Bit Blot Forum

Bit Blot => Off-Topic => Topic started by: Xiagan on December 13, 2010, 01:13:07 pm

Title: Spam
Post by: Xiagan on December 13, 2010, 01:13:07 pm
You may have noticed the spam bots got out of control. I removed over 30 spam posts 4 hours ago and did another 40 in the last 4 hours.
Since I can't be here 24/7, it's only normal that you may find various amounts of spam while visiting.

I hope a software update or something similar will happen soon - until then thank you for your understanding.
Title: Re: Spam
Post by: Xiagan on December 15, 2010, 10:50:18 am
There are 89 spam posts at the moment and I don't have the time to delete them - to be honest, I don't have the motivation either, because without a forum update it will look the same tomorrow and the day after and ... well, I'm not Sisyphus.

So please understand that I won't delete spam posts anymore without seeing some activity from our admins.
Title: Re: Spam
Post by: Alphasoldier on December 15, 2010, 05:53:08 pm
More than understandable Xiagan.
Not to hammer onto Alec, but I don't see why he can't do it. Though besides that, I'm not even close to fathoming why Derek hasn't already put in some kind of spam bot measurement.
Title: Re: Spam
Post by: Xiagan on December 15, 2010, 09:08:10 pm
Alec is deleting as much as I am, it was still not enough.

I talked with both and apparently the setting was set to 'immediate registration' which Derek changed, so it's supposed to be better now! :)
The spam bots who are still posting had already registered, so a ban should solve that problem too, so I'm looking quite forward to a new mostly spam free area!
Title: Re: Spam
Post by: Alec on December 15, 2010, 09:43:15 pm
I was deleting oodles of spam like twice a week.

But yeah, things should be less crazy now. I banned those 3 accounts you linked me to, Xia. :)
Title: Re: Spam
Post by: Aristobulus on December 16, 2010, 11:22:31 am
Man this is a very nice thing to hear, those spam bots were really depressing.
Title: Re: Spam
Post by: GMMan on December 16, 2010, 04:49:21 pm
How about a question on the registration forum that Aquaria players should know the answer to? I first saw it on the BZFlag forums. It should be something extremely simple, though spambots wouldn't be able to answer without their users to find out the answer first.
Title: Re: Spam
Post by: Alphasoldier on December 16, 2010, 06:40:14 pm
From what I gather only Derek can do it, be it permissions, owner rights, knowledge (which I doubt) or some other weird things. I appreciate the banning's, but still wonder why you can't put up some simple spambot protection with the registration.
Title: Re: Spam
Post by: Zoko on December 22, 2010, 08:28:03 am
Unfortunately from the looks of things the setting change didnt help matters much.
Title: Re: Spam
Post by: Xiagan on December 22, 2010, 10:50:43 am
Unfortunately from the looks of things the setting change didnt help matters much.

I checked them and we are mostly dealing with spam bots who registered before the changes and are posting again.
It may need a time to ban them all, but we are on a good way I think.
Title: Re: Spam
Post by: Derek on December 28, 2010, 03:02:43 am
Hey, guys, sorry about the spam!

I upgraded our forums to the latest version, which should help quite a bit.

Also, admins - if you delete a spam account you have the option to delete all of their posts with it. FYI.
Title: Re: Spam
Post by: Aristobulus on December 28, 2010, 07:46:27 am
Sounds like progress is finally being made on this, really glad to hear it. Thanks for the effort guys.
Title: Re: Spam
Post by: Alphasoldier on December 28, 2010, 11:15:44 am
Maybe it's an idea to bring around another admin, if even this post is being littered. xD

And thanks Derek!
Title: Re: Spam
Post by: Align on December 29, 2010, 12:19:05 am
Yaaaaay!
Title: Re: Spam
Post by: Aristobulus on January 02, 2011, 12:47:07 am
Xiagan's gonna have a stroke when he checks this place after taking a break for the holidays :V
Title: Re: Spam
Post by: Derek on January 03, 2011, 01:27:31 am
"Spam... spam never changes..."

