b0nfire.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Hey Jellyfin Users & Radio Lovers.
I recently got into radio again and found out how to add live streams to Jellyfin. So I'm sharing my little radio ".strm" collection again to anyone that wants them! They might play in VLC too.
(Add a library as "mixed movies and shows")(see last photo)
Mastodon special here lol. File link is good for 7 days. Cheers! Right now I'm listening to Samewave Radio and its Goood stuff.
so the wisdom of crowds is batting 500. 2 right, 2 wrong. The answers were:
That 18GB drive was the mail serverโs only drive for like 20 years. Quantum Atlas V SCSI.
I am glad to say that I have more drives working than I have dead. 32 in the rack and 7 inside in the NAS (not counting random laptops and such)
#selfhosted #selfhosting #homelab
troduction: I'm Arber โ 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania.
For the past year I watched fail2ban block tens of thousands of attacksโฆ and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it.
RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report:
โ fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping)
โ attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR
โ one aggregated X-ARF report per responsible network per day, full timestamped evidence
โ delivery tracked end-to-end: sent / bounced / acked / human reply / takedown
Month one on my own infra: 2,847 blocked attacks โ 214 responsible networks โ 31 reports โ 4 compromised hosts confirmed offline. The per-provider spread is the interesting part โ some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next.
No hack-back โ it never sends a packet at the attacker. Only professional reports to registered abuse contacts.
Docs & architecture: https://github.com/arberormeni2022/riposte
Beta access for operators: https://buymeacoffee.com/securitysystem
Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining.
#infosec #fail2ban #selfhosted #sysadmin #abusedesktroduction: I'm Arber โ 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania.
For the past year I watched fail2ban block tens of thousands of attacksโฆ and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it.
RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report:
โ fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping)
โ attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR
โ one aggregated X-ARF report per responsible network per day, full timestamped evidence
โ delivery tracked end-to-end: sent / bounced / acked / human reply / takedown
Month one on my own infra: 2,847 blocked attacks โ 214 responsible networks โ 31 reports โ 4 compromised hosts confirmed offline. The per-provider spread is the interesting part โ some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next.
No hack-back โ it never sends a packet at the attacker. Only professional reports to registered abuse contacts.
Docs & architecture: https://github.com/arberormeni2022/riposte
Beta access for operators: https://buymeacoffee.com/securitysystem
Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining.
#infosec #fail2ban #selfhosted #sysadmin #abusedesktroduction: I'm Arber โ 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania.
For the past year I watched fail2ban block tens of thousands of attacksโฆ and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it.
RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report:
โ fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping)
โ attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR
โ one aggregated X-ARF report per responsible network per day, full timestamped evidence
โ delivery tracked end-to-end: sent / bounced / acked / human reply / takedown
Month one on my own infra: 2,847 blocked attacks โ 214 responsible networks โ 31 reports โ 4 compromised hosts confirmed offline. The per-provider spread is the interesting part โ some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next.
No hack-back โ it never sends a packet at the attacker. Only professional reports to registered abuse contacts.
Docs & architecture: https://github.com/arberormeni2022/riposte
Beta access for operators: https://buymeacoffee.com/securitysystem
Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining.
#infosec #fail2ban #selfhosted #sysadmin #abusedeskHi, #introduction: I'm Arber โ 17 years running infrastructure that can't afford to be down (ISP backbones, national broadcasters, government systems), based in Tirana, Albania.
For the past year I watched fail2ban block tens of thousands of attacksโฆ and nothing ever happened to the attacker. Almost every source is someone's hijacked VPS, and the provider never hears about it. That silence started to feel like the real vulnerability. So I built something about it.
RIPOSTE turns every firewall ban into an automated, evidence-backed abuse report:
โ fail2ban / QNAP QuFirewall push events to a local FastAPI collector (no log scraping)
โ attribution via Abusix abuse-contact DNS with RDAP fallback, cached per CIDR
โ one aggregated X-ARF report per responsible network per day, full timestamped evidence
โ delivery tracked end-to-end: sent / bounced / acked / human reply / takedown
Month one on my own infra: 2,847 blocked attacks โ 214 responsible networks โ 31 reports โ 4 compromised hosts confirmed offline. The per-provider spread is the interesting part โ some suspend within 48h, some abuse mailboxes literally hard-bounce. A public per-provider accountability dashboard is next.
