XMPP Service Operators - 2025-06-06


  1. chunk

    Yea so somebody was like, a turbo spammer with the strength and hammered my MUC a couple weeks ago, circumvented the muc moderation COMPLETELY, spoofing or using fake non-registered (muc or local) data and continuing to bot spam my MUC

  2. chunk

    So I created another vhost, for the lulz, and jokes, and why take life seriously, it's on `pubchatmofos.cc` and no it is not derogatory, don't pester me about that, it's an ongoing meme, and irrelevant, and my MUC place for now

  3. chunk

    I wondered something about prosody server but I can't remember at this moment

  4. chunk

    It'll come back to me, maybe I'd ask that in prosody chat

  5. chunk

    I am packets.cc operator fyi, and the recently on vacation toofast.vip domain is mine as well

  6. Menel

    So the interesting part is that spam attack. You could analize your logs and see what happend there, to improve tools preventing that

  7. chunk

    Yea, but it keeps interesting when I don't do that and do other stuff instead

  8. chunk

    I'll be honest I don't feel threatened or offended in the least, I'm just chillin

  9. chunk

    I know who did it, and those guys are all kinda comedic, such is the lulz ya know?

  10. chunk

    I mean, I don't have white vans down the block, and im not subject to v2k atm anyways, i think it's ok

  11. chunk

    been there done that tho ^^

  12. craftxbox

    Does anyone know about thesecure.biz?

  13. craftxbox

    this marks the third signup that i've got that comes on with a hot IP and immediately tries to PM someone there, and gets bounced

  14. chunk

    craftxbox, what's a "hot ip" ?? entirely spoofed?

  15. chunk

    cuz are you suuuure?

  16. craftxbox

    Bad reputation

  17. chunk

    oh i see

  18. chunk

    r.i.p.

  19. craftxbox

    ie getipintel of 0.9 or higher

  20. craftxbox

    they seem to give up doing anything after getting the bounce report? its just weird behaviour

  21. chunk

    sounds like you need to do some firewall magic and use a www blocklist for degenerate hosts blocked at dns level maybe

  22. chunk

    today somebody muc pm-ed me, and my android locked up hard immediately\

  23. chunk

    a similar thing, somebody just signs up, says something someone, leaves never seen again

  24. craftxbox

    my service is open-reg but its not listed anywhere that i know of, im curious as to where they're finding me anyway

  25. chunk

    how many fuzzers are hitting your server?

  26. chunk

    are you on a congested or heavily farmed IP range?

  27. chunk

    r.i.p. webserver logs xD

  28. chunk

    digital ocean is a busy one, but never had such a particular issue

  29. craftxbox

    > are you on a congested or heavily farmed IP range? not really no, residential service

  30. Menel

    craftxbox: the web is scanned for open xmpp ports, and then they can get on from there, using softest that tries to make an account and test if it works. Maybe that is the initial PM. A test for connectivity

  31. Menel

    craftxbox: the web is scanned for open xmpp ports, and then they can get on from there, using software that tries to make an account and test if it works. Maybe that is the initial PM. A test for connectivity

  32. craftxbox

    Particularly why i was asking about the target server :p

  33. craftxbox

    i was curious if it was known or not

  34. craftxbox

    googling it shows that it's been used for ransomware before but pretty much nothing else

  35. tom

    > Yea so somebody was like, a turbo spammer with the strength and hammered my MUC a couple weeks ago, circumvented the muc moderation COMPLETELY, spoofing or using fake non-registered (muc or local) data and continuing to bot spam my MUC There's a prosody module for rate limiting mucs

  36. tom

    It can help limit damage when that happens until human intervention can take place

  37. chunk

    that's actually a good idea tom thanks

  38. chunk

    my muc's don't necessarily chat up that fast much a storm, it could be fine tuned, cheers

  39. tom

    yes you need to tune it for your mucs

  40. chunk

    do I need any special tools?

  41. chunk

    xD

  42. chunk gets his ruler