Skip to content

Mastodon can be used as a DDOS tool #4486

@valentin2105

Description

@valentin2105

Hi !

Today I found this tweet : https://twitter.com/mattiasgeniar/status/892446659245993984

I tried to post a link on my instance, Mastodon.cloud, and follow the link's web server logs ->

400 instant requests.

Imagine I flood 10 link, I think that go to generate more than 4k requests..
It's not great for link's web server..

Any idea how to mitigate this on futur releases ?
Why Mastodon need to crawl the link ?

Thanks


  • I searched or browsed the repo’s other issues to ensure this is not a duplicate.
  • This bug happens on a tagged release and not on master (If you're a user, don't worry about this).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions