Author |
Message |
|
Weregoose Authentic INTJ
Super Elite (Last Title)

Joined: 25 Nov 2004 Posts: 3976
|
Posted: 11 Apr 2009 03:14:20 am Post subject: |
|
|
Mass PM and some forum spam. Apparently a wave of bots are being human-validated so they can carry out their attacks.
A patch which "fixes" this problem by enabling flood control is available here.
[EDIT]
It was only one active bot, and it was an easy cleanup on the forum side – presumably, it made its posts only so it would qualify for sending messages. As there were no other accounts engaging in that activity, the sending stopped when I deleted the one member. There are four other registered users (all new) under the same IP (87.118.86.96) that could potentially become active. (Actually, we're being hit by accounts under a wide range of IP's. Let's hope that the nut behind this doesn't pay the forum another visit to do things manually.)
I made an announcement to let members know that we're aware.
Last edited by Guest on 11 Apr 2009 11:02:17 am; edited 1 time in total |
|
Back to top |
|
|
AlienCC Creative Receptacle!
Know-It-All

Joined: 24 May 2003 Posts: 1927
|
Posted: 11 Apr 2009 02:36:36 pm Post subject: |
|
|
Have you applied this patch then, or does that still need to be done? |
|
Back to top |
|
|
Weregoose Authentic INTJ
Super Elite (Last Title)

Joined: 25 Nov 2004 Posts: 3976
|
Posted: 11 Apr 2009 05:22:46 pm Post subject: |
|
|
The patch is applied, with the default time set to five minutes between each message. |
|
Back to top |
|
|
DigiTan Unregistered HyperCam 2
Super Elite (Last Title)

Joined: 10 Nov 2003 Posts: 4468
|
Posted: 13 Apr 2009 10:17:21 am Post subject: |
|
|
It looks like there is a new thread spambot, jurdreda on the loose. I tried warning the account, but tripped over my own shoelaces and accidently warned thebetter (now fixed, I think). So far, jurdreda's account has been cross-posting "aaaaaaaaa" in several threads inside 1-2 minutes time. If someone can block the spambot and/or undo thebetter's warn history that would be appreciated. |
|
Back to top |
|
|
Weregoose Authentic INTJ
Super Elite (Last Title)

Joined: 25 Nov 2004 Posts: 3976
|
Posted: 13 Apr 2009 10:53:00 am Post subject: |
|
|
It looks like no PM's were sent this time, due to sgm's quick reflexes.
Interestingly, today's bot's IP (87.118.87.96) differs by one, in the third octet, from the last one.
I'll see if there is a way to delete individual notes of a member.
[EDIT] – Done.
Last edited by Guest on 13 Apr 2009 10:55:53 am; edited 1 time in total |
|
Back to top |
|
|
DigiTan Unregistered HyperCam 2
Super Elite (Last Title)

Joined: 10 Nov 2003 Posts: 4468
|
Posted: 14 Apr 2009 04:55:17 pm Post subject: |
|
|
A new spambot, tervokskyr (profile) showed up today with the same behavior as yesterday's jurdreda one. I put the account on mod review (the right one this time ).
Last edited by Guest on 14 Apr 2009 04:56:35 pm; edited 1 time in total |
|
Back to top |
|
|
Weregoose Authentic INTJ
Super Elite (Last Title)

Joined: 25 Nov 2004 Posts: 3976
|
Posted: 14 Apr 2009 08:16:52 pm Post subject: |
|
|
Wouldya look at the IP of that one: 87.118.87.96. Same as the last one. Should we ban him?
Last edited by Guest on 14 Apr 2009 08:21:15 pm; edited 1 time in total |
|
Back to top |
|
|
DigiTan Unregistered HyperCam 2
Super Elite (Last Title)

Joined: 10 Nov 2003 Posts: 4468
|
Posted: 16 Apr 2009 02:39:33 pm Post subject: |
|
|
Is there a way to stop its PM priviliges? Until now, it looked like it couldn't cause any more trouble, but I see it's looking at its PM inbox today. Maybe we can just raise the flood control limit.
Last edited by Guest on 16 Apr 2009 02:40:22 pm; edited 1 time in total |
|
Back to top |
|
|
DigiTan Unregistered HyperCam 2
Super Elite (Last Title)

