3 ms·
hey, i'm the author of the article really... surprised it got submitted here incidentally i'm running pleroma, not mastodon. minor detail but you know
by koroshitekure 7y ago
hey, i'm the author of the article
really... surprised it got submitted here
incidentally i'm running pleroma, not mastodon. minor detail but you know
- iampims 7y agoTo avoid leaking IPs, you can use cloudflared tunnel. It might get pricy if you move a lot of bytes, but it’ll isolate you from IP leaking issues.
- koroshitekure 7y agooh, i found out where the leak was it's right at the end of the article - the attacker was abusing the "create a preview card of any posted URL" feature - he'd post a link, wait for pleroma to go and grab the url to preview it, then narrow down which one was mine based on user agent i added an upstream proxy and anonymised the user agent, so even if he were to do that, the most he'd find was my proxy box
- chvanikoff 7y agoThat might be what you are talking about, but just to confirm: Pleroma has an ability to proxy outbound requests via `pleroma.http` config out of the box
- koroshitekure 7y agoyeah that's what I'm using I also pull-requested a user agent anonymisation setting (pleroma.http.user_agent) to make this better
- TrueDuality 7y agoDid you consider using Tor to make those kind of outbound requests? I've done that in that past for a similar situation to avoid leaking IPs, there is a latency overhead but it solved my issue pretty quickly. There were some sites that were blocking Tor exits but the vast majority were successful (enough that when the feature failed it didn't really matter).
- dredmorbius 7y agoI'm quite active on Mastodon and HN, thought this might be of interest. Would you prefer the title were modified? The mods can do that. I thought that specifying what the DDoS mitigation was applied to would be helpful, though my presumption of Mastodon was in error, apologies.
- koroshitekure 7y agoI'm not too bothered about correcting it, just thought it good to note
- netsectoday 7y agoI block all Tor traffic with iptables and ipset - which allows O(log n) lookup time for each request when checking it against the Tor list. I wonder if this would have been your end-all solution. http://ipset.netfilter.org/ipset.man.html http://ipset.netfilter.org/ipset.man.html