home.social

#iocaine — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iocaine, aggregated by home.social.

fetched live
  1. oh lol, those are the iocaine URLs. Some crawler started getting thru iocaine, but still requesting its URLs.

    Maybe I can set something up to auto-ban IPs that fetch these? nginx stuff is way past me, but good chance to learn I guess.

    Also would be nice to ratelimit #iocaine, as it's exhausting nginx's resources by serving so much poison. Seems to be unsupported (for now) though without affecting Forgejo itself: git.madhouse-project.org/iocai

  2. oh lol, those are the iocaine URLs. Some crawler started getting thru iocaine, but still requesting its URLs.

    Maybe I can set something up to auto-ban IPs that fetch these? nginx stuff is way past me, but good chance to learn I guess.

    Also would be nice to ratelimit #iocaine, as it's exhausting nginx's resources by serving so much poison. Seems to be unsupported (for now) though without affecting Forgejo itself: git.madhouse-project.org/iocai

  3. oh lol, those are the iocaine URLs. Some crawler started getting thru iocaine, but still requesting its URLs.

    Maybe I can set something up to auto-ban IPs that fetch these? nginx stuff is way past me, but good chance to learn I guess.

    Also would be nice to ratelimit #iocaine, as it's exhausting nginx's resources by serving so much poison. Seems to be unsupported (for now) though without affecting Forgejo itself: git.madhouse-project.org/iocai

  4. Iocaine leads to a lot of bot traffic to the maze. Some crawlers also seems to get through Iocaine and then crawl Codeberg or other Iocaine-protected Forgejo instances. For this reason, I don't want to deploy Iocaine in front of Codberg.

    My proposed solution would be making Codberg only accessible to logged-in users and having an unauthenticated landing/explore site.

    That site would allow you to

    • browse the list of repos
    • read READMEs-see project details (contributors, issue stats, licenses, activity)
    • read project's documentation

    But commit history, file browsing and (for now also issues) wouldn't be accessible without logging in.

    What do you think about this?

    #codberg #cod #forgejo #iocaine

  5. Iocaine leads to a lot of bot traffic to the maze. Some crawlers also seems to get through Iocaine and then crawl Codeberg or other Iocaine-protected Forgejo instances. For this reason, I don't want to deploy Iocaine in front of Codberg.

    My proposed solution would be making Codberg only accessible to logged-in users and having an unauthenticated landing/explore site.

    That site would allow you to

    • browse the list of repos
    • read READMEs-see project details (contributors, issue stats, licenses, activity)
    • read project's documentation

    But commit history, file browsing and (for now also issues) wouldn't be accessible without logging in.

    What do you think about this?

    #codberg #cod #forgejo #iocaine

  6. Iocaine leads to a lot of bot traffic to the maze. Some crawlers also seems to get through Iocaine and then crawl Codeberg or other Iocaine-protected Forgejo instances. For this reason, I don't want to deploy Iocaine in front of Codberg.

    My proposed solution would be making Codberg only accessible to logged-in users and having an unauthenticated landing/explore site.

    That site would allow you to

    • browse the list of repos
    • read READMEs-see project details (contributors, issue stats, licenses, activity)
    • read project's documentation

    But commit history, file browsing and (for now also issues) wouldn't be accessible without logging in.

    What do you think about this?

    #codberg #cod #forgejo #iocaine

  7. The AI DDoS is now targeting my Forgejo server with... a very strange attack. These are all getting past #iocaine. The ASNs appear to be quite diverse. What's going on?

  8. The AI DDoS is now targeting my Forgejo server with... a very strange attack. These are all getting past #iocaine. The ASNs appear to be quite diverse. What's going on?

  9. The AI DDoS is now targeting my Forgejo server with... a very strange attack. These are all getting past #iocaine. The ASNs appear to be quite diverse. What's going on?

  10. Could we as a community move from being defensive into #offensive re internet #scraping?
    Sth more offensive beside
    - poisoning their datasets using #nepenthes or #iocaine
    - proof-of-work #anubis
    - jpeg / zip bombs en.wikipedia.org/wiki/Zip_bomb

    Is anyone working on some offensive strategies?

  11. Could we as a community move from being defensive into #offensive re internet #scraping?
    Sth more offensive beside
    - poisoning their datasets using #nepenthes or #iocaine
    - proof-of-work #anubis
    - jpeg / zip bombs en.wikipedia.org/wiki/Zip_bomb

    Is anyone working on some offensive strategies?

  12. Could we as a community move from being defensive into #offensive re internet #scraping?
    Sth more offensive beside
    - poisoning their datasets using #nepenthes or #iocaine
    - proof-of-work #anubis
    - jpeg / zip bombs en.wikipedia.org/wiki/Zip_bomb

    Is anyone working on some offensive strategies?

