buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
My cache all email got some spam/phishing email with the link url being a github.io url.
I am wondering if something scraped my Mastodon instance and misidentified the account, which doesn't have an email account created, as an email address. How do I report this to #github? #Phishing #Spam
mail-auth-service-source dot github dot io/srf-client_id-REDACTED?emp=redacted@oldfriends.live is the link
Here's a head-shake worthy #spam from overnight if anyone wants to play with the scammer:
I'm Jeff Bezos,
The CEO of Amazon, it's on this note that I'm informing the world of my intention to give out my Fortune of $124 Billion of my wealth to the lucky ones around the country and world at large.
Congratulations, your name and details were randomly selected from some Google business contact listing as one of the beneficiaries of this
charity project. each person would be awarded $1,200,000,00
[link to a cnbc story, jeff-bezos-says-he-plans-to-give-away-most-of-his-124-billion-fortune]
DONATION CODE: G506328
Contact how to proceed.
Email: mrjeffbezos87 (at) gmail dot com
Words Commonly Found in Spam Domains
In a previous post, Interisle looked at the practice of embedding brand strings in domain names used for phishing and spam. Today, we’ll provide a summary of words that we most often find in domains used to spam.'
https://interisle.substack.com/p/words-commonly-found-in-spam-domains
How Common are Brand strings in Spam and Phishing Domain Composition?
Embedding the exact string of a brand into a domain name is also a known behavior of cybercriminals.
Today, we’ll look at some current and recent past data to answer, “how common is this in spam? In phishing?”
https://interisle.substack.com/p/how-common-are-brand-strings-in-spam
Dear Spammers and Scammers over on Tumblr, I know exactly what you are trying to do when you start an unsoliticed message to me with "Hello, how are you doing". You are trying to get a conversation with me going.
Well, I am a neurodivergent person and I am not into small talk. So just tell my right away what you want (or offer), so that I can block you even faster. 😠
(Latest case was a guy who apparently is a paid beta reader. Not interested in that.)
So, hier nun meine versprochenen Infos, die ich nachreichen wollte:
In den frühen Morgenstunden bzw. heute Nacht wurden auf einer meiner Instanzen vier Accounts erstellt, auf der anderen Instanz ein Account. Da die Namen/Mailadressen mehr als auffällig waren, schaue ich mir die Logs an. Die Sichtung der Logs ergab, dass diese Registrierungen alle von der selben IP (siehe Bilder, ich schreibe die IP hier absichtlich nicht aus) kamen. Auf meiner dritten Instanz, die für Registrierungen gesperrt ist, wurde die Seite /register aufgerufen. Als man dort kein Registrierungsformular fand, war der Server wohl uninteressant.
Erste Maßnahme von mir war natürlich, die Accounts zu löschen und die IP zu sperren. So wie sich das für mich darstellt, wurde mit den vier Accounts erst einmal "angetestet", was möglich ist. Auf der zweiten Instanz wurde die Person/der Bot von mir unterbrochen und die IP gesperrt.
Wenn ich mir die Logs so anschaue, denke ich, dass hier "antrainiert" und getestet wird/wurde, wie man am besten und schnellsten neue Accounts erstellen kann. Möglich, dass hier "nur" SEO-Spam verbreitet werden soll. Evtl. aber auch Schläfer-Accounts, die irgendwann später mal agieren werden.
Nach der Erstellung der Accounts wurde innerhalb der nächsten Sekunde sofort das Profil bearbeitet (Ergebnis siehe Bilder). Danach erfolgten mehrere Curl-Abfragen der neu angelegten Profile, auch zwischendurch erfolgten curl-Abfragen. Ebenso wurde /api/v1/apps bzw. /api/v1/instance abgefragt.
Da ich mehrere Server habe, schaute ich nach, ob die IP auch auf anderen Servern zu finden ist. Ergebnis: Die IP hat nur Server besucht, auf denen Friendica installiert ist!
Weder die IPs, noch die Mailadressen tauchen auf Spam- oder Abuse-Listen auf. Auch Fail2Ban greift hier natürlich nicht wirklich, da zwischen einigen Registrierungen natürlich massig Zeit war. Natürlich kann man aber für so ein "Verhalten" einen Jail/Filter erstellen, klar. Aber auch hier gibt es dann natürlich wieder Möglichkeiten, diesen zu umgehen.
Ich kann nur jedem raten: Habt ein Auge auf die Registrierungen, in Friendica kann man auch die Anzahl der täglichen Registrierungen einstellen. Ebenso lässt sich in Friendica einstellen, dass die Registrierung nur noch mit Bestätigung möglich ist.
