PDA

View Full Version : Forum Spam



swordfish
01-15-2010, 10:45 AM
CADC Members

:soapbox:

In the past 2 days I have received 2 private messages through CADC that are spam.

The sender of the one today was from a 'Member' called LadyAdministrator, advising me to click on a link to repair a virus. This is an obvious fraud attempt.

I would strongly urge members to be very careful and suspicious of this type of private message.

Plavchek
01-15-2010, 11:59 AM
I had got two of them (lucky me). I was confused at first and believed it since this is a small website and niche in the inter-webs & why would a hacker target small forums? (adds to the credibility i assume)

I ignored it anyways so no harm done. All though I feel special I was singled out- maybe he/she wanted a date? :)

OneShot
01-15-2010, 12:34 PM
Both spammers have been banned ... unfortunatly they are of a type thats hard to stop beforehand because unlike the usual spam bots those are real people signing up.

The only measure against those would be to individually approve everybody before allowing access to the CADC and thats a step I dont want to do unless absolutly necessary.

However, for the future and as reference, there is a page on the forum where you can see all Admins & Moderators (http://www.commanders-academy.com/forum/showgroups.php). When in doubt check there.

swordfish
01-15-2010, 03:29 PM
Got a 3'rd one today. This one is from 'kkajly672' and refers to spam #2, with the same link.:frown:

Is there any chance they are all coming from the same IP? If so perhaps the IP can be banned.

Plavchek
01-15-2010, 04:02 PM
Got a 3'rd one today. This one is from 'kkajly672' and refers to spam #2, with the same link.:frown:

Is there any chance they are all coming from the same IP? If so perhaps the IP can be banned.

You could but it's easier to use a proxy to do things like that, which most likley they have done to aviod real identification.

Let's hope One Shot's suggestion doesn't become a reality, even then it's not garunteed to limit spammers.

All I can say is if they want my social security and credit number- by all means please take it and raise my credit score :D

Claus
01-15-2010, 07:04 PM
Third PM in 2 days. Now, it's from "kkajly672"

Sink the spammers! :soapbox:

"Gracias" :biggrin

CapitanPiluso
01-15-2010, 08:33 PM
I got 2 PM s too...:mob::mob:

OneShot
01-16-2010, 04:27 AM
Banned that guy too ...

As for banning by IP ... most people don't have a dedicated IP but instead get a new one every time they sign on. This means I would have to ban a range of IPs which might be pretty broad. While that might keep away the spammers it would keep away regular users within the same IP range as well.

Hence I have to stay reactive and just ban the offending users directly - more work for me but less restrictions for everybody else.

Plavchek
01-16-2010, 11:18 AM
Thanks Oneshot for doing the extra work!

Theta Sigma
01-17-2010, 03:42 AM
I wonder if these are still bots anyway. I've heard the bots/macros have improved with getting around captchas.

I'm sure they're using proxies but, by any chance, do these accounts resolve to China or Russia? Long term would be a bit hard, but a short term ban on those ranges might help.

212Alpha
01-17-2010, 08:16 AM
Next Round....

Now it's the account AdminLady.

Can someone sink it, please.

goldorak
01-17-2010, 02:18 PM
Next Round....

Now it's the account AdminLady.

Can someone sink it, please.

You can also fix the problem partially by automatically putting these emails into the spam folder of your email client, or create a rule so that these emails are automatically deleted.

swordfish
01-17-2010, 02:42 PM
AdminLady is at it now. I guess the best solution for me is to turn off the PM's altogether.

OneShot
01-17-2010, 04:47 PM
Banned her while she was sending, guess I wasn't fast enough. However I banned certain username variations - for starters everything that includes "Admin" or "Mod" ...

As for banning IP ranges ... as far as I have seen the IPs used range from russia to the u.s. and probably some inbetween ... so while its possible to do that it would prolly be very counterproductive.

Aside from that, I'm planning on upgrading the CADC to the latest vBulletin version in the not so distant future ... I have to wait tho because I'm dependent on certain mods to function - most notably the integration of the Wiki. Some things already work under vB4 for example the downloads and the arcade ... but the wiki not, at least not yet. Once thats fixed the CADC will be down for a day or two and then resurface with a hopefully more spam proof software.

robcad
01-29-2010, 06:03 PM
MannInBlackk is the spammer of the day today (Jan 28). Thanks for maintaining the board. I don't get here often, but it is great for DW stuff.
Robert

OneShot
01-30-2010, 05:33 AM
Already bannend him, obviously a tad to late ...

Transients
01-30-2010, 11:22 AM
"Ladyrootfix" is my latest. I've had about 4 of these.

KTHXBAI
01-30-2010, 12:29 PM
I've had several of these, if not dozens. They just keep coming.

Planetbrain
01-30-2010, 09:55 PM
I've had 3-4 between 17Jan & 30 Jan

ASWnut101
02-09-2010, 04:24 PM
Now the username is ForumTeamSupports.

fanqi1234
02-10-2010, 06:02 AM
new one named "RazzorrMan"

__
is it possible to filter the spammer's website URL,
OR
instead of automatically wrap URL with <a href="URL">URL</a>, wrap it with a link to a warning page?

