PDA

View Full Version : Anti-spam system in forum



ErosOlmi
04-01-2011, 22:37
Today thinBasic community forum had many new user registration. Well, all of them were spammers.

For the above reason I've installed a new forum plugin that checks users (or potential one) characteristics (username, IP, email ,....) against http://www.stopforumspam.com/ and http://akismet.com/ databases

Also posts and comments of already registered users are checked.

Hope this will stop spammers and at the same time will not create troubles to "honest" accounts.

For any problem, please email to: support at thinbasic dot com

Ciao
Eros


PS: if anyone is interested, here some plug-ins for many different forums: http://www.stopforumspam.com/contributions

Charles Pegge
04-01-2011, 23:21
Hi Eros,

John installed StopForumSpam on all his hosted forums including Oxygen. It is very effective but a few days ago I decided to take one step further and that was to disable self registration completely, and just go for an informal application by email.

All the applicants have to do is send an email of two or three lines and their preferred user name demonstrating they are human or at least pass the Turing test. If there are any spurious looking applications they go straight into the trash bin. At the same time I think it is much easier and less intimidating for real persons to join.

Personally I find many of the audio/visual tests used in forum registration systems
too difficult.

Charles

ErosOlmi
04-01-2011, 23:30
Charles,

you opted for a very drastic decision, isn't it?

Well, I will go step by step. I see that spamming level goes by waves. This period has a big and long wave but I'm sure it will decrease (at least I hope).

Looking from my forum log, actually new anti-spam plugin is doing a nice work.

Will see. Ciao
Eros

Charles Pegge
05-01-2011, 00:01
I was getting about 99% Spam bots, of which about 90% were detected and the other 9% were obviously bogus. A genuine applicant might be accidently missed when the lists are long.

Anyway good luck with the new system!

Charles

ErosOlmi
05-01-2011, 01:23
In a little more than 1 hour

2011-01-05 00:22:14 74.55.6.210 No Username Submitted japeimantee@izmail.net Spam-O-Matic Tagged email - japeimantee@izmail.net - Spammer Found and rejected.
2011-01-05 00:17:39 77.254.176.176 No Username Submitted mail2012@tlen.pl Spam-O-Matic Tagged email - mail2012@tlen.pl - Spammer Found and rejected.
2011-01-05 00:15:28 109.230.221.136 No Username Submitted galepaniccia@gmail.com Spam-O-Matic Tagged email - galepaniccia@gmail.com - Spammer Found and rejected.
2011-01-05 00:13:24 121.166.82.1 No Username Submitted franky.tyson@yahoo.co.uk Spam-O-Matic Tagged email - franky.tyson@yahoo.co.uk - Spammer Found and rejected.
2011-01-05 00:12:45 211.24.188.186 No Username Submitted rex.fischeryidgj@gmail.com Spam-O-Matic Tagged email - rex.fischeryidgj@gmail.com - Spammer Found and rejected.
2011-01-05 00:12:13 64.9.173.22 No Username Submitted maggierog33@email.com Spam-O-Matic Tagged email - maggierog33@email.com - Spammer Found and rejected.
2011-01-05 00:07:18 93.182.187.126 No Username Submitted guyper34@aim.com Spam-O-Matic Tagged email - guyper34@aim.com - Spammer Found and rejected.
2011-01-04 23:51:07 109.230.220.53 No Username Submitted leczycanin3455@leczycanie.pl Spam-O-Matic Tagged email - leczycanin3455@leczycanie.pl - Spammer Found and rejected.
2011-01-04 23:51:00 60.173.11.35 No Username Submitted udtjcoss4@aol.com Spam-O-Matic Tagged email - udtjcoss4@aol.com - Spammer Found and rejected.
2011-01-04 23:49:03 93.174.93.204 No Username Submitted wamioffella@mail.saratov.com Spam-O-Matic Tagged email - wamioffella@mail.saratov.com - Spammer Found and rejected.
2011-01-04 23:38:58 87.104.185.196 No Username Submitted fista@eurourl.net Spam-O-Matic Tagged email - fista@eurourl.net - Spammer Found and rejected.
2011-01-04 23:35:19 77.92.224.110 No Username Submitted g.o.t.o.v.i.j.b.i.z@gmail.com Spam-O-Matic Tagged email - g.o.t.o.v.i.j.b.i.z@gmail.com - Spammer Found and rejected.
2011-01-04 23:09:38 95.141.39.146 No Username Submitted boropaill@mail.ru Spam-O-Matic Tagged email - boropaill@mail.ru - Spammer Found and rejected.
2011-01-04 23:06:42 91.201.66.116 No Username Submitted racheljckb@yandex.ru Spam-O-Matic Tagged email - racheljckb@yandex.ru - Spammer Found and rejected.
2011-01-04 23:03:58 94.142.133.180 No Username Submitted nikdimsik@gmail.com Spam-O-Matic Tagged email - nikdimsik@gmail.com - Spammer Found and rejected.