Anhang: 5 Bilder (Leider werden auf manchen Fediverse-Plattformen nur 4 Bilder angezeigt, dies ist kein Fehler, sondern eine gewollte Limitierung der Software, die deine Instanz verwendet 😉 )
Nun erstmal noch nen Kaffee... ☕
Do Criminals “age” Domains?
It’s widely understood that criminals most often acquire domains through direct registration, use them shortly after acquisition, and repeat this process when they begin their next campaign(s). We call these malicious domain registrations.
It’s also been observed that some criminals acquired domain names months, even years before they were used in a campaign – through domain hijacking, by registering neglected domains, or registering and storing domains before using them – reasoning that old domains might evade detection systems that used domain age as a trust indicator.
Today, we’ll look at data that we recently ingested at our Cybercrime Information Center to understand which of these conventional wisdoms hold water.
Gaza Spams
Gaming Spams
Verification Scams
Gleich alles zusammen, mehrfach und in den letzten 12h
Das Fediverse wird populär 🙄
Check your #SPAM folders folks, filtering is not perfect.
https://www.cbc.ca/news/canada/british-columbia/vancouver-teacher-pay-suspension-emails-9.7113444
Ich hatte gerade eben bei einer meiner Friendica-Instanzen eine Registrierung mit einer E-Mail-Adresse, die explizit für KI-Agenten gemacht ist.
Hinsichtlich der gestern plötzlich aufgetretenen Spam-Attacke würde ich empfehlen, euch die genutzten E-Mail-Adressen, die bei der Registrierung auf eurer Instanz angegeben werden, einmal genauer anzuschauen.
#Friendica, #FriendicaAdmins, #Fediverse, #Admins, #Spam, #Scam, #Bot, #Phising
@stefano What I love about #Mastodon is the #community. The #spam #scammers and #malicious actors are far and few between. There isn't an incentive to look elsewhere.
Of course, that also speaks *volumes* about instance owners and administrators. 😀
There's a new wave of spam - all around the Fediverse.
Please remember, there's no "Mastodon Moderation Team" sending out strange verification messages.
That's all spam.
There's a new wave of spam - all around the Fediverse.
Please remember, there's no "Mastodon Moderation Team" sending out strange verification messages.
That's all spam.
There's a new wave of spam - all around the Fediverse.
Please remember, there's no "Mastodon Moderation Team" sending out strange verification messages.
That's all spam.
Leute passt auf, es ist schon wieder eine Scam Aktion am laufen. Fallt nicht auf den Scheiß von Verifikation rein RE:
Im Moment von mastodon.world
Days since I had to report a major Canadian retailer to their marketing mail host for not honouring marketing communications preferences, sending non-working links for "manage your preferences" or "unsubscribe", having a non-working link in the List-Help: header of an unsolicited marketing email, and having a website that errors out when trying to use the "contact us" function:
0 (zero)
#ShoppersDrugMart #Shoppers #PCid #Loblaw #privacy #security #PIPEDA #spam #marketing #UCE
Small language models, paired with reinforcement learning and proper training, could significantly improve spam detection by focusing on the emotions an email is supposed to generate. For other fascinating (and horifying) uses of reinforcement learning, see the Forbes Tech Council.
#AI #reinforcementlearning #spam
https://www.forbes.com/councils/forbestechcouncil/2026/02/24/where-reinforcement-learning-plus-human-oversight-works-best/
Friends, is this https://nxdomain.no/~peter/20260224_smtp_blast_to_imaginary_friends.txt what a successful campaign looks like?
(also see https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html or for that matter https://nostarch.com/book-of-pf-4e) @nostarch #greyptrapping #spam #spamd #pf #packetfilter #greylisting #email #cybercrime #marketing #scams
Speaking of #spam, when something signs me up in their mailing list, calling the option "I don't recall signing up for these emails" is such a bullshit option.
I do not just "not recall" signing up, I ABSOLUTELY DID NOT. How do I know? I don't just use an old e-mail alias an be like "Today I'll use this address to order myself some yammy spam!"
Fuck you, spammers.
In case you're wondering about the strong reaction, I've had two positions in my life where I've watched after corporate e-mail servers and spam was always the headache, one way or another. At times it was also a case of PEBCAK, which added the annoying user aspect to it.
Amazing just how literally everything is out to sell your e-mail address to spammers. When I was active in pinball tournament scene, I had an alias address for registering to tournaments. That address is now getting hit hard by all kinds of junk from arcade openings to arcade-related stuff being sold by dropshippers. All this from using the address in tournament sign-ups.