  13. the blog is still being hogged by the bots, I had to put a hard limit of 1 request/second + some room for short bursts (like when your browser loads a webpage).

    last night the noise of the fan in the mini PC could be heard from my room (few meters away, behind a thin door), the machine running the proxy in front of the blog is a tiny x86_64 machine around 7 years old and it was getting really hot.

    #selfHosting #iocaine

  14. the blog is still being hogged by the bots, I had to put a hard limit of 1 request/second + some room for short bursts (like when your browser loads a webpage).

    last night the noise of the fan in the mini PC could be heard from my room (few meters away, behind a thin door), the machine running the proxy in front of the blog is a tiny x86_64 machine around 7 years old and it was getting really hot.

    #selfHosting #iocaine

  15. the blog is still being hogged by the bots, I had to put a hard limit of 1 request/second + some room for short bursts (like when your browser loads a webpage).

    last night the noise of the fan in the mini PC could be heard from my room (few meters away, behind a thin door), the machine running the proxy in front of the blog is a tiny x86_64 machine around 7 years old and it was getting really hot.

    #selfHosting #iocaine

  16. I am listening to this podcast. There are some clever concepts included with Iocaine.

    Open Source Security: #Iocaine poisons bots with Gergely Nagy

    Episode webpage: opensourcesecuritypodcast.libs

    Media file: traffic.libsyn.com/secure/open

  17. I am listening to this podcast. There are some clever concepts included with Iocaine.

    Open Source Security: #Iocaine poisons bots with Gergely Nagy

    Episode webpage: opensourcesecuritypodcast.libs

    Media file: traffic.libsyn.com/secure/open

  18. I am listening to this podcast. There are some clever concepts included with Iocaine.

    Open Source Security: #Iocaine poisons bots with Gergely Nagy

    Episode webpage: opensourcesecuritypodcast.libs

    Media file: traffic.libsyn.com/secure/open

  19. Well, I set up #iocaine on my Git forge yesterday (with Nam-Shub of Enki), and figured out how to get stats from it. It's served half a gigabyte of poison in just half a day, with 250k requests from anthropic.

    However, a friend was successful in asking chat chippitty what's on the website, so I guess something somewhere is misconfigured.

    However, git.allpurposem.at is no longer serving hundreds of bots per minute, just a few now :)

  20. Well, I set up #iocaine on my Git forge yesterday (with Nam-Shub of Enki), and figured out how to get stats from it. It's served half a gigabyte of poison in just half a day, with 250k requests from anthropic.

    However, a friend was successful in asking chat chippitty what's on the website, so I guess something somewhere is misconfigured.

    However, git.allpurposem.at is no longer serving hundreds of bots per minute, just a few now :)

  21. Well, I set up #iocaine on my Git forge yesterday (with Nam-Shub of Enki), and figured out how to get stats from it. It's served half a gigabyte of poison in just half a day, with 250k requests from anthropic.

    However, a friend was successful in asking chat chippitty what's on the website, so I guess something somewhere is misconfigured.

    However, git.allpurposem.at is no longer serving hundreds of bots per minute, just a few now :)

  22. I may have stumbled into an AI blog post explaining how to get started with iocaine.
    It's the very first time I see useful slop, despite the galactic irony.

    (will not share the link, don't bother asking)

    #noAI #iocaine

  23. I may have stumbled into an AI blog post explaining how to get started with iocaine.
    It's the very first time I see useful slop, despite the galactic irony.

    (will not share the link, don't bother asking)

    #noAI #iocaine

  24. I may have stumbled into an AI blog post explaining how to get started with iocaine.
    It's the very first time I see useful slop, despite the galactic irony.

    (will not share the link, don't bother asking)

    #noAI #iocaine

  25. iocaine configured!
    we have:
    netbsd - caddy - iocaine

    if you check blog.masto.bike, you should see a regular site.
    if you install a User-Agent spoofer'[1] and use something like "Perplexity" or "ClaudeBot" you will see absolute gibberish and multi-lingual nonsense.
    It is amazing.

    [1]webextension.org/listing/usera

    #netBSD #iocaine #resistAI

  26. iocaine configured!
    we have:
    netbsd - caddy - iocaine

    if you check blog.masto.bike, you should see a regular site.
    if you install a User-Agent spoofer'[1] and use something like "Perplexity" or "ClaudeBot" you will see absolute gibberish and multi-lingual nonsense.
    It is amazing.

    [1]webextension.org/listing/usera

    #netBSD #iocaine #resistAI

  27. iocaine configured!
    we have:
    netbsd - caddy - iocaine

    if you check blog.masto.bike, you should see a regular site.
    if you install a User-Agent spoofer'[1] and use something like "Perplexity" or "ClaudeBot" you will see absolute gibberish and multi-lingual nonsense.
    It is amazing.