Joined: 10 Nov 2003 Posts: 4468
|
Posted: 17 Apr 2009 05:51:50 pm Post subject: |
|
|
* Looks away from TV *
They're baaaaaaaaaaaack! This time from 87.118.87.96. What puzzles me is the message. Shouldn't it be posting Viagra spam or something? What the heck does "aaaaaaaaaaaa" accomplish?
Last edited by Guest on 17 Apr 2009 05:52:32 pm; edited 1 time in total |
|
Back to top |
|
|
Weregoose Authentic INTJ
Super Elite (Last Title)

Joined: 25 Nov 2004 Posts: 3976
|
Posted: 17 Apr 2009 08:43:21 pm Post subject: |
|
|
We have an option in effect which prevents users of 0 postcount from sending personal messages; since the bot's goal is to spam through that medium, it needs to get over the posting hurdle first, and does so sufficiently.
I'm banning that I.P. If he uses another one next week, I'll lift the ban until we (or IPB) should find another way to handle it. Or we could incrementally ban each I.P. that he ends up using.
[EDIT] – The patch looks successful. We were a little late on the defensive this time, yet only 12 messages got out.
Last edited by Guest on 17 Apr 2009 09:04:39 pm; edited 1 time in total |
|
Back to top |
|
|
Weregoose Authentic INTJ
Super Elite (Last Title)

Joined: 25 Nov 2004 Posts: 3976
|
Posted: 27 Apr 2009 07:37:23 pm Post subject: |
|
|
Another bot, another I.P., same behavior. I deleted the member "justrakop" and banned 217.20.116.59, which historically has belonged to no other members of this forum (except for hylokopser, another potential spambot from the same creator).
He uses the same long string of a's in all of his posts, and those posts appear in multiple threads at once, so I doubt that it's a human making them. I don't know if there's a way to test the post content as a condition for blocking someone, but that sure would be nice.
Last edited by Guest on 27 Apr 2009 07:50:43 pm; edited 1 time in total |
|
Back to top |
|
|
DigiTan Unregistered HyperCam 2
Super Elite (Last Title)

Joined: 10 Nov 2003 Posts: 4468
|
Posted: 28 Jul 2009 06:08:57 pm Post subject: |
|
|
Did bbsbrian send out any mass PMs? I got a message from him but trashed it before I realized "Oh crap! That could of been legit!" His opening advertisement was suspicious compared to past spam accounts but I told him to contact us to have things cleared up. Plus, I figure if this were a bot, we'd be spammed by now.
Anyway, I wanted to run this past you guys first. In the meantime, I'll ask him to confirm his last message with mods/admin.
Message sent:
Quote: Okay, I checked with the other mod and admins. For expedience, please forward (CC) your request to the mods/admin on the list below we will get this corrected:
Weregoose
DarkerLine
sgm
AlienCC
NETWizz
Bryan Thomas
Glen
Justin W.
alexrudd
Last edited by Guest on 28 Jul 2009 06:20:15 pm; edited 1 time in total |
|
Back to top |
|
|
Weregoose Authentic INTJ
Super Elite (Last Title)

Joined: 25 Nov 2004 Posts: 3976
|
Posted: 29 Jul 2009 01:27:24 am Post subject: |
|
|
The only messages from him thus far are tied to moderators and staff.
Last edited by Guest on 29 Jul 2009 01:28:14 am; edited 1 time in total |
|
Back to top |
|
|
DigiTan Unregistered HyperCam 2
Super Elite (Last Title)

Joined: 10 Nov 2003 Posts: 4468
|
Posted: 29 Jul 2009 08:59:56 pm Post subject: |
|
|
What do you guys say? Re-enable posting but let the warning stick until later? |
|
Back to top |
|
|
DarkerLine ceci n'est pas une |
Super Elite (Last Title)

Joined: 04 Nov 2003 Posts: 8328
|
Posted: 29 Jul 2009 09:05:00 pm Post subject: |
|
|
Sounds good to me. |
|
Back to top |
|
|
Weregoose Authentic INTJ
Super Elite (Last Title)

Joined: 25 Nov 2004 Posts: 3976
|
Posted: 29 Jul 2009 09:22:55 pm Post subject: |
|
|
Yea; with the bot given the boot, we resume our normal programming. |
|
Back to top |
|
|
|