danbaron
05-01-2011, 07:41
Maybe I am the only one, but, I don't understand what you are talking about.

I know somewhat about e-mail spam, which usually are trying to sell something, or swindle people.

But, I don't understand what the purpose is to do it to this forum. You are saying that all of the applicants were not people, but, were automated applicants? In that case, the purpose would be to become forum members, and then to make posts which try to sell something or to swindle people? What other purpose could there be, unless the perpetrators are just malicious, or are some kind of anarchists?

If the applications were automated, then, I don't understand how they could join the forum. If I remember correctly, I had to click on a button on the screen, and then fill out a box in order to join the forum. I don't understand how a program could do it. Additionally, didn't I have to look at a picture, and type the characters displayed there?

You are saying that the spam databases are e-mail addresses submitted by people? If so, then, what if someone sends your or my e-mail address to such a database?

And, couldn't the spammers just constantly change their e-mail addresses? Are you saying that the databases also contain that strange number, something like, 325.341.987.567? That number identifies the internet account?

Protecting against viruses and spam, reminds me of always having to watch your house, because you know there are criminals who want to burn it down. The task is necessary, but such a source of frustration and stress, and such a waste of time and energy.

Again and again, throughout history it has been shown that those who cannot create, love to destroy the creations of others. The examples go from the tiny - someone kicking down a sand castle on the beach, to the giant - an army destroying a country's entire civilization.

Destroying is so much easier than creating, correct? What a lift to the guy's self esteem, he has the power to generate unimaginable amounts of misery and suffering!

Spam reminds me of a personal violation - like home invasion, assault, kidnapping, rape, murder, etc. And spammers are by nature, cowards, yes or no?

John Spikowski
05-01-2011, 07:55
Maybe I am the only one, but, I don't understand what you are talking about.

Most forum software is written in PHP. The source is open to anyone who cares to look at it. Most of the automated registering internet crawling forum spamming (BOTS) try to sell their crap (porn, Viagra, ...) on any site that isn't aggressive fighting them off. I have BOTS that try to register on the open source forums I facilitate 20+ times a day. The response they get to their attempts is ...

"Sorry Guest, you are banned from using this forum!"

ErosOlmi
05-01-2011, 08:53
Here the list of blocked attempts trying to register in thinBasic community forum in the last 8 hours. Can you imagine in 24 hours? and in a week?
Imagine all of them place just 1 fake post each: this place would be devastated.


that strange number is the following http://en.wikipedia.org/wiki/IP_address

You have one too, every "machine" (a router, a DSL modem, your computer, a network printer, a network hard disk, a smart phone connected using umts network, ...) have one if it is connected to a tcp/ip network (local or public).


