

  80. nuron

    Woops :)

  81. ☭Mike Yellow

    :>

  82. j.r (jugendhacker.de)

    Does anybody know the xmpp.is admin? Seems like they would want to moderate childporn@muc.xmpp.is

  83. nuron

    Looks like the mail addresses here are the only way to contact them: https://xmpp.is/contact/

  84. Projjal

    I've written to xmpp.is admin before and they usually respond very fast.

  85. Projjal

    try it

  86. paphnoutios

    ejaculationfromtheanus@conversations.im for rtbl please

  87. gooya

    paphnoutios: already on it ~9m ago