DF-21 Forums Forum Index DF-21 Forums
The Dark Forces Community
 
DF-21.net Home | FAQ | Search | Memberlist  | Register 
Profile | Log in to check your private messages | Log in

Spambots
Goto page 1, 2  Next
 
Post new topic   Reply to topic    DF-21 Forums Forum Index -> Feedback
View previous topic :: View next topic  
Author Message
Mattias Welander
Trandoshan

Joined: 27 Sep 2003

PostPosted: Sep 17, 2004 16:23    Post subject: Spambots View user's profile Send private message Send e-mail Reply with quote

During the last two days, at least two spambots have registered with the board. Fortunately, I have not yet seen any of them posting, but that might just be a matter of time (or the administrators might have removed already posted spam).

I'm curious what about what the administrators are currently doing about this situation, and what they plan to do in the future?

Matt K
Dark Trooper Phase 1

Joined: 27 Sep 2003

PostPosted: Sep 17, 2004 18:27    Post subject: View user's profile Send private message Send e-mail Reply with quote

I quickly checked the last page of the member list and found two more with little effort. Just look at their website URLs.

I don't have the power to ban these guys, but the Phase 2s do.

Jedi Cheddar
Gamorrean

Joined: 13 Sep 2004

PostPosted: Sep 17, 2004 21:14    Post subject: View user's profile Send private message Send e-mail Reply with quote

Are spambots those people that just go around posting aimlessly for no appearent reason?

_________________
It's good to be a little cheesy...

Mattias Welander
Trandoshan

Joined: 27 Sep 2003

PostPosted: Sep 17, 2004 21:40    Post subject: View user's profile Send private message Send e-mail Reply with quote

No, they are those programs that are preparing to take over our nice forum and fill it with advertisments for stupid products.

Scape Goat
Dark Trooper Phase 2

Joined: 23 Sep 2003

PostPosted: Sep 18, 2004 15:14    Post subject: View user's profile Send private message Reply with quote

Never saw any advertisements, but someone else might have cleared them.

Mattias Welander
Trandoshan

Joined: 27 Sep 2003

PostPosted: Sep 18, 2004 17:11    Post subject: View user's profile Send private message Send e-mail Reply with quote

I suspect they're just preparing for that at the moment, by registering as many users as they can... once they think they have enough, they might start spamming the board itself. The idea then would be to register so many users that a manual removal of them will miss a few.

Scape Goat
Dark Trooper Phase 2

Joined: 23 Sep 2003

PostPosted: Sep 19, 2004 16:30    Post subject: View user's profile Send private message Reply with quote

OK, I see what's going on now. I'll keep an eye on things and delete anything that needs to be.

Nottheking
Kell Dragon

Joined: 29 Sep 2003

PostPosted: Sep 20, 2004 14:09    Post subject: View user's profile Send private message Reply with quote

I didn't notice any spambots yet... Then again, I rarely look at the whole list of registered memebers... Perhaps a method of security should be implemented to prevent them from registering? (such as a image-reading confirmation such as Yahoo uses, or perhaps a Flash section, which as far as I know, a bot cannot use)

_________________
Wake up, George Lucas... The Matrix has you..

Mattias Welander
Trandoshan

Joined: 27 Sep 2003

PostPosted: Sep 20, 2004 15:19    Post subject: View user's profile Send private message Send e-mail Reply with quote

I think something as simple as a custom email verification process would do the trick. It is highly doubtful the bot authors would write customized software just for spamming DF-21.

Nottheking
Kell Dragon

Joined: 29 Sep 2003

PostPosted: Sep 20, 2004 16:10    Post subject: View user's profile Send private message Reply with quote

Mattias Welander wrote:
I think something as simple as a custom email verification process would do the trick. It is highly doubtful the bot authors would write customized software just for spamming DF-21.


I agree that that would work, and would also be a better idea than mine. Didn't the previous forum program use E-mail verification for registration?

_________________
Wake up, George Lucas... The Matrix has you..

Mattias Welander
Trandoshan

Joined: 27 Sep 2003

PostPosted: Sep 24, 2004 11:06    Post subject: View user's profile Send private message Send e-mail Reply with quote

The spambots are still flowing in unhindered, about one new every day. I would strongly urge the administrators to put up some kind of defence against them really soon now, before the situation gets out of hand.

Nottheking
Kell Dragon

Joined: 29 Sep 2003

PostPosted: Sep 24, 2004 14:19    Post subject: View user's profile Send private message Reply with quote

Apparently, four new ones have just registered today...

_________________
Wake up, George Lucas... The Matrix has you..

Mattias Welander
Trandoshan

Joined: 27 Sep 2003

PostPosted: Sep 24, 2004 14:45    Post subject: View user's profile Send private message Send e-mail Reply with quote

Hm... that's even more than I had noticed... which I think is exactly what they hoped for.

Nottheking
Kell Dragon

Joined: 29 Sep 2003

PostPosted: Sep 24, 2004 16:09    Post subject: View user's profile Send private message Reply with quote

Let's see the list of spam-bots:

Obvious Spambots:
  • and408
  • and567
  • riso12
  • are546

Likely/potential spambots:
  • Aufroy80 (moderately likely)
  • AXOX (somewhat potential)

The others on the list don't seem to be illegitimate at all, though.

