Author Topic: Regarding Spambots  (Read 10636 times)

0 Members and 1 Guest are viewing this topic.

Offline pecenipicek

  • Roast Chicken
  • 211
  • Powered by copious amounts of coffee and nicotine
    • Skype
    • Steam
    • Twitter
    • PeceniPicek's own deviantart page
i think it'd just be better if it didnt send any more e-mails after the first, until a mod checks the list, ala the "subscribe to topic" thingy on phpBB.
Skype: vrganjko
Ho, ho, ho, to the bottle I go
to heal my heart and drown my woe!
Rain may fall and wind may blow,
and many miles be still to go,
but under a tall tree I will lie!

The Apocalypse Project needs YOU! - recruiting info thread.

 

Offline Goober5000

  • HLP Loremaster
  • 214
    • Goober5000 Productions
Ironically, security and immunity from forum spam were the main reasons we moved to SMF back in 2006 or so.  This was when getting one spambot a week was considered an epidemic.

By the way, during the past week Zacam was at DefCon and I was at BrickFair, so neither of us were available to squash bots.

 

Offline Zacam

  • Magnificent Bastard
  • Administrator
  • 211
  • I go Sledge-O-Matic on Spammers
    • Steam
    • Twitter
    • ModDB Feature
Tell me about it. I really miss the "One touch ban and clean" that Game-Warden has.

There is actually a series (two) modules for SMF that could be combined that I think might be able to fit the bill of duplicating that. Add in a third module, and you can set the ban to an existing ban group (such as a general catch all bucket). Course, the ultimate idea is that we shouldn't need ban buckets anymore except for cases where actual members do something to deserve it.

(The modules in question would add both delet user and ban user buttons to the left side in the short profile section, and the second one would add the ability (when using delete) to also set up a ban, where the third one would allow you to set the ban triggers into an already existing ban element. a 4th (semi-related) module could probably be templated off either of those that would allow Moderators/Globals to one touch "Firewall" users as well.)

i think it'd just be better if it didnt send any more e-mails after the first, until a mod checks the list, ala the "subscribe to topic" thingy on phpBB.

I can see if there is a customization available that allows for that behaviour, so far I haven't seen anything in the defaults that allows it.


As far as the progress of everything else goes, we'll first need to roll out to 2.0 Final, then work in the 5 modules that made it to my list that will then need some time for configuration and what not and observation.

I also have at least 2 other modules that can be independently used to beef up our captcha, but I'm not totally satisfied with either of them individually at the moment', and I'm trying to work out a combination system. One works based of Rotating images to a correct alignment. But I want to combine that into creating what a user then has to input as well. (Basically, straighten out the letters and numbers and images, then type in (using a wildcard character for the image as a placeholder) any of the letters/numbers/symbols that show up in the order they appear (or say, in the reverse order or randomly either) into the validation box) and we'd still need to institute a delay mechanism to the registration process so that it doesn't just email out a validation code on completion.

It will also mean a slight re-organization to the member database, as I want to insulate the "pending" members and the banned/deleted members into their own database categories. This will make being able to A: Review history and sort offenders based on IP's/emails/etc to get a decent count as well as B: Give us the ability (which we don't have) to "undo" any deletes that might happen or (in the event that the anti-bot/spammer check is wrong) be able to "push" a validation, without it taking up any further slots in the db count of regular members. Which will help keep the size down on that respective db as well.
Report MediaVP issues, now on the MediaVP Mantis! Read all about it Here!
Talk with the community on Discord
"If you can keep a level head in all this confusion, you just don't understand the situation"

¤[D+¬>

[08/01 16:53:11] <sigtau> EveningTea: I have decided that I am a 32-bit registerkin.  Pronouns are eax, ebx, ecx, edx.
[08/01 16:53:31] <EveningTea> dhauidahh
[08/01 16:53:32] <EveningTea> sak
[08/01 16:53:40] * EveningTea froths at the mouth
[08/01 16:53:40] <sigtau> i broke him, boys

 
Umm, why (and when) was our unique custom-built CAPTCHA replaced with some stock thing that every bit of bot knows how to deal with?