There's also been couple of cases, where a tournament director doesn't understand what CC and BCC do in e-mail and all the sudden I see all the 200 people's e-mails, some from people who probably didn't mean theirs to be in the public.
I can only imagine how bad it is for people who put their address in every possible Send me more spam! mailing list out there.
At least I can retire that alias, people using their actual, well known addresses won't be so lucky.
When you see antisemitic bots like this that spam replies to posts criticising Israel’s ongoing genocide of the Palestinian people, make sure you report and block them.
(They block you after commenting so you can’t act on their post. Unless, that is, you run your own instance like I do and can suspend them.)
But wait, did I just call them antisemitic?
Why yes, conflating Zionism with being Jewish is to state that all Jews support Israel, settler colonialism, apartheid, ethnic cleansing, and genocide. Of course not all Jews are Zionist and support such inhumanity. And not all Zionists are Jews.
The only ones painting targets on Jewish backs are Zionists.
#israel #genocide #ethnicCleansing #apartheid #settlerColonialism #fediblock #fediverse #mastodon #zionist #bots #hasbara #spam
I use #Google Messages for #texting. It's not bad but its only solid features are the #spam blocking and the fact I can use it in a web browser. Oh, and #RCS (as questionable as that may be).
I'd really like to move away from it because, well....Google, but I haven't found a suitable replacement - either on Google Play or F-Droid.
Most #SMS apps are rather bare bones when it comes to features. I am looking for something better.
I am on my second try for Messages on F-Droid but it once again never finishes syncing messages. I deleted over 60 large old conversations and still it gets to about 2/3 done before restarting. I let it run overnight and it never finished.
https://f-droid.org/packages/org.prauga.messages
Any recommendations?
"The Rest Is Trash"
We are now halfway through the nineteenth year of greytrapping, still tracking and collecting from the wealth of imbecility out there
https://nxdomain.no/~peter/the_rest_is_trash.html (tracked https://bsdly.blogspot.com/2026/02/the-rest-is-trash.html) #spamd #greytrapping #greylisting #openbsd #freebsd #spam #antispam #cybercrime
⚠️ SCAM WARNING ⚠️
We’re getting blasted by a bot-driven barrage of accounts requesting Palestine aid.
These are the avatars being used, and account names look like this:
Mahmoud│⟪Hear Our Cries⟫
Mahmoud│⟪Feed Our Hunger⟫
Mahmoud│⟪Dry Our Tears⟫
The person in the photo may be real, but the accounts are not. They use signature spam methods.
Report, block, and DO NOT give money. Many already have. This is theft from real Palestinians.
Follow-up note…
There are lots of legitimate accounts on Mastodon that are seeking aid for Palestinians. This warning does NOT imply that they’re all scams. I am only warning about this one particular pattern.
Use your judgment about any mutual aid account. Please only heed my warning specifically about this particular pattern of accounts. The names/avatars here are the flags you should look for.
Give aid to legitimate folks who need it. 🙌🏻
Rechtsanwaltskanzlei (!) aus Stuttgart schickt mir schon zum zweiten Mal unbestellt eine E-Mail mit einem PDF im Anhang. Eine Preisliste zu Liquidationsartikeln. Meine Anfrage, ob sie für die Aussendung verantwortlich sind (Absender ist nicht ihre eigentliche Mailadresse, aber die ist in der Mail genannt), woher sie die Daten haben usw., beantworten sie mit „Ist Ihr Leben wirklich so langweilig..“
OK, dann muß es halt der zuständige Datenschutzbeauftragte sein. Nein, mein Leben ist eigentlich nicht langweilig, Herr Rechtsanwalt. Aber Ihres wird bald spannend.
#Neuland #Podcast - Neues aus dem Internetz: Neuland Finale 2025 und Ausblick auf 2026 - #Linux auf dem Vormarsch & nervige KI-Contentfarmen
In dieser Neuland-Ausgabe erfahrt ihr:
✅ Warum #LinuxGaming plötzlich ernsthaft konkurrenzfähig ist
✅ Wie #Windows UX-Chaos & #Werbung User vergrault
✅ Warum #ARM, #Handhelds & #Steam den Trend pushen
✅ Wie KI-#Spam & Content-Farmen das Netz fluten
✅ Warum #Google entscheiden muss, was Reichweite bekommt
✅ Wieso #Nextcloud & europäische Clouds an Bedeutung gewinnen
✅ Wie sich #Creator-Ökonomie & Wertschöpfung verändern
✅ Und weshalb 2026 das entscheidende Tech-Kipppunkt-Jahr wird.