I guess installing the new version of SMF reset the visual captcha to "Medium" instead of "High". Fixed. I hope that's the reason why there was a huge deluge the past couple of days.

I'll make Xiagan an admin, too, so he can help delete spam accounts.
Title: Re: Spam
Post by: Xiagan on January 03, 2011, 09:38:04 am
Thanks Derek! I hope your measures help and there isn't much need for deleting spam accounts, but if necessary, this will make my work more easy. :) There must be a new trick with smf the spammers found. The amount in other smf forums I attend has increased too...
Title: Re: Spam
Post by: Alphasoldier on January 03, 2011, 06:16:50 pm
Actually, I believe that SOME spammers nowadays are just humans who are being paid to do shit like that. Easy cash n stuff.

Oh and once again thanks Derek. <3
Title: Re: Spam
Post by: Aristobulus on January 03, 2011, 06:21:55 pm
Actually, I believe that SOME spammers nowadays are just humans who are being paid to do shit like that. Easy cash n stuff.

Oh and once again thanks Derek. <3

If that was the case wouldn't they make less ridiculous, mechanical looking posts? Some of the shit that gets posted looks like it was never once actually written by a human with any sort of understanding of the english language and is just random words and links thrown together.
Title: Re: Spam
Post by: Alphasoldier on January 03, 2011, 09:20:17 pm
Some spamposts in this forum actually made me think a real person made it, seeing it connected perfectly on the topic, but their signatures still had links in them.
Oh and their reactions were general, like they don't know what the forum was about but they did read the post before that.
Title: Re: Spam
Post by: Xiagan on January 03, 2011, 09:26:23 pm
Some spamposts in this forum actually made me think a real person made it, seeing it connected perfectly on the topic, but their signatures still had links in them.
I think some of them just copy parts of the first (or just earlier) posts. This way it looks very on topic.
Title: Re: Spam
Post by: vibra6 on January 11, 2011, 02:22:30 am
Yeah.. what's the deal with that... Make me a mod. i'll help remove them!
Title: Re: Spam
Post by: Alphasoldier on January 11, 2011, 06:23:47 pm
See what I was talking about Xia? =p
Title: Re: Spam
Post by: Xiagan on January 11, 2011, 08:00:10 pm
But his links don't make sense.. :P sigh...
Title: Re: Spam
Post by: Liarra Sniffles on January 13, 2011, 02:22:46 am
what you guys need is one of thos anti spam bot things that detect
 advertising and reports it to you,
 then you can just mark the ones that are not spam and it will auto ban the rest.
i have no idea where to get one, but one of my old blogs had one (google it?).  ^-^
Title: Re: Spam
Post by: GMMan on January 13, 2011, 04:45:30 pm
what you guys need is one of thos anti spam bot things that detect
 advertising and reports it to you,
 then you can just mark the ones that are not spam and it will auto ban the rest.
i have no idea where to get one, but one of my old blogs had one (google it?).  ^-^

I consider that too much work. There are more legitimate new posts these few days than spam (or it's just Xiagan doing a very good job).
Title: Re: Spam
Post by: Alphasoldier on January 13, 2011, 06:04:05 pm
Yeah, Xia has been fairly busy. I noticed a few spam posts every now and then from (I hope) old accounts, and I bet I don't even see everything.
Title: Re: Spam
Post by: GMMan on January 14, 2011, 04:42:07 pm
I find it somewhat useful to look at the Users Online section for spammers. A simple check of their profile usually reveal who they are. And no, the anti-spam mechanisms are still not working. All of the spam members I checked from the Users Online page was registered today.
Title: Re: Spam
Post by: False.Genesis on February 19, 2011, 01:34:03 am
Admins! Don't give this forum up please! (And spare poor Xiagan the work)

Talked with Xiagan yesterday on IRC about the spams, and here is an SMF addon that may help (not older then 2 weeks, and installing it on my test forum was a breeze):
http://custom.simplemachines.org/mods/index.php?mod=2932

Fairly new way to make a captcha, but if it works.. and it does :)
I have set up a test forum (http://fg.kicks-ass.org/f/index.php?action=register) that is already using appropriate captcha images ^-^

PM'd Xiagan some more details, and now i hope he can get that addon in, or poke Derek to do something.

