-
chunk
Yea so somebody was like, a turbo spammer with the strength and hammered my MUC a couple weeks ago, circumvented the muc moderation COMPLETELY, spoofing or using fake non-registered (muc or local) data and continuing to bot spam my MUC
-
chunk
So I created another vhost, for the lulz, and jokes, and why take life seriously, it's on `pubchatmofos.cc` and no it is not derogatory, don't pester me about that, it's an ongoing meme, and irrelevant, and my MUC place for now
-
chunk
I wondered something about prosody server but I can't remember at this moment
-
chunk
It'll come back to me, maybe I'd ask that in prosody chat
-
chunk
I am packets.cc operator fyi, and the recently on vacation toofast.vip domain is mine as well
-
Menel
So the interesting part is that spam attack. You could analize your logs and see what happend there, to improve tools preventing that
-
chunk
Yea, but it keeps interesting when I don't do that and do other stuff instead
-
chunk
I'll be honest I don't feel threatened or offended in the least, I'm just chillin
-
chunk
I know who did it, and those guys are all kinda comedic, such is the lulz ya know?
-
chunk
I mean, I don't have white vans down the block, and im not subject to v2k atm anyways, i think it's ok
-
chunk
been there done that tho ^^
-
craftxbox
Does anyone know about thesecure.biz?
-
craftxbox
this marks the third signup that i've got that comes on with a hot IP and immediately tries to PM someone there, and gets bounced
-
chunk
craftxbox, what's a "hot ip" ?? entirely spoofed?
-
chunk
cuz are you suuuure?
-
craftxbox
Bad reputation
-
chunk
oh i see
-
chunk
r.i.p.
-
craftxbox
ie getipintel of 0.9 or higher
-
craftxbox
they seem to give up doing anything after getting the bounce report? its just weird behaviour
-
chunk
sounds like you need to do some firewall magic and use a www blocklist for degenerate hosts blocked at dns level maybe
-
chunk
today somebody muc pm-ed me, and my android locked up hard immediately\
-
chunk
a similar thing, somebody just signs up, says something someone, leaves never seen again
-
craftxbox
my service is open-reg but its not listed anywhere that i know of, im curious as to where they're finding me anyway
-
chunk
how many fuzzers are hitting your server?
-
chunk
are you on a congested or heavily farmed IP range?
-
chunk
r.i.p. webserver logs xD
-
chunk
digital ocean is a busy one, but never had such a particular issue
-
craftxbox
> are you on a congested or heavily farmed IP range? not really no, residential service ↺
-
Menel
craftxbox: the web is scanned for open xmpp ports, and then they can get on from there, using softest that tries to make an account and test if it works. Maybe that is the initial PM. A test for connectivity✎ -
Menel
craftxbox: the web is scanned for open xmpp ports, and then they can get on from there, using software that tries to make an account and test if it works. Maybe that is the initial PM. A test for connectivity ✏
-
craftxbox
Particularly why i was asking about the target server :p
-
craftxbox
i was curious if it was known or not
-
craftxbox
googling it shows that it's been used for ransomware before but pretty much nothing else
-
tom
> Yea so somebody was like, a turbo spammer with the strength and hammered my MUC a couple weeks ago, circumvented the muc moderation COMPLETELY, spoofing or using fake non-registered (muc or local) data and continuing to bot spam my MUC There's a prosody module for rate limiting mucs ↺
-
tom
It can help limit damage when that happens until human intervention can take place
-
chunk
that's actually a good idea tom thanks
-
chunk
my muc's don't necessarily chat up that fast much a storm, it could be fine tuned, cheers
-
tom
yes you need to tune it for your mucs
-
chunk
do I need any special tools?
-
chunk
xD
- chunk gets his ruler