Webseite der Episode: https://share.transistor.fm/s/77812e7d
Mediendatei: https://media.transistor.fm/77812e7d/1541d955.mp3
I find it funny how many shitty #Spam #eMails try to #blackmail the recipient.
Personally, the only recommendes step is to delete them unread and completely ignore them.
Plus they don't even personalize messages.
Still, as they all ask for #Shitcoins like #Bitcoin, I just have a collection I got over the years on multiple occasions so #AntiFraud professionals & #Investigators can take a closer look and flag the Addresses for further analysis.
I have a specific email address I only use to sign up for newsletters & blogs.
I've just had my first ever spam email on that address.
Within hours of signing up to the EURAO amateur radio newsletter - coincidence?
I wonder whether they also believe in the tooth fairy:
Jan 25 07:48:32 skapet spamd[52525]: (GREY) 111.68.23.116: <> -> <delivery9.nospamcloud.com-1769323698-testing@bsdly.net>
Jan 25 07:48:32 skapet spamd[43842]: new entry 111.68.23.116 from <> to <delivery9.nospamcloud.com-1769323698-testing@bsdly.net>, helo delivery9.nospamcloud.com
Yes, it's a fresh one, see https://nxdomain.no/~peter/twenty-plus_years_on_smtp_callbacks_are_still_pointless.html #smtpcallbacks #antispam #counterproductive #spam #cybercrime
If you use #GMAIL, you should be aware that as of this post's timestamp, their spam detection is down and it is likely your emails aren't being scanned for spam, unverified senders, or harmful software.
"We advise the users to be extra diligent in lieu of missing spam checks." #Spam #Google
Google Status:
https://www.google.com/appsstatus/dashboard/incidents/NNnDkY9CJ36annsfytjQ
@ustralien Obviously, #widthdrawals in the form of #subscription are the main leverage here and many if not all sites operate on 4 pillars to keep revenue incoming.
Making "onboarding easy - offboarding painful, frustrating and hard" is something sites literally pay for!
The latest "Lazy reading" by Dragonfly Digest @dragonflydigest https://www.dragonflydigest.com/ has "Eighteen years of Greytrapping" https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html featured. Later this year it will be nineteen years :) (and updates will come) #spamd #spam #openbsd #antispam #greytrapping #greylisting #cybercrime
Es gibt eine neue Spam-Welle 😌 Sucht am besten nach dem Usernamen @Archive_Shinzai.
Fairphone is really losing points with me right now. I received an email with a survey from bazaarvoice-cgc.com, which was actually commissioned by Fairphone to conduct these surveys via email. On their website, they even lie to your face:
"Is Bazaarvoice spam?
This email from Bazaarvoice is not spam or a phishing attempt; it is a genuine request to share your experience with the product you purchased with Fairphone."
Go to hell and rot in my blacklist.
BSI prüft E-Mail-Programme
"In der vorliegenden Untersuchung wurden zwölf für den Verbrauchermarkt relevante E-Mail-Programme dahingehend analysiert, inwiefern sie Eigenschaften wie Transport- und Inhaltsverschlüsselung, SPAM-, Phishing- und Tracking-Schutz sowie Prinzipien der Usable Security umsetzen".
https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/DVS-Berichte/E-Mail-Programme.html
#did #digital #email #datenschutz #spam #tracking
A Major Mail Provider Demonstrate They Likely Do Not Understand Mail At All https://nxdomain.no/~peter/they_do_not_understand_mail_at_all.html (tracked https://bsdly.blogspot.com/2026/01/a-major-mail-provider-demonstrate-they.html)
#greytrapping #spam, #antispam #greylisting #blocklist, #openbsd #freebsd #smtp #email #SMTP, #contentfiltering #SPF #DMARC #security #networking
@nixCraft I consider all "#AI" output #malicious until priven otherwise and all #AIslop as #Spam!
