Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Abuse report - Bots spamming room invite #11997

Closed
TheFrenchGhosty opened this issue Jan 22, 2020 · 5 comments
Closed

Abuse report - Bots spamming room invite #11997

TheFrenchGhosty opened this issue Jan 22, 2020 · 5 comments
Labels

Comments

@TheFrenchGhosty
Copy link

TheFrenchGhosty commented Jan 22, 2020

Description

It looks like some people are abusing a bug/feature of Riot/Matrix and have created a bot that is spamming room invite.

At first I received an invite by someone I didn't know, we didn't have any room in common (I checked) named "karmabot".

I tried to accept the invite, I couldn't, I tried to reject it I couldn't either (just a message "failed to join the room")

After some hours, I could finally reject it, but I instantly received an invite to the same room by someone else (a bot I guess) named No One Leaves.

The original invite come from @ karmabot : calamari . space

The room name is # fun : calamari . space (DO NOT JOIN IT)

The room ID is !xTFUshdYJofEwnzxfi : calamari . space

The bot is @ no_one_leaves : matrix . kiwifarms . net

After I joined the room I instantly received a "greeting" by "No One Leaves", and noticed that lots of people are affected by this.

1

2

2000+ invites...

3

@turt2live
Copy link
Member

We're aware of this and have taken measures to protect matrix.org users. For your own server, https://gist.github.com/turt2live/7bf1e589664298d786dfa6aeccda294a has some options.

Please report these things with an email to abuse@matrix.org in the future.

@TheFrenchGhosty
Copy link
Author

TheFrenchGhosty commented Jan 22, 2020

They're threatening to use dot tk domains (might be a good idea to block those)

In the screenshot, "gamer" is the owner of calamari . space and "divineintellect" (an account on calamari . space) is the owner of the bot.

4

@turt2live
Copy link
Member

@TheFrenchGhosty we're not going to be able to monitor this thread - please use abuse@matrix.org

@TheJonny
Copy link

They're threatening to use dot tk domains (might be a good idea to block those)

I don't think blocking tk-domains is a good idea, if they are not massively abused: It is frustrating for people, who register their first domain and want to try matrix to get blocked.

@scottwallacesh
Copy link

I just blocked matrix.calamari.space using PiHole.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants