So some spam signups just happened (all username12345678@gmail.com format e-mail) This caused bounced mail to increase, causing Mailgun to block our domain to prevent it getting blacklisted.
So:
- Mail temporarily doesn’t work
- I closed signups for now
- I will ban the spam accounts
- I will check how to prevent (maybe approval required again?)
Stay tuned.
Edit: so apparently there is a captcha option which I now enabled. Let’s see if this prevents spam. Registrations open again.
Edit2 : Hmm Mailgun isn’t that fast in unblocking the domain. Closing signups again because validation mails aren’t sent
Edit 3: I convinced Mailgun to lift the block. Signups open again.
I’ve run into this issue with some of my servers in the past and it’s a real PITA to deal with because not only do you have to mitigate the issue, but then you have to make requests to get de-blacklisted, etc. I finally got sick of it all and installed a Barracuda spam firewall in front of the mail server. I have MUCH easier control over IMAP/SMTP now.
I was vaguely aware of that, but I’m very glad that you posted this link because I didn’t realize that it was this serious and that it hasn’t been patched! My unit is completely up-to-date with firmware and patches, but I can’t find an actual list of affected models ANYWHERE! I’ve taken a cursory look at my system and it doesn’t appear to be compromised, but I emailed Barracuda for additional info. Thanks for this!
The spam battles are heating up!
Wanna recruit a helper who promises nothing but benevolent assistance?
I solved this problem once. What you do is have a custom captcha that you code yourself. It can be as simple as “What is 2+3?” and have 10-20 questions that you rotate between. Most spammers will be too lazy to update their spambot.
Don’t just include it as text though. Rather, present the question as text in a picture.
I love how transparent you are with the management of this instance. Kudos!
I am from Lemmy Canada. I have noticed that when I come to a community hosted on Lemmy World I am often signed out. Do I need to sign up here to participate?
I was trying to open my account just when lemmy.world was closed earlier. When I pressed the button to create it I only got and enless “charging” animation. But when it reopened, I just started the process again, and was as easy as a breeze and extremely fast. Glad to be here! (and this is my first post)
Thanks for staying on top of things! Really appreciate your efforts!
Wow that was quick, amazing job as always!
Those usernames are so unimaginative. Who would pick a name like that?
I know, right? That’s the kind of thing an idiot would have on their luggage!
12345 is the code to my luggage
FYI 18.0 does not have captcha according to release notes. May want to delay upgrade until 18.1? Or institute a stricter signup like requiring email verification? just wanted to mention it
Thanks for the tip- I’m having the same issue. How do I ban those accounts? I can’t even tell who my users are
My instance also experienced this. I’m the only active user (I made it a day ago), but the user count is up to 2K now. It stopped after I enabled captchas, but I want to remove these spam accounts so they don’t cause issues elsewhere.
I don’t even have a slight clue as to what I should look for in my database.
If you haven’t figured it out yet or got a response yet, hop onto the instance admin group on matrix for Lemmy (details are on the GitHub or join Lemmy page somewhere I believe) and one of the many other folks running instances can probably walk you through it
can’t have anything nice nowadays