Btw, there is SMF 1.1.13 out with some bug fixes, but nothing major that spambots could exploit from what i have seen.

I estimate the majority of the spambots that register here try to improve their google ranks by providing links to websites they want to promote. We can be lucky only a small fraction of these bots actually starts posting, as them collectively waking up would be a disaster. There are bots that registered months ago and still check the forum, although they have not posted a single thing.
Do you guys think its possible to clean the user database from most of these bots automatically? Most of the names are made following a simple pattern, that is [a-zA-z]+[0-9]+[a-zA-Z]*, and many provide the same link twice in their signature... helps identifying them automatically.

Lastly, if that helps anyone i set up a little trap for those nasty email harvesters here (http://fg.kicks-ass.org/userlist), in case some are here. Hopefully these stupid bots pick up the URL and spread it, as it is also in my sig.
(Someone has to do something, right?)

Oh, and this: http://en.spambot.pl/ <-- i lold. Shame on them.


EDIT:
From their site:
Quote
Protection against the program
The protection of one’s own websites against the program is included. You simply need to upload to your website server a file entitled ‘spambot.txt’ with the content ‘spambot.pl’. If the program tries to spam this page, it will be announced that spamming can’t be done because there is the file ‘spambot.txt’ on the server. Before spamming, the program always checks if there is such a file on the server.

Worth a try imho :P


EDIT2 (half a day layer):
Geez, more spam posts... If you let me, i'd help deleting stupid bots and cleaning up the forum  :(

EDIT3: Another mod that looks promising, just updated today, now works with SMF 1.1.x: http://custom.simplemachines.org/mods/index.php?mod=2502

EDIT4: The images i used for notCaptcha can be found here (http://fg.kicks-ass.org/f/mystuff/)
Title: Re: Spam
Post by: Alec on February 20, 2011, 10:23:12 pm
Sounds cool, I'd add it but I don't think I have the access to do that.

AFAIK Derek is the only one with the web login craziness?

Maybe I should see if I can get him to hook me up with the info required. I might be able to do that at GDC. (sometimes it's hard to reach him by email cause he's doing crazy Spelunky stuff)
Title: Re: Spam
Post by: Inyssius on March 26, 2011, 10:39:00 am
My word, what an interesting technique this HJJ bot has. Ten threads in one forum, none in any of the others--each post apparently assembled from a strange syntactical mishmash of somewhere between two and ten different news articles, each studded with dozens of surreally-titled links and then followed by a bunch of straight-up URLs at the bottom of each post just for good measure.

How odd.
Title: Re: Spam
Post by: Alphasoldier on March 26, 2011, 11:24:01 am
I don't even click posts that have 0 replies anymore.
Title: Re: Spam
Post by: Inyssius on March 28, 2011, 05:35:39 am
Atoneanies! Debt Adcarnality! Cradapt! Greaanalysis! Unseconvalescent De! Administer artificial armamentariums! Acquaint burningly application the coffers and get abolishment! Aboriginal footfall.


... Brokacy!


(Spammer Tiggs has an amusing technique as well, it seems.)
Title: Re: Spam
Post by: False.Genesis on March 29, 2011, 02:04:58 am
What about we just spam Dereks email until he installs a spam filter or a useful captcha system?  :P
... AND also gives Alec access to these things too.

Sounds cool, I'd add it but I don't think I have the access to do that.

AFAIK Derek is the only one with the web login craziness?

