re: toot/blocklist scraping info request
If so, you can send an abuse report to abuse@aussiebroadband.com.au, regarding ips `159.196.229.70` and `2a01:4f8:162:6027::2`. One of my servers shows scraping access logs going back to at least December 2022
re: toot/blocklist scraping info request
also `2a01:4f8:162:6027::2`, with user-agents "Ruby, mastodon 0.1.1" or "mastodon_stream v0.1"
toot/blocklist scraping info request
can other server admins grep their logs for `159.196.229.70`, they seem to be doing mass scraping of public timelines, toots and blocklists.
from an Australian residential ip?
instance block rec
#FediBlock bbad.com (instance at fediverse.bbad.com)
federates/interacts with all the usual scum
re: Mitigating blocklist scraping by fash
Quite interesting workaround; the kiwifarms scraper is configured to not follow HTTP redirects, so by adding one you can make them give up, while legit users can still view the page without issues.
https://git.pixie.town/f0x/nixos/src/branch/main/nodes/aura/services/nginx.nix#L202-L215
Adapts my nginx setup to redirect /about/more to /about/much-more
Of course a scraper could go to much-more directly now, but if we all pick something unique, that's impossible to hardcode for. And if they *do* start following redirects, we could introduce honeypot instances that redirect all around the place, disrupting the scrape (which all happens in sequence across domains btw)
re: Blocklist scraping by fash
`70.106.192.146` too, though it's unclear what software it's running
Blocklist scraping by fash
So this has been an ongoing issue, would love it if people found the earlier threads about it for more context cause I don't have the spoons right now
Originally written by "mint", hosted on the kiwifarms git is a tool that continuously scrapes publicized instance blocklists to allow searching who has you blocked (resulting in emails like uwu we did nothing wrong how dare you block our instance)
Through correlation, turns out the main IP being used by fba.ryona.agency is `54.37.233.246`. Blocking that at the firewall level prevents them from getting any new data.
Other instances exist too though, being hosted on
`23.24.204.110`, `45.86.70.49`, `88.65.6.124`, `187.190.192.31`
the drow.be / bka.li / teleyal.blog / mooneyed.de "kromonos" user has their own version, that feeds an API that gives your instance a highscore for blocking their shit, scrapes from `185.244.192.119`, with user agents presenting as random instances
These, and other scrapish ip's are also listed in https://git.pixie.town/f0x/nixos/src/branch/main/nodes/aura/configuration.nix#L103
MastoAdmin SQL queries to get followers/following by remote domains
#MastoAdmin tip because at least on our version the Domain summary will *count* the number of following relations, but with has no way to list who is following who.
Postgres queries:
"Their followers here":
```
SELECT user_follows.username, user_follows.domain, user_following.username as follows, user_following.domain as follows_domain FROM follows INNER JOIN accounts AS user_follows ON user_follows.id=follows.account_id INNER JOIN accounts AS user_following ON user_following.id=follows.target_account_id WHERE user_following.domain='gts-dev.pixie.town';
```
"Our followers there":
```
SELECT user_follows.username, user_follows.domain, user_following.username as follows, user_following.domain as follows_domain FROM follows INNER JOIN accounts AS user_follows ON user_follows.id=follows.account_id INNER JOIN accounts AS user_following ON user_following.id=follows.target_account_id WHERE user_follows.domain='gts-dev.pixie.town';
```
instance block rec, racism
#FediBlock librosphere.fr
- Racist replyguying
- federates with all the usual garbage instances
- instance about page links to the kiwifarms blocklist scraper tool to show how sad they are to get blocked by other instances
- offers soapbox frontend
Fediblock - Stux, list of all his instances and domains that I'm aware of.
Mastodon instances:
• mstdn.social,
• mastodon.coffee,
• masto.ai.
Pixelfed instances:
• pixey.org,
• gram.social,
• catgram.co.
Misskey (shut down):
• misskey.ai.
Peertube:
• peertube.tv,
• stux.tv (I assume that was Peertube based on the tld),
• stuxmedia.com (shut down).
His Goldfish project & instance:
• goldfish.social.
