Anyone else seeing spammy-looking signups from QUALITYNETWORK IP ranges? #mastoadmin
Here's a slightly revised CIDR list that seems to cover all the IPs used by the spammers so far:
(some CIDRs are redundant because they're from different sources)
Hopefully that'll do for now.
Here's a version of the block list you can dump in your nginx to get rid of the bots:
The advantage of using nginx here instead of your firewall/iptables is that you'll have an easier time checking for false-positives in logs (in case I fucked up); the bots follow a predictable pattern (GET / then GET /auth/sign_up) while real traffic would stand out.
@pfigel Is there an easy way to put that into iptables or maybe nginx?
@pfigel Sidenote but - I hope there is a nice list :3
mastodon.at is a microblogging site that federates with most instances on the Fediverse.