GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Admin Jerry (admin@hear-me.social)'s status on Friday, 18-Apr-2025 21:53:29 JSTAdmin JerryAdmin Jerry
    • Eugen Rochko
    • ClearlyClaire

    Riddle me this. How can a spammer start their account creation from /auth/confirmation? He does this every week. He never accesses /auth/sign_up. He always first shows up in the logs accessing /auth/confirmation.

    I have his ASN blocked by the Cloudflare firewall from accessing /auth/sign_up. I see in the Cloudflare logs that he tried to access /auth/sign_up but got a 403 from Cloudflare. The request is nowhere in my logs. It was truly blocked by the proxy server.

    But, then suddenly he's using /auth/confirmation with the same blocked ASN seconds later and creates the account. Today I added the same ASN restriction to /auth/confirmation to try to stop future sign-ups, but this is beside the point.

    It's like he tries to go to sign_up, gets a 403, and then uses some alternative means to begin the signup process.

    He's not getting in with an invitation code, either.

    Can he be using an existing account in some way to get an access token for an API call of some type to begin registration?

    How does he do this?

    #MastoAdmin #MastoDev @Gargron @ClearlyClaire

    In conversationabout 3 months ago from hear-me.socialpermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.point.it
      Agenzia di Marketing e Comunicazione | POINT Studio Prato
      Soluzioni personalizzate in linea con le esigenze di aziende e professionisti, progetti di marketing integrato dall'offline al digitale.
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.