    [1]webextension.org/listing/usera

    #netBSD #iocaine #resistAI

  28. @gairdeachas A few months ago I was feeding these crawlers with #iocaine. They have been very greedy and aggressive. I hope I polluted their databases enough to have an impact.

  29. @gairdeachas A few months ago I was feeding these crawlers with #iocaine. They have been very greedy and aggressive. I hope I polluted their databases enough to have an impact.

  30. @gairdeachas A few months ago I was feeding these crawlers with #iocaine. They have been very greedy and aggressive. I hope I polluted their databases enough to have an impact.

  31. EDIT : Résolu.
    le problème venait que la partie POST n'est pas prise en compte dans l'upstream qui redirige vers iocaine et le renvoi d'une erreur 500 est "normal".
    Je l'ai bypass en ajoutant le code 500 aux error codes qui permettent d'accéder au fallback

    dites les gensss, j'ai un problème avec
    #iocaine que je viens de mettre en place.

    Ca marche nickel sur les pages, par contre, la moindre requête POST (par exemple : login sur gitea) renvoie une erreur 500 du reverse (nginx).

    J'ai toujours le même message : invalid URL prefix in ""


    J'ai suivi la méthode d'intégration là :

    iocaine.madhouse-project.org/documentation/3/reverse-proxies/nginx/#integrating-iocaine


    Du monde qui saurait m'aider à comprendre ce qui se passe ?

  32. EDIT : Résolu.
    le problème venait que la partie POST n'est pas prise en compte dans l'upstream qui redirige vers iocaine et le renvoi d'une erreur 500 est "normal".
    Je l'ai bypass en ajoutant le code 500 aux error codes qui permettent d'accéder au fallback

    dites les gensss, j'ai un problème avec
    #iocaine que je viens de mettre en place.

    Ca marche nickel sur les pages, par contre, la moindre requête POST (par exemple : login sur gitea) renvoie une erreur 500 du reverse (nginx).

    J'ai toujours le même message : invalid URL prefix in ""


    J'ai suivi la méthode d'intégration là :

    iocaine.madhouse-project.org/documentation/3/reverse-proxies/nginx/#integrating-iocaine


    Du monde qui saurait m'aider à comprendre ce qui se passe ?

  33. EDIT : Résolu.
    le problème venait que la partie POST n'est pas prise en compte dans l'upstream qui redirige vers iocaine et le renvoi d'une erreur 500 est "normal".
    Je l'ai bypass en ajoutant le code 500 aux error codes qui permettent d'accéder au fallback

    dites les gensss, j'ai un problème avec
    #iocaine que je viens de mettre en place.

    Ca marche nickel sur les pages, par contre, la moindre requête POST (par exemple : login sur gitea) renvoie une erreur 500 du reverse (nginx).

    J'ai toujours le même message : invalid URL prefix in ""


    J'ai suivi la méthode d'intégration là :

    iocaine.madhouse-project.org/documentation/3/reverse-proxies/nginx/#integrating-iocaine


    Du monde qui saurait m'aider à comprendre ce qui se passe ?

  34. CW: mouse makes rocks do math (forge & CI & NetBSD edition)

    @algernon given that #pkgsrc appears to be the (only?) packaging system with an explicit policy against committing LLM generated code to the packaging repository (it can include entries for LLM generated packages, but the config and build patches in pkgsrc cannot include LLM generated code), it could be considered an irony crime that someone hasn't already committed a pkgsrc entry for #iocaine :-p

  35. CW: mouse makes rocks do math (forge & CI & NetBSD edition)

    @algernon given that #pkgsrc appears to be the (only?) packaging system with an explicit policy against committing LLM generated code to the packaging repository (it can include entries for LLM generated packages, but the config and build patches in pkgsrc cannot include LLM generated code), it could be considered an irony crime that someone hasn't already committed a pkgsrc entry for #iocaine :-p

  36. @heiseonline Gut, dass sie sich die Mühe machen. #iocaine ist gegen Bots viel effizienter.

    #fuckai

  37. @heiseonline Gut, dass sie sich die Mühe machen. #iocaine ist gegen Bots viel effizienter.

    #fuckai

  38. #iocaine is just not happy, but not giving me any errors. Been following the nixos install instructions and I'm not understanding what is wrong.
    Systemd service goes straight to failed.
    journalctl doesn't show anything interesting
    Running manually (with the exec command from the systemd config) returns immediately with no output

  39. Wir alle: …
    Claudebot: Schlürft sich die Inhalte vom Iocaine auf meinem Server rein.

    Noch jemand ein bisschen Text von
    blog.numerfolt.de/Linksmultipl

    Nein, das ist nicht aufrufbar, aber es enthält unter anderem Sätze wie:
    „Prejudice in favour of size was about three acres, there were several bad cases were in a hostile hot fusion establishment the excuse that.“

    Und nein, das ergibt keinen Sinn xD
    Das ist iocaine von madhouse project am Werk…
    #iocaine #selfhosted