His Twix project:
• twix.social.
Lemmy:
• u.fail (redirects),
• geddit.social.
Kbin:
• forum.fail.
Wordpress:
• stuxstore.com.
Other domains:
• stuxhost.com,
• stuxcraft.com,
• stuxnet.ai,
• stux.info,
• share.fail,
• social.as,
• social.fo,
• loazy.com,
• stuckr.net.
His account handles on the various instances:
• stux,
• stuxhost,
• stuxcraft,
• io,
(Will list them all I find below: https://toots.hwl.li/@jase/110578809874522137)
This is for informative purposes for anyone desiring to block anything ran by Stux, since he runs so damn much.
And for anyone that saw when he blocked my instance at the end of May, and if your only context is based on my pissy report at him, here's context on that, all the reasons that lead to me blocking him 10 months ago that he had a tantrum to his followers over about:
https://toots.hwl.li/@jase/110572122255495642
(And his Geddit instance hasn't blocked anything yet from when I last looked either and is actively federating with baest and crap, how clever..)
Edit: just remembered, Stux also runs the Soapbox front end at coffee.mastodon.coffee.. another thing I have not been happy at all at him about, and he used to have it also at beta.mstdn.social.
If you want to know what it's like to be visibly Jewish on Mastodon. It's the harassment you will get whenever you publicly express joy and love for your own Jewishness.
Because the bigots want you to be ashamed of it, and hate it like they hate it.
#Fediblock emacs.ch
@RyukoRazz This is exactly how I feel about it as well. Every year or so I re-evaluate my UI options (in both JS and Rust) and every time the answer is the same: all of it is a shitshow, just to varying degrees.
