The spam campaign attacking Writefreely instances is out of control. Can you contact the admins you know?
nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqg8nzq79lxtdky004lkkzxdsny8ec49z5mzqv0jzwa679ted8nzwq340nql (nprofile…0nql)
Yesterday I received this message from my friend nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq7yr2jr0mtzvamucdw93u7s5lk6jznq84vh67dqsd0znjce9223wsyzyzvs (nprofile…yzvs):
Are you the one running the "writefreely blogs" bot, aka writefreely@poliverso.org? Because there are tons of English accounts full of links that post nonstop.
And indeed, that account republishing posts from some Italian instances had a staggering amount of spam.
This is due to a very serious vulnerability that hasn't yet been patched by the developers, but which has (obviously) started to be exploited on a large scale.
I've notified all the Italian administrators of nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq7aejn8hcs5smqkpwemcdz6gdvsqfr4lqz3y3ycz8pvwl28aqklvq0hn7l8 (nprofile…n7l8) instances, but I'm having some difficulty contacting the foreign ones.
These are the ones with the most users:
https://write.otter.homes/read
https://infosec.press/read
https://blog.liberta.vip/read
https://write.tedomum.net/read
https://val-vgms.gay/read
https://bolha.blog/read
But there are many others.Is there anyone among you who can try this or at least spread the word?Note: As I mentioned, the vulnerability has been known for a long time and is currently being exploited on a large scale.
https://github.com/writefreely/writefreely/issues/1649