2011-01-05 07:41:11 178.239.57.203 AlielmImmax boniek123123@o2.pl Spam-O-Matic Tagged email - boniek123123@o2.pl - Spammer Found and rejected.
2011-01-05 07:39:50 94.181.63.73 No Username Submitted qrawstikutro1@mail.ru Spam-O-Matic Tagged email - qrawstikutro1@mail.ru - Spammer Found and rejected.
2011-01-05 07:36:17 213.5.71.160 No Username Submitted contreras.orval80@gmail.com Spam-O-Matic Tagged email - contreras.orval80@gmail.com - Spammer Found and rejected.
2011-01-05 07:33:21 79.120.85.139 No Username Submitted huy2@online-pillshop.com Spam-O-Matic Tagged email - huy2@online-pillshop.com - Spammer Found and rejected.
2011-01-05 07:25:22 187.11.225.18 No Username Submitted chrisdoove@gmail.com Spam-O-Matic Tagged email - chrisdoove@gmail.com - Spammer Found and rejected.
2011-01-05 07:15:15 83.28.1.226 kredyty24 kredyty303@o2.pl Passed StopForumSpam checks. Sent to vBulletin Registration System.
2011-01-05 07:15:13 83.28.1.226 No Username Submitted Passed StopForumSpam checks. Sent to vBulletin Registration System.
2011-01-05 07:15:12 83.28.1.226 No Username Submitted Passed StopForumSpam checks. Sent to vBulletin Registration System.
2011-01-05 07:10:23 74.55.6.210 No Username Submitted asymouscuby@topmagic.org Spam-O-Matic Tagged email - asymouscuby@topmagic.org - Spammer Found and rejected.
2011-01-05 06:33:22 89.248.174.76 No Username Submitted tedotrogeno@xsecurity.org Spam-O-Matic Tagged email - tedotrogeno@xsecurity.org - Spammer Found and rejected.
2011-01-05 06:31:08 188.126.69.7 No Username Submitted spinnendertr@hirschsaeure.info Spam-O-Matic Tagged email - spinnendertr@hirschsaeure.info - Spammer Found and rejected.
2011-01-05 06:17:40 74.55.6.210 No Username Submitted mosyessenolom@mainru.com Spam-O-Matic Tagged email - mosyessenolom@mainru.com - Spammer Found and rejected.
2011-01-05 06:00:10 91.201.66.133 No Username Submitted firmasps@hotel-zk.lviv.ua Spam-O-Matic Tagged email - firmasps@hotel-zk.lviv.ua - Spammer Found and rejected.
2011-01-05 05:47:03 89.248.174.76 No Username Submitted lypetypegrorm@peugeot-club.org Spam-O-Matic Tagged email - lypetypegrorm@peugeot-club.org - Spammer Found and rejected.
2011-01-05 05:42:28 94.181.176.2 No Username Submitted vasilisaandreeva201.0@gmail.com Spam-O-Matic Tagged email - vasilisaandreeva201.0@gmail.com - Spammer Found and rejected.
2011-01-05 05:37:01 208.53.131.149 No Username Submitted margaretarzun@gmail.com Spam-O-Matic Tagged email - margaretarzun@gmail.com - Spammer Found and rejected.
2011-01-05 05:32:20 91.210.106.252 No Username Submitted hortaman@gmail.com Spam-O-Matic Tagged email - hortaman@gmail.com - Spammer Found and rejected.
2011-01-05 05:18:31 195.162.68.146 No Username Submitted guviolu@gmail.com Spam-O-Matic Tagged email - guviolu@gmail.com - Spammer Found and rejected.
2011-01-05 04:52:06 79.142.67.137 No Username Submitted devona.chestee.n@gmail.com Spam-O-Matic Tagged email - devona.chestee.n@gmail.com - Spammer Found and rejected.
2011-01-05 04:48:37 195.162.68.146 No Username Submitted guviolu@gmail.com Spam-O-Matic Tagged email - guviolu@gmail.com - Spammer Found and rejected.