 

Offline Iss Mneur

  • 210
  • TODO:
Umm, why (and when) was our unique custom-built CAPTCHA replaced with some stock thing that every bit of bot knows how to deal with?

IIRC, it was broken a few months back.


@admins: Out of curiosity, does HLP take part in something like Project Honeypot to help classify incoming users?
"I love deadlines. I like the whooshing sound they make as they fly by." -Douglas Adams
wxLauncher 0.9.4 public beta (now with no config file editing for FRED) | wxLauncher 2.0 Request for Comments

 

Offline Zacam

  • Magnificent Bastard
  • Administrator
  • 211
  • I go Sledge-O-Matic on Spammers
    • Steam
    • Twitter
    • ModDB Feature
Umm, why (and when) was our unique custom-built CAPTCHA replaced with some stock thing that every bit of bot knows how to deal with?

Or "unique" custom captcha only operates on the posting level. Not on the registration level. Yet. Hence where we are going to be beefing it up more.


@admins: Out of curiosity, does HLP take part in something like Project Honeypot to help classify incoming users?

Not at present it does not. But there is an SMF module for it that will be added which will provide it to us. I just need to tie it into the registration collection process (but before the activation email is sent) so that we can reject out-right spam accounts from ever being created in the first place, and retain suspicious looking ones on the "Pending" list (again, still without sending an activation email) so that we can approve or reject them as necessary. But the default out-of-the package module needs some adjustment to play well with the other modules I'm looking to combine and customizations to insert it into the proper place, etc.
Report MediaVP issues, now on the MediaVP Mantis! Read all about it Here!
Talk with the community on Discord
"If you can keep a level head in all this confusion, you just don't understand the situation"

¤[D+¬>

[08/01 16:53:11] <sigtau> EveningTea: I have decided that I am a 32-bit registerkin.  Pronouns are eax, ebx, ecx, edx.
[08/01 16:53:31] <EveningTea> dhauidahh
[08/01 16:53:32] <EveningTea> sak
[08/01 16:53:40] * EveningTea froths at the mouth
[08/01 16:53:40] <sigtau> i broke him, boys

 
Our "unique" custom captcha only operates on the posting level. Not on the registration level. Yet. Hence where we are going to be beefing it up more.
[/color]

It was used for registrations too, I remember checking it out myself (I mean the one with the ship names). But the CAPTCHA we have now (for registration) is in use pretty much everywhere, so obviously bots know how to deal with it...

IIRC, it was broken a few months back.

I wonder if the surge in spambot activity coincided with the removal of it?

 

Offline Woolie Wool

  • 211
  • Fire main batteries
A second wave of the bastards seems to be inbound. I've already reported two of them.
16:46   Quanto   ****, a mosquito somehow managed to bite the side of my palm
16:46   Quanto   it itches like hell
16:46   Woolie   !8ball does Quanto have malaria
16:46   BotenAnna   Woolie: The outlook is good.
16:47   Quanto   D:

"did they use anesthetic when they removed your sense of humor or did you have to weep and struggle like a tiny baby"
--General Battuta

 

Offline Droid803

  • Trusted poster of legit stuff
  • 213
  • /人 ◕ ‿‿ ◕ 人\ Do you want to be a Magical Girl?
    • Skype
    • Steam
I don't think they come in waves but rather a continuous steady stream.
(´・ω・`)
=============================================================

 

Offline Goober5000

  • HLP Loremaster
  • 214
    • Goober5000 Productions
Yeah, like a fire hose.  There's still a crapload in the memberlist we haven't gotten rid of yet.  Zacam is working on a proper batch-delete feature.

