Avatar
jascha
2479739594ed5802a96703e5a870b515d986982474a71feae180e8ecffa302c6
Run Relayable.org #nostr relay Bitcoin Class of 2009 🧑 Founder of @npub1tpy5sj0wc4txn8fdx02y7lrq33yxmwcrupfgw9jxzunmf9ypfhhs837gzc Cybersecurity pro with head in Clouds. By day I also build massively scalable and redundant data center/cloud architecturesβš‘πŸ«‚πŸ’œ 9367 9961 90C9 B785 889D 276E A61B 8390 B08D CD40

Also checkout Room 104 Season 2 Episode 2 "Mr. Mulvahill" is genius.

8 since some episodes left me disappointed. But others are brilliant.

Been playing whack-a-mole all day. πŸ‘ΎπŸ”¨πŸ•³οΈ

Thanks to nostr:npub1t0nyg64g5vwprva52wlcmt7fkdr07v5dr7s35raq9g0xgc0k4xcsedjgqv for the Onyx builds, it's my go-to for getting spam info on mobile. πŸ€™πŸ’œ

When I want to see a more raw relay feed.

Documenting all the TTPs (Tactics, Techniques & Procedures) for spammers and bots come across to share with relay operators. Data sharing is gonna be key to prevention. Assuming purely up to the client is not sustainable long term. #nostr #relay #relays

Replying to Avatar jascha

Yesterday and overnight seen a few variations on the spam attacks. With nostr:npub16fcy8ynknssdv7s487nh4p2h4vr3aun64lpfea45d7h4sts9jheqevshgh noticed some Chinese language posts mentioning using Relayable relays. Not long after saw our US relay getting an influx of Chinese language posts and Spam from Chinese IPs. Which is odd since someone in mainland China would be directed by our latency based DNS routing to our Singapore relay.

These spam posts are much more evasive than others usng short or long string. Seems to be effecting a lot of relays. We have blocked IPs and found sources of a lot of the spam. The previous spam over weekend was tracked to US and Spain IPs. Adding more policies to thwart these type of attacks. If run relay feel free to DM me for the IP list. πŸ€™πŸ«‚

Examples:

Another is the "cat hugger"

Example:

Replying to Avatar jascha

Yesterday and overnight seen a few variations on the spam attacks. With nostr:npub16fcy8ynknssdv7s487nh4p2h4vr3aun64lpfea45d7h4sts9jheqevshgh noticed some Chinese language posts mentioning using Relayable relays. Not long after saw our US relay getting an influx of Chinese language posts and Spam from Chinese IPs. Which is odd since someone in mainland China would be directed by our latency based DNS routing to our Singapore relay.

These spam posts are much more evasive than others usng short or long string. Seems to be effecting a lot of relays. We have blocked IPs and found sources of a lot of the spam. The previous spam over weekend was tracked to US and Spain IPs. Adding more policies to thwart these type of attacks. If run relay feel free to DM me for the IP list. πŸ€™πŸ«‚

Examples:

Another version of spam seeing is spam complaining about spam (inception spam?). The irony is not lost on me. 🀣

Both. I was purposely baiting the bots overnight to get them to reveal IPs and tactics. The Chinese spam I started to get seemed more organized and focused after the influx of real Chinese users. So in my fiat life this alludes to something usually more sinister. Still digging into it but some source IPs are Chinese govt potentially.

Replying to Avatar jascha

Yesterday and overnight seen a few variations on the spam attacks. With nostr:npub16fcy8ynknssdv7s487nh4p2h4vr3aun64lpfea45d7h4sts9jheqevshgh noticed some Chinese language posts mentioning using Relayable relays. Not long after saw our US relay getting an influx of Chinese language posts and Spam from Chinese IPs. Which is odd since someone in mainland China would be directed by our latency based DNS routing to our Singapore relay.

These spam posts are much more evasive than others usng short or long string. Seems to be effecting a lot of relays. We have blocked IPs and found sources of a lot of the spam. The previous spam over weekend was tracked to US and Spain IPs. Adding more policies to thwart these type of attacks. If run relay feel free to DM me for the IP list. πŸ€™πŸ«‚

Examples:

One interesting behavior is if tag as spam in Amethyst after a few minutes you get another random account replying to that. It seems to have a purposeful delay to (I assume) avoid rate-limiting.

Example:

Yesterday and overnight seen a few variations on the spam attacks. With nostr:npub16fcy8ynknssdv7s487nh4p2h4vr3aun64lpfea45d7h4sts9jheqevshgh noticed some Chinese language posts mentioning using Relayable relays. Not long after saw our US relay getting an influx of Chinese language posts and Spam from Chinese IPs. Which is odd since someone in mainland China would be directed by our latency based DNS routing to our Singapore relay.

These spam posts are much more evasive than others usng short or long string. Seems to be effecting a lot of relays. We have blocked IPs and found sources of a lot of the spam. The previous spam over weekend was tracked to US and Spain IPs. Adding more policies to thwart these type of attacks. If run relay feel free to DM me for the IP list. πŸ€™πŸ«‚

Examples:

Proof of Steak πŸ₯©

#foodstr

Doing some key cutting practice to keep the skills sharp. #keystr #redteam