2011-01-05 04:45:52 173.234.122.93 insomniac1983 genius1983@hotmail.com Spam-O-Matic Tagged username - insomniac1983 - Spammer Found and rejected.
2011-01-05 04:39:59 83.59.90.58 No Username Submitted klara@gamesforyou.info Spam-O-Matic Tagged email - klara@gamesforyou.info - Spammer Found and rejected.
2011-01-05 04:34:33 94.142.134.178 No Username Submitted jcksn239404@aim.com Spam-O-Matic Tagged ip - 94.142.134.178 - Spammer Found and rejected.
2011-01-05 04:11:03 74.55.6.210 No Username Submitted mosyessenolom@mainru.com Spam-O-Matic Tagged email - mosyessenolom@mainru.com - Spammer Found and rejected.
2011-01-05 03:54:13 89.248.174.76 No Username Submitted lypetypegrorm@peugeot-club.org Spam-O-Matic Tagged email - lypetypegrorm@peugeot-club.org - Spammer Found and rejected.
2011-01-05 03:28:19 75.126.15.76 No Username Submitted jordanmillert@gmail.com Spam-O-Matic Tagged email - jordanmillert@gmail.com - Spammer Found and rejected.
2011-01-05 03:19:18 74.55.6.210 No Username Submitted annolahog@lviv.in Spam-O-Matic Tagged email - annolahog@lviv.in - Spammer Found and rejected.
2011-01-05 03:12:34 74.63.240.58 No Username Submitted yf0bf9@tom.com Spam-O-Matic Tagged email - yf0bf9@tom.com - Spammer Found and rejected.
2011-01-05 03:10:19 91.201.66.13 No Username Submitted cialispills12@stroitel-ru.com Spam-O-Matic Tagged email - cialispills12@stroitel-ru.com - Spammer Found and rejected.
2011-01-05 03:07:12 89.248.174.76 No Username Submitted neefgooca@peugeot-club.org Spam-O-Matic Tagged email - neefgooca@peugeot-club.org - Spammer Found and rejected.
2011-01-05 02:58:26 95.26.76.180 No Username Submitted rito.c.hk.au.s.t.i.h.o.miro.vn.a1985@gmail.com Spam-O-Matic Tagged email - rito.c.hk.au.s.t.i.h.o.miro.vn.a1985@gmail.com - Spammer Found and rejected.
2011-01-05 02:42:22 74.63.240.58 No Username Submitted yf0bf9@tom.com Spam-O-Matic Tagged email - yf0bf9@tom.com - Spammer Found and rejected.
2011-01-05 02:40:56 138.199.65.167 No Username Submitted f.ranciscosaccone@gmail.com Spam-O-Matic Tagged email - f.ranciscosaccone@gmail.com - Spammer Found and rejected.
2011-01-05 02:33:32 91.210.104.45 No Username Submitted jennings.dustin000@gmail.com Spam-O-Matic Tagged email - jennings.dustin000@gmail.com - Spammer Found and rejected.
2011-01-05 02:29:30 93.182.149.38 No Username Submitted 1ovaryicdychiacle308@elfox.net Spam-O-Matic Tagged email - 1ovaryicdychiacle308@elfox.net - Spammer Found and rejected.
2011-01-05 02:22:41 89.137.74.227 No Username Submitted dorethaeskin@aol.com Spam-O-Matic Tagged email - dorethaeskin@aol.com - Spammer Found and rejected.
2011-01-05 01:46:22 78.228.210.153 DuroTureJuh vetScache@vetScache.com Passed StopForumSpam checks. Sent to vBulletin Registration System.
2011-01-05 01:46:08 78.228.210.153 No Username Submitted vetScache@vetScache.com Passed StopForumSpam checks. Sent to vBulletin Registration System.
2011-01-05 01:45:33 78.228.210.153 No Username Submitted vetScache@vetScache.com Passed StopForumSpam checks. Sent to vBulletin Registration System.
2011-01-05 01:43:06 78.162.34.233 No Username Submitted gdfgdfrd@yandex.ru Spam-O-Matic Tagged email - gdfgdfrd@yandex.ru - Spammer Found and rejected.