No hack-back โ it never sends a packet at the attacker. Only professional reports to registered abuse contacts.
Docs & architecture: https://github.com/arberormeni2022/riposte
Beta access for operators: https://buymeacoffee.com/securitysystem
Which firewall should get an adapter next? Happy to talk WHOIS/RDAP swamp-draining.
Plainva 0.7.0 is out.
A window was never the limit โ the limit was that "the vault" was one thing.
Notes, databases, the graph, tasks, calendar and mail can each live in their own window now, and two windows can show two different vaults. One process: the central window keeps every background service and every write, so the whole sync hardening still works against exactly one writer.
Today I learned how to:
- create a partition
- assign a file system
- mount file system
- use mergerFS to merge all my media on multiple HDDs
- simplify my Jellyfin and Arr stack's volume bindings
- finally get my arr stack to automate Cpt Jack Sparrow properly from a Seerr request.
Now I have to do it on the actual server and hope there's no unexpected downtime or the fam will have my head ๐
#linux #selfhosted
Plainva 0.6.8 is out.
Notes can now say where they came from and who checked them โ following OKF 0.2. Stamped only where a machine writes: your own notes are never touched after the fact.
Two data fixes come first: connecting an account twice no longer creates a second one โ which quietly duplicated every mirrored task โ and a large attachment no longer leaves a hundred copies in the version history.
ok i just released a thing, over a year in the making ๐
cruciverb - a daily crossword server that speaks ActivityPub
yes, really. your instance federates like a mastodon server: puzzles, clues and leaderboards flow between instances, and solves are signed so they follow you around the fedi
also: you can DRAW the letters. handwriting recognition runs entirely in your browser
no accounts, no ads, no tracking, CC0
Update:
So this morning I was successfully able to jump my GTS container from my Synology NAS to a container on my main server box. It worked no problem this time, so I suspect my hypothesis about getting limited by LetsEncrypt was correct; after letting it cool down for a couple of days itโs started up no problem.
Iโm expecting a noticeable performance bump as the new hardware has a lot more torque. Performance on the NAS was fine, until it started doing disk-intensive stuff which introduced quite a bit of lag.
Update on the #GoToSocial project: it definitely seems to stall out when the disk I/O ramps up on the NAS due to a scheduled backup task. I tried relocating the GTS instance to container on a different machine, and then to a VM on a different machine but both attempts failed; something to to with LetsEncrypt. I suspect maybe I got rate-limited?
Anyway, itโs back under the NAS for now. I did some tweaking of the ย timing of the backup jobs so weโll see what happens tomorrow morning. ๐คทโโ๏ธ
RE: https://social.lol/@phillip/117061432689860232
The postmortem of the hack on my Forgejo instance is here! I had fun investigating and writing it, so I hope yโall enjoy reading about it :)
#Homelab #SelfHosted #Cybersecurity #Infosec
https://phunky.cafe/my-homelab-got-hacked/
nyan boostedWelp. My Forgejo instance got popped by CVE-2026-60004. Hooray for RCE ๐
My two screw-ups were
1. I pinned it to v13 "for stability" forever ago, then forgot about it.
2. I accidentally left sign-ups enabled.Grabbed the seemingly obfuscated payload script from the attacker's server. Looks like it hits a different IP and grabs one of three different binaries depending on the victim's CPU architecture. You best believe I'm grabbing those too
Will probably write a blog post on what I find, but I'll at least post updates here, too
Welp. My Forgejo instance got popped by CVE-2026-60004. Hooray for RCE ๐
My two screw-ups were
1. I pinned it to v13 "for stability" forever ago, then forgot about it.
2. I accidentally left sign-ups enabled.
Grabbed the seemingly obfuscated payload script from the attacker's server. Looks like it hits a different IP and grabs one of three different binaries depending on the victim's CPU architecture. You best believe I'm grabbing those too
Will probably write a blog post on what I find, but I'll at least post updates here, too
With Apple phasing out AFP in macOS 27 and Time Capsules officially reaching end-of-life, it's time to move network backups to proper SMB.
