@fediadminbr já temos uma nova cepa do scam da verificação de conta no Mastodon.
Agora eles pedem para escanear um QR Code para "desbloquear sua conta".
Obviamente, não escaneiem nada suspeito que te mandem

@fediadminbr já temos uma nova cepa do scam da verificação de conta no Mastodon.
Agora eles pedem para escanear um QR Code para "desbloquear sua conta".
Obviamente, não escaneiem nada suspeito que te mandem
Why block <mastodon.arell.ai> when you can block <arell.ai> entirely? This way, any new subdomain they come up with will already be blocked.
I suggest you do this instead, if you're an instance admin.
We have a #phishing #scam on #Mastodon. The fake-accounts (often 0 followers/followees) pose in comments as "administrators" or "support teams" of Mastodon asking for account verification. Real admins would never do that!
It's very important that you *report* them! Don't click their link
The mods of mastodon-social acted very fast to delete such an account but the scammers seem to try it now on other instances, especially smaller ones.
heads up to everyone that I got malicious mastodon spam posing as an administrator asking for account verification. it was actually caught and deleted before I could even report it!, but they'll probably be trying from other, less actively moderated instances too.
@fediadminbr atenção gente, apareceu um site chamado arell.ai, que visa "criar ambientes de alta qualidade para IA".
Eles iniciaram um servidor do Mastodon e vêm clonando contas pelo fediverso. Exemplo:
- Pegaram esse perfil: https://infosec.exchange/@hacks4pancakes
- Clonaram aqui: https://mastodon.arell.ai/@hacks4pancakes
São mais de 3.900 contas criadas nesse servidor cheio de gororoba de IA e perfis clonados sem autorização.
Eles também estão falsificando verificação de contas. Aparece um selinho verde de domínio verificado, mas o endereço não tem links de volta para o perfil falso.
A sugestão é bloquear o domínio "arell.ai" inteiro (isso bloqueia todos os subdomínios também).
Referências:
- https://metalhead.club/@thomas/114878505580336321
- https://social.growyourown.services/@homegrown/114879556671836673
- https://oldfriends.live/@paul/114878547592351644
- https://social.growyourown.services/@homegrown/114879608886941947
#FediBlock recommendation, there's a rogue server cloning lots of real accounts so it can impersonate them. There is no legitimate reason for such behaviour, admins should suspend it ASAP:
mastodon.arell.ai
Admins might want to suspend the main domain:
arell.ai
This would be good in case the owner tries the same stunt on a different subdomain. Blocking the main domain also blocks all of its subdomains.
(via @thomas, thread at https://metalhead.club/@thomas/114878505580336321 )
So a #bluesky #mastodon bridge has triggered a huge drama requiring technical experts (like the mastodon creator) to step up , explain what was happening and so on.
I never have been fond of unwanted , imposed , jammed down my instance bridges .
So, here's the new politic for all the services hosted on projetretro.io projetretro.fr and projetretro.tf :
- All bridges (bluesky, nostr, your mom lovense) will be defederated and if applyable firewalled from accessing our network
- All "echo" type software like those who copy Xitter will be suspended and also firewalled
I choose to be on the #fedi , not on #bluesky, #nostr and so on. Don't Force me to be on those without my knowledge nor consent
PSA, reminder regarding fedi scam bots
We've updated the indieweb.social Community Guidelines
Following consultation with the indeweb.social community we have updated the server Community Guidelines.
Thank you to everyone who offered feedback and helped us fine-tune, especially those who support the server Patreon.
Please become familiar with the new Community Guidelines and boost so your peers are aware of this change too.
In case you missed it, the hosting providers @fedihost@mstdn.social make nice video tutorials for Fediverse admins. They're easy to understand and mainly aimed at admins using managed hosting:
https://video.fedihost.co/videos/browse
You can follow their video account at:
The videos currently cover Mastodon, PeerTube and GoToSocial. They also make videos for end users, and podcast discussions about the Fediverse.
Following multiple requests, we've made the decision to turn on Mastodon's latest discovery setting...
External sites will now be able to see referral traffic from indieweb.social
This setting allows publishers to see where the traffic to their site is coming from. The more Fediverse they see, the more they'll start taking decentralised social media seriously.
It won't signal out individual users, only the server
Fediverse admins, especially Mastodon admins,
Scam messages trying to trick users into "verifying" by giving their credit card details are still spreading on the Fediverse. The people behind them pretend to be Mastodon admins and use admin-like profile images.
You might want to warn your server's members that this is going on, and that they should never ever give their card details.
More info about the scam (including a screenshot) at https://social.growyourown.services/@FediTips/114836903383114603
Dear #fediadmin, regarding the current ongoing full force assault on our services by AI scrappers with all the risks associated (costs, services stability, data being stolen and so on) I can only recommend the setting up of #techaro #anubis requests filter to "weight the souls of incoming HTTP requests"
I tested it so far on #alpine #debian deployed services with either #caddy , #apache2 / #httpd and #nginx for the following services #nextcloud, #mastodon, #forgejo, #lemmy, #funkwhale, #bookwyrm and a #minecraft #mapviewer with little hassle and no big issues
Following the use of #anubis, all scrapper (AI and regular) logs dropped drastically and bandwitch usage was cut by two third on the mastodon instance and half for the others services
Do yourself and your users a favor try it : https://github.com/TecharoHQ/anubis
If you're running a public Mastodon server, you can make an announcement to all your members:
1. Log into your admin account
2. Go to ⋯ > More > Administration > Announcements
3. Click "New Announcement"
4. Write the announcement, optionally add timings, click "Create Announcement"
5. When the announcement is live, it will appear above all members' Home timelines
6. You can optionally also email it to all your members by clicking "Notify users" on announcement's listing
Oops! An update brought divas.joburg down and took an impossible time to bring back up. #fediadmin
Seit ein paar Tagen melden sich immer wieder Konten an, die unsere Instanz zum Ausspielen von Werbung / Spam nutzen möchten.
Ist das bei euch auch der Fall?
Oh btw , if your instance hosts a "verify your account " scam, I will nuke the fédération to and from it .
You choose to be #fediadmin time to show isn't just a posture
You can give your Mastodon server its own unique visual identity by adding your own artwork, icons, themes and custom CSS.
You don't have to do all of these things, but each one helps to make your server more distinct and visually appealing. It can instantly get across the intended atmosphere of your server.
https://fedi.tips/how-to-customise-your-mastodon-servers-icons-and-thumbnail
Admins with tech skills might also want to see the article on adding new themes and custom CSS:
https://fedi.tips/customising-your-mastodon-servers-appearance
What tools do you use to manually validate prospective users?