2011-01-05 01:40:30 91.201.66.51 No Username Submitted viagrapric06@torgoviy-dom.com Spam-O-Matic Tagged email - viagrapric06@torgoviy-dom.com - Spammer Found and rejected.
2011-01-05 01:24:44 95.69.150.115 No Username Submitted nod.upor@gmail.com Spam-O-Matic Tagged email - nod.upor@gmail.com - Spammer Found and rejected.
2011-01-05 01:21:20 74.118.194.229 No Username Submitted gi.tulho.oo@gmail.com Spam-O-Matic Tagged email - gi.tulho.oo@gmail.com - Spammer Found and rejected.
2011-01-05 01:17:42 78.162.34.233 No Username Submitted gdfgdfrd@yandex.ru Spam-O-Matic Tagged email - gdfgdfrd@yandex.ru - Spammer Found and rejected.
2011-01-05 01:16:05 138.199.65.167 No Username Submitted f.ranciscosaccone@gmail.com Spam-O-Matic Tagged email - f.ranciscosaccone@gmail.com - Spammer Found and rejected.
2011-01-05 01:14:51 109.230.221.136 No Username Submitted galepaniccia@gmail.com Spam-O-Matic Tagged email - galepaniccia@gmail.com - Spammer Found and rejected.
2011-01-05 01:14:04 91.201.66.87 No Username Submitted cex3k@lcfshop.info Spam-O-Matic Tagged ip - 91.201.66.87 - Spammer Found and rejected.
2011-01-05 01:13:32 74.55.6.210 No Username Submitted annolahog@lviv.in Spam-O-Matic Tagged email - annolahog@lviv.in - Spammer Found and rejected.
2011-01-05 01:10:46 89.248.174.76 No Username Submitted neefgooca@peugeot-club.org Spam-O-Matic Tagged email - neefgooca@peugeot-club.org - Spammer Found and rejected.
2011-01-05 01:07:25 46.17.100.203 No Username Submitted testspaaam@hotmail.com Spam-O-Matic Tagged email - testspaaam@hotmail.com - Spammer Found and rejected.
2011-01-05 00:57:35 109.236.83.187 No Username Submitted dieksaeesw@mail.ru Spam-O-Matic Tagged email - dieksaeesw@mail.ru - Spammer Found and rejected.
2011-01-05 00:54:11 203.146.15.125 No Username Submitted gerckenkoptig@gmail.com Spam-O-Matic Tagged email - gerckenkoptig@gmail.com - Spammer Found and rejected.
2011-01-05 00:41:50 188.143.232.25 No Username Submitted noadsasaphseg@gmail.com Spam-O-Matic Tagged email - noadsasaphseg@gmail.com - Spammer Found and rejected.
2011-01-05 00:29:28 93.174.93.204 No Username Submitted agreenneista@yalta.krim.ws Spam-O-Matic Tagged email - agreenneista@yalta.krim.ws - Spammer Found and rejected.
2011-01-05 00:25:59 91.218.39.40 No Username Submitted gerrtoloksr@mail.ru Spam-O-Matic Tagged email - gerrtoloksr@mail.ru - Spammer Found and rejected.
2011-01-05 00:23:01 89.248.174.76 No Username Submitted speedaabidway@mail.saratov.com Spam-O-Matic Tagged email - speedaabidway@mail.saratov.com - Spammer Found and rejected.
2011-01-05 00:22:14 74.55.6.210 No Username Submitted japeimantee@izmail.net Spam-O-Matic Tagged email - japeimantee@izmail.net - Spammer Found and rejected.
2011-01-05 00:17:39 77.254.176.176 No Username Submitted mail2012@tlen.pl Spam-O-Matic Tagged email - mail2012@tlen.pl - Spammer Found and rejected.
2011-01-05 00:15:28 109.230.221.136 No Username Submitted galepaniccia@gmail.com Spam-O-Matic Tagged email - galepaniccia@gmail.com - Spammer Found and rejected.
2011-01-05 00:13:24 121.166.82.1 No Username Submitted franky.tyson@yahoo.co.uk Spam-O-Matic Tagged email - franky.tyson@yahoo.co.uk - Spammer Found and rejected.