Maybe I should see if I can get him to hook me up with the info required. I might be able to do that at GDC. (sometimes it's hard to reach him by email cause he's doing crazy Spelunky stuff)

So far heard nothing new about this. Update plz? :-X

EDIT: Sent spam, got reply, yay!  ^-^
Title: Re: Spam
Post by: Xiagan on April 05, 2011, 08:50:27 pm
Spam's a lot better for a few days, thanks Derek? :)
Title: Re: Spam
Post by: False.Genesis on April 07, 2011, 03:56:02 pm
Oh oh.
Monthly Summary - New Topics - New Posts - New Members - Most Online -
2011-04-04319437180
2011-04-0501951973
2011-04-06315132793
Looks like another spammer found the forum...  (and more bots have  a different naming pattern now.)
Oh c'mon, time to stop the exponential growth? Derek?  *poke* :o
Title: Re: Spam
Post by: Sindhi on April 07, 2011, 07:50:31 pm
Yes, please, Derek. BTW my belief is that a neat CLOSET is the sign of a sick mind....
Title: Re: Spam
Post by: Alphasoldier on April 08, 2011, 12:24:16 am
My closet is very neat, and I'm perfectly sane!...I hope.
Title: Re: Spam
Post by: Inyssius on April 08, 2011, 05:31:11 am
My closet is very neat, and I'm perfectly sane!...I hope.

Mine too!

--although admittedly that may be due in part to the fact that it is empty, because all of my clothing is draped over chairs and I haven't gotten around to ironing it yet.
Title: Re: Spam
Post by: Derek on April 08, 2011, 11:59:04 am
Hey, everyone! Sorry about all the spam. I'm going to set aside some time soon to upgrade the forums and install some anti-spam stuff.

I will update this thread once I've done so.
Title: Re: Spam
Post by: Align on April 08, 2011, 01:17:31 pm
Sweetness!
Title: Re: Spam
Post by: EshDee on April 08, 2011, 02:15:09 pm
Awesome!   :D
Title: Re: Spam
Post by: Derek on April 08, 2011, 02:16:33 pm
Alright, done. Let me know if the situation improves. :)
Title: Re: Spam
Post by: False.Genesis on April 08, 2011, 05:36:57 pm
Thanks a lot!
*loves and praises Derek*
(Huh, new smileys :P)
Title: Re: Spam
Post by: Alphasoldier on April 08, 2011, 07:31:44 pm
There's new smilies?

Also awesome on the spam thing.
I see another one just registered and posted some spam, but let's hope it'll become way less.
Title: Re: Spam
Post by: Derek on April 09, 2011, 03:45:12 am
Yeah, sorry, it seems like some of the froggy smilies got replaced in the upgrade. :(

I'm pretty sure some of these spammers are actually human. Or at least they use human beings to register.
Title: Re: Spam
Post by: False.Genesis on April 09, 2011, 03:46:35 am
There are still some registering, either they are humans, or they know how to use search engines, and parse the answers for the registration questions from the results.
(Afaik you could enter fulltext questions to google....)
Not sure if the 2 questions boxes are really that effective. Well i hope they are.

@Derek: What about more mods?  :P

EDIT: Ah, same thought, cool. Damn humans.

EDIT2: Just another thought, if someone wanted to specifically target and flood this forum, it is still easily possible to hardcode the answers to these questions. Nevermind my paranoia though.
Title: Re: Spam
Post by: EshDee on April 09, 2011, 10:57:39 am
Oddly enough, at some other forums I visit, there are adbots increasing in numbers despite captchas and recaptchas.
And some of them even quote other replies in a thread, and make it seem that they've posted it themselves. I really do think these are humans that are spamming.
Title: Re: Spam
Post by: Xiagan on April 11, 2011, 07:36:45 pm
Thanks Derek! :)

And some of them even quote other replies in a thread, and make it seem that they've posted it themselves.
They are the most tricky ones. Luckily I am good at remembering posts/writing styles and so I (nearly?) always get them. :) Usually it is the first or second reply in the same topic, though...
Title: Re: Spam
Post by: Align on December 13, 2011, 02:21:12 pm
Seems to have dropped off the map recently!
Title: Re: Spam
Post by: False.Genesis on February 04, 2014, 12:24:11 am
I'm just saying this now, after a long time of silence there's a new wave of spam incoming. I'm currently deleting ~10 spam topics per day and banning the bots behind them, hope it doesn't get more...
Would be nice if someone did something against it.
Title: Re: Spam
Post by: bstrey on February 04, 2014, 03:40:00 am
If non-admins had the ability to "flag as spam" it might be easier to sort through at the very least. I've also seen forums where, before creating a thread, you need to answer a simple question related to said forums. As an example, we could use: "What is the name of the protagonist?".