Heh. Looks like the tracked version of Why 451 is Good for You - Greylisting Perspectives From the Early Noughties https://nxdomain.no/~peter/why_451_is_good.html (tracked https://bsdly.blogspot.com/2025/12/why-451-is-good-for-you-greylisting.html) hit hackernews: https://news.ycombinator.com/item?id=46414653
No, I willl not respond to those comments either :D
#greylisting #greytrapping #spam #spamtrapping #antispam #spamd #openbsd #smtp
The update you have been waiting for:
"Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off?" https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html)
now has the complete 2025 data in place. #openbsd #spamd #greytrapping #spam #antispam #cybercrime #spamtraps #blocklists
Why 451 is Good for You - Greylisting Perspectives From the Early Noughties https://nxdomain.no/~peter/why_451_is_good.html (tracked https://bsdly.blogspot.com/2025/12/why-451-is-good-for-you-greylisting.html) @nostarch #greytrapping #greylisting #smtp #email #spam #antispam #bookofpf
LinkedIn's 2025 Data Crisis: 4.3 Billion Records Leaked, Risks Rise https://www.webpronews.com/linkedins-2025-data-crisis-4-3-billion-records-leaked-risks-rise/ #cybersecurity #LinkedIn #DataTheft #scams #spam #DataScraping
For anyone curious: I am currently scraping my #SPAM folder clean and I am curious how many people are stupid enough to believe the shitty #blackmail #spam #eMails demanding ransom for something that doesn't exist.
Obviously I'd not pay any ransom as a matter of principle!
I'm not sure how Layla and May001 snuck past SpamAssassin but the assassin is being re-trained.
@marcel @cryptoparty @zalintyre ja, und juristisch wäre das was was ich nicht ohne fachanwaltliche Rücksprache versuchen würde.
Ich bin ja eher für automatisiertes Reporting:
Und in der Zwischenzeit werden die Hoster automatisch blocklisted!
@iwritelike Wow. It's SO good that you have to spam social media hashtags! Blocked. #spam
Immer mehr Mastodon Instanzen treten plötzlich aus dem osteuropäischen Raum hervor, die einfach nur als Verbreiter von kommerziellem Müll von irgendwelchen WordPress Seiten dienen, gepaart mit Free Speech Anspruch ohne Moderation. Diese Instanzen versuchen, auf weiteren kleineren Instanzen zusätzliche Bot oder Plugin Accounts zu erstellen, um so ihren Müll noch besser und schneller verbreiten zu können.
Wer macht in diesen Tagen ähnliche Erfahrungen?
I turned off "smart features" (aka #AI) in my gmail account. Doing that means instead of parsing the inbox into Primary, Social, and Promotions, it's now all one big inbox.
Now, I spend time each day Unsubscribing from email lists I'm on. Also unsubscribing to most substacks.
I had no idea how bad it was, as I generally avoided the Social and Promotions folders. There's a lot of junk email in this world, and I seem to have opted into most of it.
#Spam Watch 2025: The hidden trackers and inbox overload behind holiday marketing
https://proton.me/blog/spam-watch-2025
#privacy #email #holidays #GiftGiving #OnlineShopping #eCommerce
(I'm not asking for advice about dealing with spam. SpamAssassin has this one well in hand. I'm just curious if anyone else has been seeing spam like this).
Receiving a growing number of automated fundraising requests for candidates around the country, on a phone number that has never been associated with any political activity (or, really, any activity at all).
Thanks, data breaches.
Democrats: this is not a way to make friends.
Oh, here's a new one. I've been added to a team in Microsoft Teams! The team name is as follows, with a few redactions. Typos left as-is.
Subscription Payment of Amount 799. 99 USD is confirmed. If this wasn’t you reach Support immediateIy at 1 (805) 284-xxx, Plan: Norton Ultimate Plus (1 Year) Invoice ID:ANE-93xxxx
God help us. Are they sharing our email addresses with the alt-right White House press corp? Got an unsolicited, not opted-in for, out-of-the-blue introductory newsletter from The Epoch Times that went to a dedicated, unpublished email account I use ONLY to conduct personal government business, like SSA, IRS, etc.
The email said when I click an article link I will be consenting and an account would be created based on my email.
The article in the email weren't alt-right or conspiracy ones. They were bait. #USPol #Spam #Disinfo
Anyone else yet?
I gather they've finally taken this measure because of the preponderance AI-generated slop, but with any luck these other issues will improve too. The arXiv press release states “Review/survey articles or position papers submitted to arXiv without this documentation will be likely to be rejected and not appear on arXiv” so it does sound like they are acknowledging the other problems and intend to enforce their rules more strictly in the future.
"arXiv says it will no longer accept Computer Science papers that are still under review due to the wave of AI-generated ones it has received."
From https://infosec.exchange/users/josephcox/statuses/115486903712973154
#Google #GoogleClassroom #Gmail #spam #MonopolistsDontInnovate
This post is not an invitation to scold me for using Google products or to suggest alternatives. It is also not a request for technical support.