2011-01-05 00:12:45 211.24.188.186 No Username Submitted rex.fischeryidgj@gmail.com Spam-O-Matic Tagged email - rex.fischeryidgj@gmail.com - Spammer Found and rejected.
2011-01-05 00:12:13 64.9.173.22 No Username Submitted maggierog33@email.com Spam-O-Matic Tagged email - maggierog33@email.com - Spammer Found and rejected.
2011-01-05 00:07:18 93.182.187.126 No Username Submitted guyper34@aim.com Spam-O-Matic Tagged email - guyper34@aim.com - Spammer Found and rejected.
2011-01-04 23:51:07 109.230.220.53 No Username Submitted leczycanin3455@leczycanie.pl Spam-O-Matic Tagged email - leczycanin3455@leczycanie.pl - Spammer Found and rejected.
2011-01-04 23:51:00 60.173.11.35 No Username Submitted udtjcoss4@aol.com Spam-O-Matic Tagged email - udtjcoss4@aol.com - Spammer Found and rejected.
2011-01-04 23:49:03 93.174.93.204 No Username Submitted wamioffella@mail.saratov.com Spam-O-Matic Tagged email - wamioffella@mail.saratov.com - Spammer Found and rejected.
2011-01-04 23:38:58 87.104.185.196 No Username Submitted fista@eurourl.net Spam-O-Matic Tagged email - fista@eurourl.net - Spammer Found and rejected.
2011-01-04 23:35:19 77.92.224.110 No Username Submitted g.o.t.o.v.i.j.b.i.z@gmail.com Spam-O-Matic Tagged email - g.o.t.o.v.i.j.b.i.z@gmail.com - Spammer Found and rejected.
2011-01-04 23:09:38 95.141.39.146 No Username Submitted boropaill@mail.ru Spam-O-Matic Tagged email - boropaill@mail.ru - Spammer Found and rejected.
2011-01-04 23:06:42 91.201.66.116 No Username Submitted racheljckb@yandex.ru Spam-O-Matic Tagged email - racheljckb@yandex.ru - Spammer Found and rejected.
2011-01-04 23:03:58 94.142.133.180 No Username Submitted nikdimsik@gmail.com Spam-O-Matic Tagged email - nikdimsik@gmail.com - Spammer Found and rejected.
2011-01-04 23:02:28 93.174.93.199 No Username Submitted actignethelia@lipetsk.in Spam-O-Matic Tagged email - actignethelia@lipetsk.in - Spammer Found and rejected.
2011-01-04 23:00:16 188.163.92.94 No Username Submitted parse4000@mail.ru Spam-O-Matic Tagged email - parse4000@mail.ru - Spammer Found and rejected.
2011-01-04 22:44:07 209.102.248.129 Wekros tumeigo@gmail.com Passed StopForumSpam checks. Sent to vBulletin Registration System.
2011-01-04 22:43:27 122.192.87.152 No Username Submitted leaveplu@gmail.com Spam-O-Matic Tagged email - leaveplu@gmail.com - Spammer Found and rejected.
2011-01-04 22:43:14 209.102.248.129 OwdOr HBSBL Passed StopForumSpam checks. Sent to vBulletin Registration System.
2011-01-04 22:40:14 213.251.154.218 No Username Submitted Spam-O-Matic Tagged ip - 213.251.154.218 - Spammer Found and rejected.
2011-01-04 22:10:58 74.55.6.210 No Username Submitted japeimantee@izmail.net Spam-O-Matic Tagged email - japeimantee@izmail.net - Spammer Found and rejected.
2011-01-04 21:50:11 193.105.210.11 No Username Submitted kevacumba50@hotmail.com Spam-O-Matic Tagged email - kevacumba50@hotmail.com - Spammer Found and rejected.
2011-01-04 21:27:19 109.230.213.121 No Username Submitted ang.el.aracelistevens@gmail.com Spam-O-Matic Tagged email - ang.el.aracelistevens@gmail.com - Spammer Found and rejected.
2011-01-04 21:26:53 79.133.133.157 No Username Submitted algernoncasanovamail@gmx.com Spam-O-Matic Tagged email - algernoncasanovamail@gmx.com - Spammer Found and rejected.

