【站长提醒|大范围撞库盗号】最近联邦宇宙出现一轮大规模撞库盗号:9 月 6 日 12:05–12:41 UTC 短短一小时内,至少 82 个实例、142+ 个账号被同一套脚本改名为「HACKED -...
【站长提醒|大范围撞库盗号】
最近联邦宇宙出现一轮大规模撞库盗号:9 月 6 日 12:05–12:41 UTC 短短一小时内,至少 82 个实例、142+ 个账号被同一套脚本改名为「HACKED - Join t[.]me/HomeFucker5」并置顶垃圾帖。我站也有两个账号中招。
这是撞库(拿其他网站泄露的邮箱+密码来登录),不是 Mastodon 或站点的安全漏洞:从 4.1 到 4.8-nightly、已打满补丁的实例都被命中。攻击者先用密码悄悄"验号",几周后再集中变现,所以现在没发帖不代表没被盗。
建议各位站长排查:
• 登录记录(login_activities)中 UA 为 Go-http-client/1.1 的成功登录,尤其来自这三个 IP:193.202.84.104、45.134.142.231、81.92.219.205
• 昵称含「HACKED」的账号;近期新建的、名为「boost」的 OAuth 应用
• 命中的账号:重置密码、吊销全部会话与应用授权、通知本人
• 提前在 管理 → 审核 → IP 规则 把上述 IP 设为「禁止访问」
也请提醒所有用户:换一个只在本站使用的新密码,开启两步验证,密码不要和其他网站重复。
—————
[Admin alert | Mass credential-stuffing account takeovers]
A large credential-stuffing wave hit the fediverse on 6 Sep 2026, 12:05–12:41 UTC: 142+ accounts on 82+ instances were renamed "HACKED - Join t[.]me/HomeFucker5" with pinned spam. Two accounts on my instance were hit.
This is credential stuffing (leaked email+password pairs from other sites), NOT a Mastodon or server vulnerability: victims run everything from 4.1 to 4.8-nightly, including fully patched servers. The bot quietly validates passwords weeks in advance and monetizes in one wave, so "no spam yet" does not mean "not compromised".
Admins, please check:
• login_activities for successful logins with user-agent Go-http-client/1.1, especially from 193.202.84.104, 45.134.142.231, 81.92.219.205
• display names containing "HACKED"; recently created OAuth apps named "boost"
• For any hit: reset the password, revoke all sessions and app authorizations, notify the user
• Pre-emptively add those IPs under Moderation → IP rules as "No access"
Please remind your users: set a new password used only here, enable 2FA, and never reuse a password across sites.
暂无评论