“Boom Protocol” Spam
This post will collate posts that share advice and guidance on the spam registration activity connected to “BoomProtocolProbe” and the bulk creation of accounts.
Notes: Over the course of days, the attack has changed approach several times. Each mitigation is quickly overcome. Please do not overly-share specific details as the actor in question may be monitoring the network for mitigations and adapting accordingly. Use your private groups, backchannels, email etc to communicate with your trusted peers. If you wish to share with the community, please use #bpSpam to help others find your content.
https://hear-me.social/@admin/117250060656308016
https://bardicperspiration.club/@Overgoddess/117248747537023800
https://mastodon.pnpde.social/@spielleitung/117242341921660658 offers a database trigger for Mastodon and PeerTube: https://pad.pnpde.social/p/FUloCtoOiNZPX6d18-_r
Fediponics beta testers can use Custom Keyword Groups to auto-suspend these accounts


If you see a resource or advice worth sharing on this page, please message @iftas
@iftas
I set up a rule in Mastodon to require approval for any name with "bp" and after rejecting dozens manually, I finally set up a Cloudflare edge rule. So far it has blocked 59 attempts to open accounts here after running for about 8 hours today (10-Sep)
What is wrong with this person?
The rule I set, which I hope is only temporary, is to block if this is true:
(http.user_agent contains "aiohttp" and http.request.uri.path contains "/oauth")
If u are seeing a wave of spammy regs today and u want a quick fix, we have one that is working. We are not sharing publicly to avoid the spammer seeing and changing the junk, but is okie to msg if u need help.
Takes like... 2 minutes.
The spam accounts from the last few hours ("Automated protocol deliverability probe") appear to be logging in via their own OAuth app called “BoomProtocolProbe.” So here's an attempt:
To prevent “BoomProtocolProbe” from registering, we created a trigger in the Mastodon database that checks the name BEFORE INSERT and blocks the app if it matches.
@about.iftas.org @iftas
Those arseholes are targeting #PeerTube instances now too