danbaron
05-01-2011, 09:24
Why would you suddenly get so many?

Does it indicate that most, or all, are from the same source?

Does it indicate that someone deconstructed this forum software, wrote and distributed an entry program, and now all of the spammers know how to get in? ThinBasic recently moved from a previous forum software, correct? I guess each forum "host" has a different name, yes? I don't know what the names of this one or the old one are. The forum sponsor permits thinBasic to use its software, in return for displaying advertising?

If the forum software has suddenly been breached, then every forum which uses this forum system should be experiencing the same trouble now, yes?

It doesn't seem very smart to let everyone examine the PHP code, does it? Maybe, it is difficult to stop.

Do the spammers actually make money from their spam - does anyone actually buy the porn and Viagra? I guess people do, or the spam would be pointless. But, people can buy the stuff from all over the internet anyway, so why would they choose to use a spam site?

The whole thing is weird to me.

ErosOlmi
05-01-2011, 09:52
Dan, please do not make assumptions that can alarm other users.

Every internet system on hearth suffer of illegal intrusions attempts but this does not means that that system is insecure, it just means that someone or something (automatic applications) try to login in order to do something illegal or against that place rules.

This forum is based on the well known vBulletin system, one of the best forum software. It is not a free software but a commercial one. It is used in many thousands of forums sites with success. It is well developed and well maintained. There are very frequent updates.

So (for the moment :D ) be sure you are in a safe place driven by an honest and well documented admin (me :onthequiet: ) that does his best to maintain this place a safe place.

Ciao
Eros

John Spikowski
05-01-2011, 10:01
Do the spammers actually make money from their spam - does anyone actually buy the porn and Viagra? I guess people do,

Dan,

If a spammer sends out 1000 messages and gets one sale out of it, it's a good day. I have gotten hundreds of offers to move large sums of money to my bank account. Imagine some old person living on a fixed income that falls for this and ends up having their life saving drained from their account.

What makes the internet so great also makes it so dangerous.

Charles Pegge
05-01-2011, 10:04
I believe that most forum spamming is mindless vandalism amplified by easy access to the malware that is able to pass the visual tests.

Only a tiny tiny percentage of people on the internet engage in this disruptive activity but 1 malignant human in a million can make its presence felt in an internet population of 2 billion.

For this reason the web has to have strong "immune" systems.

Charles

ErosOlmi
05-01-2011, 20:11
Attached a mail I got from another well known commercial forum software I'm registered about this matter confirming it is currently running a wave of forum spamming.

danbaron
05-01-2011, 22:32
Hi Eros.

I wasn't alarmed, and I wasn't trying to alarm anyone else.

Even if vBulletin is breached, and spammers can get in, why should I be alarmed? To me, at most it is an irritation. They can post anything they want, how would that harm any of us? Will they post pictures that are so shocking that we will have a heart attack and drop dead? I doubt it. Are they going to send messages which will hypnotize us and cause us to send them all of our money? I doubt it.

I don't think anyone with half a brain would even think about blaming you for this. But, I do know that IT guys can become paranoid. Whenever something bad happens to "their" system, they get blamed, even if a meteor strikes the main server. In any corporation, when something bad happens, someone is going to be blamed. And that someone will be of lower rank than those doing the blaming. Maybe every IT guy has nightmares about there being a user panic - about a mob storming his house at midnight with torches and pitchforks.

On the other hand, thinBasic is not a corporation. So, I don't exactly see what the big deal is.

I admit that spam invasions anger me. And I bet they anger you, too. I asked questions, because, I was trying to understand some things, -->

1.
The nature of a particular forum system, this one being vBulletin, as you informed me.

2.
How a program can register as a human in a forum. John said it is because the spammers obtain the PHP forum code. So, I guess they must somehow write a program that can interact with, or circumvent the forum's user interface.