 
They're more aggressive than I ever seen them to be. I've ran a little forum as the administrator for around 3 years and they were annoying but not particularly hard to beat with limited means. It could just be my perception but they really seem to be much more insistent than around 5-6 years when i last worked on my forum. Still, looking at how they're acting like they're real people... makes me wonder, how long until someone perfects this and uses it against forums o.o

Of course it's more an entertaining thought than anything else.
I'm all about getting the most out of games, so whenever I discover something very strange or push the limits, I upload them here:

http://www.youtube.com/user/JCDentonCZ

-----------------

"Do you begin to see, then, what kind of world we are creating? It is the exact opposite of the stupid hedonistic Utopias that the old reformers imagined. A world of fear and treachery and torment, a world of trampling and being trampled upon, a world which will grow not less but more merciless as it refines itself. Progress in our world will be progress to more pain."
- George Orwell

 

Offline The E

  • He's Ebeneezer Goode
  • 213
  • Nothing personal, just tech support.
    • Steam
    • Twitter
Well, a little forum 3 yers ago and a middle-sized one now can hardly be compared (HLP gets about 1.5 million pageviews per month, I believe?). We're definitely a juicier target.
If I'm just aching this can't go on
I came from chasing dreams to feel alone
There must be changes, miss to feel strong
I really need lifе to touch me
--Evergrey, Where August Mourns

 

Offline pecenipicek

  • Roast Chicken
  • 211
  • Powered by copious amounts of coffee and nicotine
    • Skype
    • Steam
    • Twitter
    • PeceniPicek's own deviantart page
one of my "9 months unused" forums suddenly got a spike in traffic, resulting in around of 11 gigabytes of traffic generated.

i was at first like "What the?", then i went checking subdomains. suddenly, one of the forums i used to run was shown to have somewhere like 400 new members. go check posts, went over 10k posts total. on a forum that previously had less than 500 total.


i'd let it go on, but then i simply nuked the subdomain and the forum.

Skype: vrganjko
Ho, ho, ho, to the bottle I go
to heal my heart and drown my woe!
Rain may fall and wind may blow,
and many miles be still to go,
but under a tall tree I will lie!

The Apocalypse Project needs YOU! - recruiting info thread.

 

Offline Goober5000

  • HLP Loremaster
  • 214
    • Goober5000 Productions
I wonder how The Forum of James is doing.

 

Offline pecenipicek

  • Roast Chicken
  • 211
  • Powered by copious amounts of coffee and nicotine
    • Skype
    • Steam
    • Twitter
    • PeceniPicek's own deviantart page
the what?
Skype: vrganjko
Ho, ho, ho, to the bottle I go
to heal my heart and drown my woe!
Rain may fall and wind may blow,
and many miles be still to go,
but under a tall tree I will lie!

The Apocalypse Project needs YOU! - recruiting info thread.

 

Offline Shivan Hunter

  • 210
  • FRED needs lambdas!
Forum of James. Every link of his is dead though so I assume it's been deleted. :P

What about that other guy's hyper-conservative forum? Some of us in IRC trolled it but it got boring.

 
To prevent multi-reporting, I just saw Shade do something neat, and absurdly simple. He reported a bot, and replied to the topic stating that he did so.

EDIT: Holy sheep! Two more bots in the couple of minutes since I posted this!
« Last Edit: August 21, 2011, 12:47:38 am by Scourge of Ages »

 

Offline Mongoose

  • Rikki-Tikki-Tavi
  • Global Moderator
  • 212
  • This brain for rent.
    • Steam
    • Something
Yeah, that idea is greatly appreciated, since it cuts down on the flood of e-mails that we've all been getting. :) Someone else did it a day or two ago, though I don't know if it was Shade, since the post got deleted along with the thread.

 

Offline JGZinv

  • 211
  • The Last Dual! Guardian
    • The FringeSpace Conversion Mod
Just had a spam bot that's online now hit the FringeSpace board and I took care of the post.

Here's the user name - incorvitos
True power comes not from strength, but from the soul and imagination.
Max to PCS2 to FS2 SCP Guide
The FringeSpace Conversion Mod

 

Offline Fury

  • The Curmudgeon
  • 213
@admins: Out of curiosity, does HLP take part in something like Project Honeypot to help classify incoming users?
CloudFlare would do that and much more too. The only reason why it was disabled shortly after it was tried out was that Starman01 was having weird issues. I'd suspect these are fixed by now. HLP CloudFlare account still exists with all but the newest (if any) domains already set up. Only GoDaddy DNS needs to be changed and it'd be good to go once again.