• Warning: recurring flood targeting open NNTP and Mail-to-News services

    From Gab Virebent@n2usenet@virebent.invalid to news.admin.peering,news.software.readers,alt.fee.newsservers on Tue Sep 15 22:52:59 2026
    From Newsgroup: news.admin.peering

    A recurring flood is currently targeting /alt.privacy.anon-server/ and
    appears to be exploiting open or unauthenticated Mail-to-News and NNTP injection paths.

    The campaign initially used PGP-armored messages through a local
    Mail-to-News gateway. After that pattern was filtered, it continued with cleartext messages. It later moved to an external Mail-to-News gateway
    and reached other servers through normal NNTP transit.

    Operators of open NNTP and Mail-to-News services should consider:

    - rate limits per account, injection path and target group;
    - strict daily limits for anonymous gateways;
    - Cleanfeed flood_groups with PHR enabled;
    - phr_aggressive when no useful NNTP-Posting-Host is available;
    - PHN limits for repeated posting-host activity;
    - applying Path rules through bad_paths, not bad_hosts, when the
    relevant evidence is a Path component;
    - retaining narrow campaign signatures only as secondary, temporary
    protection;
    - sharing timestamps, Message-IDs and complete Paths with the relevant
    gateway operators.

    Gab Virebent aka Gabx
    ---
    https://news.tcpreset.net

    --- Digital Signature --- Z6HuD2rnTwU7/+5Mf7SF1Ac7Jrd2fzXnT2bNqDToFALeShHCHISlAly8De8AySC1LWi0JDe6ctpL3actza9HBQ==

    --- Synchronet 3.22a-Linux NewsLink 1.2