-
based.pt
hello
-
Samson Smith
hi
-
Kris
boa noite
-
based.pt
tom, sorry for what happened, i dealt with the situation already. and updated my server contacts.
-
based.pt
also blocked account creation
-
tom
based.pt, are you also the admin of nigga.pt?
-
based.pt
i am
-
tom
why did you chose those domains?
-
based.pt
same server, diferent domains, no account registration can be done
-
Kris
ugh
-
based.pt
> why did you chose those domains? no reason in particular, 5 letter words
-
Kris
sure 🙄
-
tom
based.pt, do you have any idea who was behind the spam attacks? Some of which were targeted to specific groups and people with different messages.
-
based.pt
my muc was spammed by accounts from xmpp.earth the same day i banned an user from it. It could be the same user
-
based.pt
after the spam i made it so only memeber could message
-
jjj333_p [pain.agency]
ive heard theories that its rewtkid, no evidence to corroborate though
-
based.pt
who is rewtkid?
-
jjj333_p [pain.agency]
a well known xmpp spammer, kinda known for doing similar things
-
tom
based.pt, your server is prosody or ejabberd?
-
based.pt
prosody
-
moparisthebest
> Has anybody been running a xmpp server without dialback security implemented? The consumer of dialback on my server are compliance checkers testing for it. All actual servers have moved onto SASL tom: yea I haven't had dialback or tls 1.2 enabled for years, zero problems, I didn't know anyone had it enabled ↺
-
tom
based.pt, I would be open to restoring federation if you would be willing to implement and configure the following protections on your server: https://modules.prosody.im/mod_throttle_unsolicited.html https://modules.prosody.im/mod_report_affiliations.html https://prosody.im/doc/modules/mod_limits Would this be acceptable to you?
-
based.pt
i will look into it and then let you know
👍 1 -
jjj333_p [pain.agency]
mod_muc_limits is good too for protecting any mucs you host
-
based.pt
tom, do i need extra configuration?
-
tom
based.pt, the rate limits can be tuned to values for your local site. The defaults work well for most sites. You would need to add nuegia.net and the rtbl service to report_affiliations_trusted_servers =
-
based.pt
whats the rtbl service?
-
xa0.uk
having rtbl on a server called nigga.pt is the funniest concept
-
tom
https://xmppbl.org/
-
based.pt
thank you
-
based.pt
done
-
based.pt
would it be safe to enable public registration again?
-
tom
you should definitely configure more protections on your public registration that out outside the scope of the requirement I have laid out for federation restoration.
-
tom
others may be able to help you with that.
-
based.pt
ok, i will try and improve on that, meanwhile the server will have registration closed
-
based.pt
and again, sorry
-
based.pt
you weren't the only one affected, i had another spam report
-
based.pt
i assume the same individual spammed on a few more servers
-
tom
based.pt, do you already have your server configured to forward spam reports to you?
-
based.pt
yes
-
based.pt
i already have the 3 modules you sent
-
based.pt
unsolicited_messages_per_minute = 10 unsolicited_s2s_messages_per_minute = 100 report_affiliations_trusted_servers = { "nuegia.net", "xmppbl.org" }
-
based.pt
im adding mod_anti_spam now
-
based.pt
and spam_reporting
-
tom
thank you.
-
based.pt
done
-
based.pt
everything added
-
based.pt
test