Skip to main content

“Boom Protocol” Spam

This post will collate posts that share advice and guidance on the spam registration activity connected to "BoomProtocolProbe" and the bulk creation of accounts. Notes: Over the course of days, the attack has changed approach several times. Each mitigation is quickly overcome. Please do not overly-share specific details as the actor in question may be monitoring the network for mitigations and adapting accordingly. Use your private groups, backchannels, email etc to communicate with your […]
Federation Bot

This post will collate posts that share advice and guidance on the spam registration activity connected to “BoomProtocolProbe” and the bulk creation of accounts.

Notes: Over the course of days, the attack has changed approach several times. Each mitigation is quickly overcome. Please do not overly-share specific details as the actor in question may be monitoring the network for mitigations and adapting accordingly. Use your private groups, backchannels, email etc to communicate with your trusted peers. If you wish to share with the community, please use #bpSpam to help others find your content.

https://hear-me.social/@admin/117250060656308016

https://bardicperspiration.club/@Overgoddess/117248747537023800

https://mastodon.pnpde.social/@spielleitung/117242341921660658 offers a database trigger for Mastodon and PeerTube: https://pad.pnpde.social/p/FUloCtoOiNZPX6d18-_r

Fediponics beta testers can use Custom Keyword Groups to auto-suspend these accounts

If you see a resource or advice worth sharing on this page, please message @iftas

@iftas
I set up a rule in Mastodon to require approval for any name with "bp" and after rejecting dozens manually, I finally set up a Cloudflare edge rule. So far it has blocked 59 attempts to open accounts here after running for about 8 hours today (10-Sep)

What is wrong with this person?

The rule I set, which I hope is only temporary, is to block if this is true:

(http.user_agent contains "aiohttp" and http.request.uri.path contains "/oauth")

The spam accounts from the last few hours ("Automated protocol deliverability probe") appear to be logging in via their own OAuth app called “BoomProtocolProbe.” So here's an attempt:

To prevent “BoomProtocolProbe” from registering, we created a trigger in the Mastodon database that checks the name BEFORE INSERT and blocks the app if it matches.

pad.pnpde.social/p/FUloCtoOiNZ

2