If the people who so loudly complain about Electron proliferation were to put just 5% of that effort into actually addressing the UI problems that are driving people towards Electron to begin with...
⚠️ READ BEFORE FOLLOWING ⚠️
if i don't know you from elsewhere (under same nick), shoot me an introductory DM first (following back is fine)
I do anarchist tech stuff and run free services at https://pixie.town
I program, solder rgb led thingies, and fly fpv quadcopters
en: they/them
nl: die/dies (langzaldieleven.nl)
“i don't trust like that”
not a furry, actually
Extreme coffee-out-of-a-wineglass Energy
something something trans list stop scraping bios
and now a word from our sponsors (screenreader warning it's zalgo)
T̀ͧ̓̑͐̓̍̂̏҉̴̷͚̦̤͙̜̖͙̝͟ợ̵͈̗̮̲̥͕̼̩̭̞̙͉̆ͮͧ̉̒́̑̍̋ͭ̌ͭ̒̉́̕͟ ̐̅̈́ͯ҉̸̴҉̹̟͕̖̠̟̤͕į̸̙̮͓̤̠̘̫̦̥̣̻͚̣̎ͭͯ̋̉͝n̔̄̏̈́̃̇͛̂̋̇̐́͘͝҉͙͔̠͇̖̤̹̭̱̪v̴̴̛̘̠̰̹͚̱͉̳̘̥̞̳̪͈ͥͭ̅ͥͦ̀͛̔̃̃̎͋̋̎͐͌ͪ̚͟͢ͅö́́̎ͬ̔͑̆̃̅̒̿ͪͯ̓͏̞̱̜͍̬̗̹̫̝̪͓͕̳̬̰͘͝kͥ̒ͣͦ̌͛̃͒̀̿ͣͪͤͬ̍ͮ̚̚̕͝҉̹̰̟̰̻̻͍̠̗̳̬̬̬̞̟̹̩͇́͜ẹ̴̡̨̱̹͍̯̱̗̗͍̬̐ͣ̑͑̐̓̈̑ͥ̅́̇̃͒̀̃̂́ ̨̛͖̬͇̣͔̼̥̬̝̥̣̭̝̪͎͈̌̅͆̉̀͘͜ͅẗ́̄͊̌̍̆́̿́̊ͣͮ̅ͥͩ̔̏͏̧̳͎̥͈ͅh̴̴͇̻ͧ̍̐̈͐̎͛́̀̽̃̒̔͢͢ȩ̸̶̶̟̗̮̺̭̥͕̭͎̺̙͎̖͔ͪ̑͛̓̅ͪ̄́ͧ͡ͅ ̡̧͇̤͚̻̬͉͔̥̫̟̙ͮͩ͌̿́̆͋͜h̵̨̭̰͎̭̱͊͒́͒͆̎ͮ̈́̆ͪͧ̚͞î̛̦̞͓͖̭͈̮͔̩͙̱̖̞̳̥̦̩ͭ̂̏͒ͨ̃̿̽̓͑ͫ̕͝͡vͧ͋ͪ̌̂̑́͌̂̒͑ͮ̋̂ͫ̈́҉̹͜͢ȩ̡̖̯̞̺̭̗͔͇̻̤̼͈̙̞͉͙̈ͤ͊ͨ̀̆͆͒̓̄̿ͭ̃̚͜͝͡-̶̪̪̠̝̜̯̜̹̭̯͎͍̲̱͉ͪ̏͒̊ͫ̀̈͘͡m̸̪̘͙̰͚̗̳͕̟̖̿̌͐̔̐̈̽̃ͯ̅͢ͅͅi̸̷̧̛͍̝̦̫̮̤̐͑͗̏ͬn̡̨͆ͩͤͫ̔̈́̈́͊͐̂͛̀̚͞҉̜͍̝̰̱͚̜̹̞̝̞͈d̢̫͕͚͕̥̰̝͆͗́ͨ͑̈́̓͜ ̡̩̜͎̳͎͂̓ͫͭ͐̀͡ȑ̷ͭ̑ͪͭ͋͢͏͕̳̟͜ͅͅe̴͌̅ͣ̾͒̔́̊̔ͭ̅̄̇͏͎͉͈̤̙p̀ͥ̈ͨͩ͛ͥͣ͗̄̈́̚҉̢͔͉͍̹̮͉̺r̵̸̡̩͎̱̟̺̟̞͈̯̯̪̹͂́ͣ̐͑̒̒̀ͧͩ̿ͮ̕͞ě̵̡̱͈̜̯̳͍̝̦̜̫͈̜̗̘̪̪̓͆͑͋ͮͯͪ̅̂͐̔̆̃ͫ͑̾͒͢ͅş̶͓͉͚̜̪̜͓̘̻̃̔ͨ́̀ͅẻ̵͇͈̮̝̠͖͍̫͉͓̪̠͔̬͕͛̊͐̎̓̽ͫ̌ͧ̅̿́͘n̛͚̺͈͍̰͉͙̤̘̺͖͉̤͖̈͑͑̍̅ͪ̎͂́ͦ̒ͣ̋̆̄̄̍̃̊͟t̵̛͙͚̥͇̫̻̞͖͕̰͈̩̰̱͉ͣ̃ͫ̋̍̈ͥ͗̎ͭ͋͜i̵̡̤͇̣̰̦̟̭̮̩̲͔̭̟̖̹̙ͥ̆̋ͫ̓͌̒̾̍̄̾̎̂͂̏̇ͩ̚͢n̶̮̹̤̻͈̙͔͎̦̟ͫ̀͌͛̋̌̽̀̓̂̕g̷̣͖̠̩͈̲̥͍̦̘̺̏̍͛͋̎͛͒ͪ̇ͮ͠͝ ͦ͂́̿͐̅̌̊̌̉̍̀҉҉͈͖̮̩͎̮̬͖c͖̬̠̫̠̫̗̉̾͋͒̏̄̈́ͬ̊̓͘͝h̴̷̨͉͖̱̗̪̣͕̮͓͕̺͖͈͙̥̬͓̟ͣ̏̀͐̀́̍ͪ̋͒͐ͪ͐́̕a͍͈͉͎̥̠͍͛ͭ͛̃ͫ͒͋́͟ö͙̻͔̙͖̰́̋̑́͜s̶̸̫̖̫͇̣̻̺̹͔ͧ͐̂̈́ͮ͋̌͠.̰̯̞͎̗̺̠͔̫͍̖ͮͦ̒̏̈̾ͭͧ̉͘͢͠