If you run a FreeBSD server, you can build a fast, rock-solid, and secure Time Machine target powered by ZFS and Samba - neatly isolated inside a FreeBSD jail using Bastille.
https://it-notes.dragas.net/2026/01/28/time-machine-freebsd-jail/
Keep your macOS backups running smoothly via SMBv3 (with full vfs_fruit support) and full dataset quota control on ZFS!
#FreeBSD #macOS #TimeMachine #ZFS #BastilleBSD #Samba #SysAdmin #Backup #OwnYourData #SelfHosted #BSD #RunBSD #OwnYourData
One beef, the lower bar stays on the screen on my phone in Firefox-based browsers and doesn't allow me to click past it to hit fullscreen. Aside from that, it's impressive that it does what it does already.
Anyway, here's the source:
https://github.com/rommapp/romm?tab=readme-ov-file#folder-structure
There's also clients and a budding community adding things constantly. Keep it in your sights.
#roms #emulation #classicgaming #retrogames #selfhosted #webapps
Plainva 0.5.1 is out.
Connecting one Microsoft account used to mean three consent screens โ files, calendar, mail โ and three refresh tokens for the same account. Not a security feature; just me building each service when I needed it. There is now one token broker per account: one sign-in, shared.
Also: repeating tasks, mail signatures, every bar in one settings area, mail on the phone.
What many people misunderstand about hosting your own content (like this social media instance) is thinking we somehow NEED a big audience or Big Tech involvement.
I'm perfectly fine if the world faded away and it was just the thousand of us here. It's like the early days of the web when we had small forums, nobody missed Reddit back then. Federation is a big plus, not a requirement.
It's the same with websites or IRC for me. I know people use Discord, but I still stick to IRC even if there are only about a hundred of us left. I know people use AI now and website visitors are dropping, but who cares? I still keep doing it for those who like to read.
I don't need the whole world involved for this to feel worthwhile. It's mine, I own it, and I host it for as long as I breathe. After that, it won't matter to me anymore, but I hope other admins keep things running the way I did.
#SelfHosted #SelfHosting #OpenSource #Fediverse #Mastodon #OpenWeb #SocialWeb
Wow. Yesterday I posted a little introduction about Solent.Social, and over the last 24 hours, you've blown me away with 50 boosts and nearly 40 reactions! Thank you all so much for the incredible support. Running a small, independent instance can feel daunting, but your reactions have completely validated that this project is worth the time and effort. Incredibly grateful to the Fediverse community today! Thank you all for the support :3
โ โ
โ
RE: https://solent.social/notes/anmlh8frlte5048g
jonny (nonvenomous) boosted๐ Solent.social is growing! ๐
We are a self-hosted, anti-AI, pro-privacy social space dedicated to the Solent & South Coast (UK) area, full of gamers, video creators, and tech nerds.To keep our community safe and high-quality, we are Invite-Only. However, our members get fresh invite codes every 24 hours! Allowing them to invite friends and family regularly.
If you live in the local area (Hampshire, Isle of Wight, etc.) or fit our vibe and want a cozy home feed, reply to this post or DM me for an invite code.
๐ฅ(Boosts appreciated to help your local neighbors find us!)
#Solent #UKFedi #SelfHosted #Gaming #SouthCoast #iow #IsleOfWight #Portsmouth #Winchester #Southampton #NewForest #AntiAI #VideoCreation
๐ Solent.social is growing! ๐ To keep our community safe and high-quality, we are Invite-Only. However, our members get fresh invite codes every 24 hours! Allowing them to invite friends and family regularly. If you live in the local area (Hampshire, Isle of Wight, etc.) or fit our vibe and want a cozy home feed, reply to this post or DM me for an invite code. (Boosts appreciated to help your local neighbors find us!)
We are a self-hosted, anti-AI, pro-privacy social space dedicated to the Solent & South Coast (UK) area, full of gamers, video creators, and tech nerds.
Just showing some love for the Feishin music player in Linux. I'm using it for my Jellyfin library, and it's so much better than the previous player I was using, Finamp.
Very nice looking, intuitive, and even has a built in web radio player. Ooh la la!
A cellular travel router is a wonderful thing.
#Tailscale and all the other bells and whistles.
On vacation, at home, and at work.