There have been multiple accounts created with the sole purpose of posting advertisement posts or replies containing unsolicited advertising.

Accounts which solely post advertisements, or persistently post them may be terminated.

Lots of dead Lemmy/Kbin domains have CNAME records pointing to the same domain parking company

publication croisée depuis : lemmy.pierre-couy.fr/post/584644

While monitoring my Pi-Hole logs today, I noticed a bunch of queries for XXXXXX.bodis.com, where XXXXXX are numbers. I saw a few variations for the numbers, each one being queried several times.

Digging further, I found out these queries were caused by CNAME records on domains that look like they used to point to Lemmy/Kbin instances.

From what I understand, domain owners can register a CNAME record to XXXXXX.bodis.com and earn some money from the traffic it receives. I guess that each number variation is a domain owner ID in Bodis’ database. I saw between 5 to 10 different number variations, each one being pointed to by a bunch of old Lemmy domains.

This probably means that among actors who snatch expired domains, several of them have taken a specific interest with expired domains of old Lemmy instances. Another hypothesis is that there were a lot of domains registered for hosting Lemmy during the Reddit API debacle (about 1 year ago), which started expiring recently.

Are there any other instance admins who noticed the same thing ? Is any of my two hypothesis more plausible than the other ? Should we worry about this trend ?

Anyway, I hope this at least serves as a reminder to not let our domains expire ;)

Zagorath ,
@Zagorath@aussie.zone avatar

Out of interest, is pathfinder.social among those snatched up by these?

pcouy OP ,

It does not seem to be the case. Was it the full domain for this instance ?

Ghoelian ,

According to this service, that domain never had any subdomains, so looks like there’s just nothing there at the moment.

Not sure how reliable it is, but it did correctly identify all of my own subdomains for a website that no one ever goes to.

pcouy OP ,

These services usually use either or both of passive DNS replication (running public recursive DNS resolvers and logging lookup that returns a record) and certificate transparency logs (where certificate authorities publish the domain names for which they issue certificates). A lot of my subdomains are missing from these services

Zagorath ,
@Zagorath@aussie.zone avatar

Yes, that’s the full domain. It used to host communities such as !pf2general. Unfortunately it’s been dead for 9–10 months now.

pcouy OP ,

The fact that it has not been bought as soon as the domain expired makes me believe this instance went down before the trend started

Zagorath ,
@Zagorath@aussie.zone avatar

I’m actually not really clear on what the status of that instance is. Like, for me, when I browse to pathfinder.social, I actually see what looks like an empty Lemmy instance running 0.18.2. Some communities show the same for me, while others show a generic error message. So I don’t know whether it’s running in some failed state due to caching, or deregistered, or what.

pcouy OP ,

That’s really really weird, I cannot resolve the domain to an IP, even after trying a bunch of different DNS servers. If you’re on linux, can you run nslookup pathfinder.social and paste the output here ?

Zagorath ,
@Zagorath@aussie.zone avatar

If you’re on linux

I’m not, but I do have WSL installed. It returned “Can’t find pathfinder.social: No answer”

Out of interest, I tried the same command in Microsoft PowerShell, I get:


<span style="color:#323232;">Server:  dns9.quad9.net
</span><span style="color:#323232;">Address:  9.9.9.9
</span><span style="color:#323232;">
</span><span style="color:#323232;">Name:    pathfinder.social
</span>

That’s the full output. No actual list of returned addresses.

I’m guessing my system just has pathfinder.social cached.

pcouy OP ,

Yeah, this probably has to do with the cache. You can try opening dev tools (F12 in most browsers), go to the network tab, and browse to pathfinder.social. You should see all requests going out, including “fake requests” to content that you already have locally cached

Zagorath ,
@Zagorath@aussie.zone avatar

Oh neat, I’d never thought of that before. Woulda been handy back last time I was working on a PWA!

200 OK (from service worker)

So yeah, getting it from the cache.

qaz ,

I feel like this could be abused by a bad actor by recreating instances in several ways:

  1. Use the “dead” accounts that are still mods on communities on other instances.
  2. Sneakily monitor user behavior (like votes etc.) without looking out of place.
  3. Impersonate users.

I feel like it would be a good idea to start a list of the domains of dead instances and add them to a blocklist until the original people start using them again.

delirious_owl ,
@delirious_owl@discuss.online avatar

Thanks for sharing your research

  • All
  • Subscribed
  • Moderated
  • Favorites
  • [email protected]
  • random
  • lifeLocal
  • goranko
  • All magazines