https://box.n3ko.cc/_/aapa
提问箱
可以许愿制品/插图/碎碎念/骚扰信息,不一定都会回答
RE: https://darkwitch.net/@fury/117225301709619550
近期联邦宇宙正在发生一轮较大规模的撞库攻击,且目前攻击仍在进行。无论你的账号位于本站还是其他 Mastodon 实例,都建议立即自查。
所谓“撞库”,是指攻击者利用其他网站泄露过的邮箱+密码组合,自动尝试登录别的网站。也就是说,即使 Mastodon 或实例本身没有安全漏洞,只要你在别处用过相同或相似的密码,就可能被直接登录。
请用户检查:
不要跨平台账号重复使用相同密码。 如果这个密码曾经在其他网站用过、使用多年、过于简单,都建议更换。
可使用 Have I Been Pwned 检查邮箱是否曾出现在公开数据泄露中,并通过其 Pwned Passwords 服务检查密码是否属于已知泄露密码:
https://haveibeenpwned.com/
https://haveibeenpwned.com/Passwords
若密码已经 pwned,请不要继续使用。
开启 Mastodon 两步验证(2FA),并妥善保存恢复代码:
https://m.cmx.im/settings/two_factor_authentication_methods
即使密码泄露,2FA 也能大幅降低账号被接管的风险。
使用密码管理器生成一个足够长、随机、且只用于当前账号的密码,并管理密码: https://www.privacyguides.org/zh-TW/passwords/
邮箱密码尤其不要和 Mastodon 密码相同,因为邮箱通常也是账号找回的最后一道保障。
本站已经发现部分账号存在与本轮撞库相符的异常,并正在对已确认或高度怀疑被撞库的账号重置密码。
如果你突然发现原密码无法登录,请不要反复尝试旧密码,请直接使用登录页面的忘记密码 (https://m.cmx.im/auth/password/new) 通过注册邮箱重新设置一个全新且未在其他网站使用过的密码。
【站长提醒|大范围撞库盗号】
最近联邦宇宙出现一轮大规模撞库盗号:9 月 6 日 12:05–12:41 UTC 短短一小时内,至少 82 个实例、142+ 个账号被同一套脚本改名为「HACKED - Join t[.]me/HomeFucker5」并置顶垃圾帖。我站也有两个账号中招。
这是撞库(拿其他网站泄露的邮箱+密码来登录),不是 Mastodon 或站点的安全漏洞:从 4.1 到 4.8-nightly、已打满补丁的实例都被命中。攻击者先用密码悄悄"验号",几周后再集中变现,所以现在没发帖不代表没被盗。
建议各位站长排查:
• 登录记录(login_activities)中 UA 为 Go-http-client/1.1 的成功登录,尤其来自这三个 IP:193.202.84.104、45.134.142.231、81.92.219.205
• 昵称含「HACKED」的账号;近期新建的、名为「boost」的 OAuth 应用
• 命中的账号:重置密码、吊销全部会话与应用授权、通知本人
• 提前在 管理 → 审核 → IP 规则 把上述 IP 设为「禁止访问」
也请提醒所有用户:换一个只在本站使用的新密码,开启两步验证,密码不要和其他网站重复。
—————
[Admin alert | Mass credential-stuffing account takeovers]
A large credential-stuffing wave hit the fediverse on 6 Sep 2026, 12:05–12:41 UTC: 142+ accounts on 82+ instances were renamed "HACKED - Join t[.]me/HomeFucker5" with pinned spam. Two accounts on my instance were hit.
This is credential stuffing (leaked email+password pairs from other sites), NOT a Mastodon or server vulnerability: victims run everything from 4.1 to 4.8-nightly, including fully patched servers. The bot quietly validates passwords weeks in advance and monetizes in one wave, so "no spam yet" does not mean "not compromised".
Admins, please check:
• login_activities for successful logins with user-agent Go-http-client/1.1, especially from 193.202.84.104, 45.134.142.231, 81.92.219.205
• display names containing "HACKED"; recently created OAuth apps named "boost"
• For any hit: reset the password, revoke all sessions and app authorizations, notify the user
• Pre-emptively add those IPs under Moderation → IP rules as "No access"
Please remind your users: set a new password used only here, enable 2FA, and never reuse a password across sites.