Other than that, I don't see how it can be limited.
Title: Re: Spam
Post by: Xiagan on February 04, 2014, 03:26:24 pm
I'm just saying this now, after a long time of silence there's a new wave of spam incoming. I'm currently deleting ~10 spam topics per day and banning the bots behind them, hope it doesn't get more...
Would be nice if someone did something against it.
yeah, me too... No idea what to do, though...
Title: Re: Spam
Post by: False.Genesis on February 04, 2014, 05:29:26 pm
If non-admins had the ability to "flag as spam" it might be easier to sort through at the very least.

This would not be useful. I'm using the forum's RSS feed so my PC makes the sound of truck when someone posts and i'm like YAAY SPAMS TO BAN.

I've also seen forums where, before creating a thread, you need to answer a simple question related to said forums. As an example, we could use: "What is the name of the protagonist?".
This was exactly what used to be there all the time, since ~2011, when the first big spam wave started.

Other than that, I don't see how it can be limited.

Seems that they moved hosts, as some subdirs that were on the server are no longer there, the forum member list is back (it was an empty page before), and the forum's version number jumped from 1.1.17 to 1.1.19. So apparently whatever spam protection was  there got lost during the move.

That said, the questions require to register were a bad choice imho.
I know of enough people who were initially unable to register because they were not able to spell "independent" right, apparently.
I had sent a nice SMF registration antispam plugin to derek back in the days but apparently it wasn't good enough or dunno.

I'm also worried about the wordpress version used for the blog. It's kinda old, and the exploit list available is quite long.

yeah, me too... No idea what to do, though...

Mmm.. Try to use an exploit to get in, and apply some extra security this way? >:D
If i had the chance i'd certainly patch the thing for good.
But no, better not this way.
Title: Re: Spam
Post by: False.Genesis on March 09, 2014, 02:25:24 pm
So, we're now at 108 123 spam posts within a short time. Any chance for some antispam? I'm sick of deleting this shit and banning half of the internet by IP, and stopped doing so few days ago because it's a useless effort.

Someone could at least give me the right to delete users with all their posts, I'm kinda lazy to remove every single spam post manually.

EDIT: Plus here's a possible solution for the bandwidth outage problem near the end of a month. SMF is actually stupid enough to deliver a captcha image with text that doesn't change. So spambots can keep requesting new captcha images over and over and will eventually be able to solve the challenge, wasting bandwidth in the process. There's Bad behavior SMF mod (http://custom.simplemachines.org/mods/index.php?mod=2502) which will prevent spambots from actually seeing the site they requested (wasting even less bandwidth).
Title: Re: Spam
Post by: bstrey on April 16, 2014, 06:05:35 am
Oh, the irony of spam posts in the spam thread...
Title: Re: Spam
Post by: Chibi on April 17, 2014, 01:23:10 am
Oh, the irony of spam posts in the spam thread...

It's brutal.
Title: Re: Spam
Post by: False.Genesis on April 17, 2014, 03:40:25 am
I'm working on getting the necessary attention, dw :D

EDIT: Deleting this load is of no use, so i'm not doing it (for now). The spam will come back anyway.
EDIT2: Heh, at least there's no spam bots on IRC  ::)
Title: Re: Spam
Post by: Derek on May 03, 2014, 09:21:01 am
Added the registration questions back, which should cut down on most of the spam. I'll add the other mods if it doesn't. All the existing spam has been deleted (that was a lot!).

And if the site goes down again this month, let me know, and I'll upgrade the hosting.
Title: Re: Spam
Post by: IcyEyeG on May 04, 2014, 02:46:51 pm
Thank you Derek! Let's see how it goes.
Title: Re: Spam
Post by: Derek on May 28, 2014, 06:44:59 pm
We hit the execution limit on our hosting again, so I upgraded it. Shouldn't happen again.