toot.community Support

664 Followers
3 Following
225 Posts

Welcome to toot.community Support! πŸ“£

We're your friendly guides in this vibrant Mastodon hub, based in the Netherlands.

Our goal: help you navigate, solve issues, and enrich your online experience. Embracing our motto, "Be excellent to each other!", we foster a community of respect and open dialogue. Need help or have queries? We’re just a Toot away!

Together, let's create a digital neighbourhood to be proud of.

Ko-Fihttps://ko-fi.com/tootcommunity
Patreonhttps://www.patreon.com/tootcommunity
Information Hubhttps://hub.toot.community
πŸ’° Andy has just made a donation of $30.00 on Ko-Fi!
πŸ’° KevM has just joined the ranks of recurring contributors with $4.00/month on Ko-Fi!
πŸ’° Ian has just made a donation of $24.00 on Ko-Fi!
πŸ’° Steve has just made a donation of $20.00 on Ko-Fi!
πŸ’° joe jenett has just made a donation of $25.00 on Ko-Fi!
πŸ’° Dulce Maria has just joined the ranks of recurring contributors with $2.00/month on Ko-Fi!

Hetzner is raising prices for cloud & servers from 1 Apr 2026 as hardware & infrastructure costs rise, affecting existing and new contracts.

If you value this instance and want to help keep it running smoothly, please consider supporting with a one-off or recurring donation:

πŸ‘‰ https://ko-fi.com/tootcommunity
πŸ‘‰ https://patreon.com/tootcommunity

Monthly support helps with long-term stability so we can keep building and maintaining this server. Thanks πŸ™

#tootcommunity

Support toot.community

Support toot.community

Ko-fi

RE: https://toot.community/@jorijn/116005533731877540

We've been under attack for about 12 hours now. Mitigative steps were taken early this morning, but it takes a while for all the IPs to be captured and banned. You'll notice intermittent slowness. We're sorry for any inconvinience.

Was greeted this morning by monitoring notifying me of crashing web containers throughout the night.

Root cause: distributed /media_proxy flood where clients request the entire srcset attribute as a URL (%20 + ,%20https:/.../small%20...w). At peak: 23,298 unique IPs per 5 min + lots of 499/503.

Mitigated via CrowdSec trigger on Traefik logs (path-based): https://github.com/toot-community/platform/commit/183ddfff3b70c8bf4b168cda52f84e6e3bf942de

This detection logic should apply to any WAF, though.

FYI #MastoAdmin

crowdsec: detect srcset-style media_proxy abuse Β· toot-community/platform@183ddff

Platform code for the toot.community Mastodon instance - crowdsec: detect srcset-style media_proxy abuse Β· toot-community/platform@183ddff

GitHub