Conversation

Morning gang :) what did I miss?

2
0
0
@jeff @monkey a bucnh of instances got attacked at once, none enough to actually go down. Worst i've seen was slow image loading
2
0
2

@snacks @monkey where they all on the same hosting provider?

1
0
1
@jeff @monkey don't think xenofemme is on the fedi meme provider. Don't rember what it's called
1
0
0

@snacks @monkey which side of the fediblock iron curtain are they on? that’ll help track down who done it

3
0
0

@snacks lol wait what DID I miss I thought you were joking.

1
0
0
@monkey someone seems to have tried ddosing a bunch of instances at once, idk why
0
0
0

@snacks @monkey i bet someone got upset that they didn’t comply with the whims of the fediblock witch hunts

0
0
0
@jeff @snacks @monkey
ryona, drc, poast, hj's instance and lain.la/abestos got all hit. Common denominator is Pleroma :D
7
1
6
@phnt @monkey @jeff maybe the new release is just doing smth weird?
2
0
0

@phnt @snacks @monkey yup, some tranny with a botnet is assmad about posts on the internet

0
0
1
@snacks @monkey @jeff Doesn't make sense, I've been running basically the release code for over a month. Someone would have noticed that.

And the traffic apparently all has Win10 user-agents coming from third world countries.
1
0
2
@phnt @jeff @monkey at least their media stopped loading for me for a bit
0
0
0
@snacks @monkey @jeff I don't follow anybody from there. xnfm also runs Pleroma.
1
0
1
@phnt @monkey @jeff @snacks nazis getting what they deserve, switching to mastodon immediately
3
0
6

@lain @phnt @snacks @monkey but nazis can’t use the mastodon network, german laws make that illegal!

0
0
2
@phnt @monkey @lain @jeff @snacks oh btw @bajax u needed help getting undefederated from poast so i made this for u
0
0
2

anime graf mays 🛰️🪐

Edited 27 days ago

@phnt @monkey @jeff @snacks >Common denominator is Pleroma :D

meanwhile on Poast TV (peertube)

Status for the jail: nginx-444
|- Filter
|  |- Currently failed: 0
|  |- Total failed:     949798
|  `- File list:        /var/log/nginx/access.log
`- Actions
   |- Currently banned: 42389
   |- Total banned:     42389
0
0
3
@phnt @monkey @jeff @snacks Anything greppable?

I don't see anything unusual on munin side of things here (even nftables).
1
0
0
@lanodan @monkey @jeff @snacks Top 500 list: https://ryona.agency/media/19/5d/72/195d72edcc55a588112282c7e5208a975e522383fc3e4e98ce665e18c3721153.txt?name=pidor.txt

Other than that, not yet. I have not seen anything out of the ordinary even though I talked about it on public timeline from almost the start which seemingly didn't attract attention unlike last time.
3
0
0
@lanodan @jeff @monkey @snacks And this from poast access logs
85.108.217.219 - - [02/Jan/2026:16:33:56 +0000] "GET / HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" "Corlu" "59" "TR" "-"
129.224.215.137 - - [02/Jan/2026:16:33:56 +0000] "GET / HTTP/2.0" 444 0 "https://poast.org" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" "Buenos Aires" "C" "AR" "-"
150.228.105.179 - - [02/Jan/2026:16:33:56 +0000] "GET / HTTP/2.0" 444 0 "https://poast.org" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" "Baghdad" "BG" "IQ" "-"
102.157.39.157 - - [02/Jan/2026:16:33:56 +0000] "GET / HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" "Tunis" "11" "TN" "-"
77.226.173.3 - - [02/Jan/2026:16:33:56 +0000] "GET / HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "Madrid" "MD" "ES" "-"
47.63.243.38 - - [02/Jan/2026:16:33:56 +0000] "GET / HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "Malaga" "AN" "ES" "-"
139.192.61.168 - - [02/Jan/2026:16:33:56 +0000] "GET / HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" "Srengseng" "JK" "ID" "-"
213.196.103.200 - - [02/Jan/2026:16:33:56 +0000] "GET / HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" "Belgrade" "00" "RS" "-"
1
0
1

@phnt @monkey @snacks @lanodan you know what’d be funny, if every IP that participated got put on every malware dnsbl.

1
0
1

@phnt @monkey @jeff @snacks I guess I haven't got hit then, none of those IPs match requests I got, and none of them have been ip-blocked.
(With cutting IPv6 to the /64)

0
0
1
@phnt @jeff @monkey @snacks

> Common denominator is Pleroma :D

Pattern matches the people that have been hammering fedilist. I'll have more information shortly.
0
0
1