KTHXBAI
02-10-2010, 08:16 AM
Another one... Again. :gdamnit:

MALOGuy
02-10-2010, 10:16 AM
I just received a second piece of spam mail informing me of a possible virus and providing a helpful link to fix the "problem". Both emails were identical in their message.
Unfortunately, it may be time for a "Spam" button on the control panel.
I left both emails in case the moderators want to have a look at them.

TorpedoMo81
02-10-2010, 06:03 PM
Hi!

Also received to SPAM PMs today from:

"RazzorrMan" and "Desterman"

Peter.Steele
02-10-2010, 10:59 PM
8 between 13JAN10 and 10FEB10. Same names as previously listed. Two today from this prick 'Dersterman.'

PM's are now turned off, for me anyway.

DD59
02-11-2010, 04:17 PM
3 spams today only, lets hope this will stop soon...

KTHXBAI
02-11-2010, 10:29 PM
Another one from a cat named "CuurioussGirl."

:gdamnit:

Tarrasque123
02-12-2010, 07:15 PM
Also GafarozzMan and Hummannic

OneShot
02-13-2010, 03:14 PM
Banned the listed users and added a few choice words to those that are not allowed as usernames. Furthermore I've disabled the PM system for the moment, this however will only be temporary until I've taken some measures to prevent "fresh users" meaning with a low number of posts from sending PMs at all ... I know thats possible with vBulletin, I just have to figure out the smartest way ... should be done by tomorrow night local.

vance
02-14-2010, 12:50 AM
Some "fresh users" are legitimate. Last week I received a PM for a copy of the TMA tool I developed. As I recall, the member joined last month and had zero posts.

Since the tool requires MathCAD to run, making it available thru a PM request seems more appropriate because most DW users don't have MathCAD.

I rarely post here even though I visit on a regular basis. Maybe there's a way to keep the PM available for infrequent posters and still solve the spam issue.

Regards,

Vance

OneShot
02-14-2010, 07:10 AM
@Vance : Unfortunatly I can't see one right now ... except approving each new user on an individual basis meaning a lot of work for me or someone else from the Admin/Mod group. Since I'm often away from home (and an Inet Connection) due to RL it would mean that someone else would have to take care of that or it wouldn't happen in a timely manner.

Therefore the only solution I see now is to create a new usergroup where all users belong to until they have reached for example a set number of posts.

And thats the way I'll go until I see a better solution.

EDIT : Changes done ...

There is a new Usergroup now ... "Apprentice Users". This group has all priviliges of the Registered Usergroup except the ability to send PMs until they have been with the board for at least 30 days and have a post count greater then two.

I hope I haven't forgotten to tick of a necessary checkbox in regards to other permissions ... please let me know if you are in the Apprentice Users group and for example can't access the downloads or play on the Arcade.

mechan9
02-28-2010, 07:18 PM
Just wanted to give a heads up about spam I received through a private message.

It was from DennieeAdamz who has zero posts.


Your computer was noticed in email spam. It is quite possible that it is a part of botnet (see Wikimedia Error). Strongly recommend you to scan your computer for malware. You can do it online at: http://total-scan.org/spammers/Raspu...k;mechan9;Spaz
Please, follow this. Otherwise I have to send abuse mail to your ISP with all the ensuing consequences.
Truly yours, Dennis Adams.

OneShot
03-01-2010, 11:27 AM
Took care of him ... he was still part of the registered users group - must have been slipped through when I moved all the 0 posters over to the Apprentice Users group.

Yskonyn
03-23-2010, 05:55 PM
A new one ColinXHoward is the name. 0 posts; I got the above mentioned spam notification via pm.

OneShot
12-27-2010, 11:23 AM
Well, I had to take some steps today. First off after the upgrade I had to reinstate that new users end up in the Apprentice Users Group which is quite restricted when it comes to using eMails/PMs and posting on the board. Since a number of users ended up in the Registered Users Group who don't belong there I made it easy for me and copied all those over with 0 Posts (After checking the forum for Spam posts). Hopefully those measures together with everything else I did take care of the spammer problem or at least keep it within workable and reasonable bounds. Well, we will see.

While the Apprentice Users Group is restricted in terms of posting and such - everything else including the downloads works. However if anybody feels he ended up in the wrong Group or something is not working please email me at oneshot(AT)commanders-academy(DOT)com.

Molon Labe
12-27-2010, 12:15 PM
I just tried to find the Apprentice User Group at the Control Panel and only found Uncategorized.

OneShot
12-27-2010, 02:37 PM
Believe me - its there. Its a custom Usergroup (not a Group) ... you should look under Usergroups and not Groups :)

Molon Labe
12-27-2010, 04:33 PM
Still don't see it... maybe I don't have access to Custom Usergroups.

Subber
03-08-2011, 12:53 PM
That user-group thing seems like a good idea. Being a new user, I hate being part of the problem, basically. But I'm not a spammer, so I'll just keep posting and hope for the best!











Managers need business continuity planning software (http://www.coop-systems.com/)... and a whip.