3.
Why spammers, spam. I found out from John and Charles, that the purpose is either to make money; or to destroy just for the pleasure of destruction, like breaking into an art museum and spray painting the art.

4.
Why there would suddenly be a giant wave of spam. Now, my guess is that a particular malware suddenly appears, and circulates, like a flu virus.


I don't understand how I can learn, if I have to censor the questions I want to ask. Being a member of this forum is not like being in the CIA - I hope.

:p

John Spikowski
05-01-2011, 22:49
I don't understand how I can learn, if I have to censor the questions I want to ask. Being a member of this forum is not like being in the CIA - I hope.

Eros is a smart, fair and generally nice guy. Where you will see a deviation is when his loyalty is challenged by the BIG GUY and he is forced to make decisions he wouldn't make for anyone else. I don't like putting Eros in this position and we all must remember, it's his Basic and forum and we are just his guest.

ErosOlmi
05-01-2011, 23:59
I admit, being an IT man for my profession, I can be a little paranoid on security both from outside the company but more from the inside. So I tend to extend my paranoia to my passion too driving this site.

But I ask you: would you spend so much time of your time in a place like this (and I can see you are a frequent visitor here) if this place would be full of garbage, bad posts, links to the worst web sites or (in the best case) links to web sites created only to drive ads? Would you continue to be here? I do not think so.

Now think for a while this site is not only a passion and a pleasure of a single but behind me there could be some people earning their salary (and maintaining other people with it) from this activity. What about if spammers or automatic bots would destroy this place posting hundred of messages or even defacing this place? What about credibility of that site? What about that salaries and the people living with them?

There are many activities that are mostly or partially internet based from commercial to humanitarian so I could go on with examples for days.

Since yesterday my log shows 167 unique try to register as new user in thinBasic community forum. So potentially 167 new fake users posting fake messages. And consider this place is just nothing or very little known. Without the new spam filter I installed yesterday I would have spent my day trying to block spammers lowering the credibility of this place to the minimum.

That said, yes, you can place any question about this phenomenon. My reply to you was mainly due to my paranoid on the subject, sorry :oops:

Ciao
Eros

danbaron
06-01-2011, 09:06
If this was my site, I would do everything I could to stop spammers. I agree that they could potentially make this forum, or any forum useless.

Because of my nature, I like to always try to understand things. I didn't understand the phenomenon of spam, either mechanically or psychologically.

I agree with John, that this is your forum, and although we may be part of it, our parts are smaller. As you realize, we wouldn't frequent this place, if we didn't approve of you.

When people communicate face to face, the chance of a misunderstanding is minimized. When people communicate by telephone, the chance of a misunderstanding is increased. When people communicate by text, the chance of a misunderstanding increases more. I think that is why we use the emoticons in our messages - to attempt to express the emotions which we otherwise would demonstrate visually and/or auditorily. In your request to me, you used the word "please", and you included two friendly emoticons. I interpreted those cues as indicating that you were not so much angry at me, but instead, were primarily nervous about this situation. And, in my last post, I wouldn't have included the remark about censoring my questions and the CIA, if I thought you would be offended by it. I think that even when people only communicate by text, they slowly over time, begin to understand each others' personalities.

Additionally, if this was my site, I would also be worried about what other trouble hackers could potentially cause. We can all imagine the possibilities, so, here I will suppress my inclination to always say whatever I am thinking, and hold my tongue. As Shakespeare wrote, "The better part of valor, is discretion.". (But, to be honest, my social discretion is not very good.)

:p

ErosOlmi
06-01-2011, 11:21
Thanks a lot.
You have always interesting/stimulating discussions and thoughts.

zak
12-06-2011, 11:52
i found this impossible to crack by automatic programs, some sites apply this method. like this forum (http://www.thenakedscientists.com/forum/)
7285