_________________
Wake up, George Lucas... The Matrix has you..

Mattias Welander
Trandoshan

Joined: 27 Sep 2003

PostPosted: Sep 24, 2004 16:27    Post subject: View user's profile Send private message Send e-mail Reply with quote

I believe several I've noticed before have been removed. Also, a possible strategy they might be using is to register both obvious and non-obvious spambots, hoping the administrators will focus their attention on the obvious ones, thus leaving the non-obvious in the system so they're there the day they start to talk.

Scape Goat
Dark Trooper Phase 2

Joined: 23 Sep 2003

PostPosted: Sep 24, 2004 19:39    Post subject: View user's profile Send private message Reply with quote

Yeah, I've deleted a few over the past few days or so. E-mail confirmation is now turned on. We'll see how that works out.

Mattias Welander
Trandoshan

Joined: 27 Sep 2003

PostPosted: Sep 25, 2004 18:11    Post subject: View user's profile Send private message Send e-mail Reply with quote

I fear we must conclude by now that the current implementation of email confirmation does not succeed in stopping the spambots. Unfortunately, without knowing how it is implemented, I don't know where the weak point is.

Scape Goat
Dark Trooper Phase 2

Joined: 23 Sep 2003

PostPosted: Sep 26, 2004 14:19    Post subject: View user's profile Send private message Reply with quote

They can still register, but they shouldn't be able to post unless they activate their account via e-mail.

japh
Gamorrean

Joined: 30 Sep 2003

PostPosted: Sep 27, 2004 22:59    Post subject: View user's profile Send private message Reply with quote

Nice.

I have heard that phpbb is full of holes, though. Beware.

Mattias Welander
Trandoshan

Joined: 27 Sep 2003

PostPosted: Nov 16, 2004 16:39    Post subject: View user's profile Send private message Send e-mail Reply with quote

One of the spambots on another phpBB message board I frequent just activated, and started posting. As I suspect there aren't that many different spambot owners out there, chances are our spybots will activate soon, too. Keep your eyes open!

Nottheking
Kell Dragon

Joined: 29 Sep 2003

PostPosted: Nov 16, 2004 17:37    Post subject: View user's profile Send private message Reply with quote

Mattias Welander wrote:
One of the spambots on another phpBB message board I frequent just activated, and started posting. As I suspect there aren't that many different spambot owners out there, chances are our spybots will activate soon, too. Keep your eyes open!


I'm still suspicious about Aufroy80 and AXOX. I guess we'll find out if my suspicions were well founded...

_________________
Wake up, George Lucas... The Matrix has you..

Jackson
Dark Trooper Phase 2

Joined: 24 Sep 2003

PostPosted: Nov 16, 2004 21:08    Post subject: View user's profile Send private message Send e-mail Reply with quote

Don't worry, I'm personally keeping my eyes peeled.
If any spambots activate, I'll either defenestrate them or delete their accounts to control the damage.

japh
Gamorrean

Joined: 30 Sep 2003

PostPosted: Nov 29, 2004 23:18    Post subject: View user's profile Send private message Reply with quote

japh wrote:
Nice.

I have heard that phpbb is full of holes, though. Beware.



On that note: http://www.itlab.musc.edu/itlab/updates/Exploit_Explained.html

Fenwar
Admiral Ackbar
Admiral Ackbar

Joined: 15 Sep 2003

PostPosted: Nov 30, 2004 09:45    Post subject: View user's profile Send private message Reply with quote

japh wrote:
japh wrote:
Nice.

I have heard that phpbb is full of holes, though. Beware.



On that note: http://www.itlab.musc.edu/itlab/updates/Exploit_Explained.html



Patched. Thanks for bringing that to my attention Smile

Guest




PostPosted: Nov 03, 2006 00:59    Post subject: Reply with quote

Hi! I'm a spambot. Please force me to die in a fire.

(Matt K approves this fiery death)

Darth Oosha
Trandoshan

Joined: 24 Sep 2003

PostPosted: Nov 03, 2006 01:03    Post subject: View user's profile Send private message Reply with quote

...Did it think we were calling for it?

The MAZZTer
Death Star
Death Star

Joined: 25 Sep 2003

PostPosted: Nov 03, 2006 14:13    Post subject: View user's profile Send private message Send e-mail Reply with quote

I recommend someone go into the phpBB registration system code and tweak it just enough so that automatic registration is no longer possible (IE changing the username input tag name value would be enough).

_________________
http://www.mzzt.net/ | I am a respectable admin with a respectable sig.

NathanWilson
Dark Trooper Phase 1

Joined: 22 Sep 2003

PostPosted: Nov 07, 2006 06:16    Post subject: View user's profile Send private message Reply with quote

Well, somebody has been bringing threads to my attention, and although I no longer remember any of the back-end addresses for admin stuff, I've deleted threads when I have seen them. Not remembering the stuff to ban users doesn't really matter as I'm no longer a Phase 2; likely a good choice given my rather long absence.

(Yes, I'm still around, vaguely).

Darth Oosha
Trandoshan

Joined: 24 Sep 2003

PostPosted: Nov 29, 2006 18:05    Post subject: View user's profile Send private message Reply with quote

Obvious Spambots:Likely/potential spambots:
I'm ignoring accounts with no profile info, based on the assumption that there's no way to tell with them. Also, I should probably stop clicking their "www" links to confirm their botness, since that just tells them that registering on DF-21 will increase their site hits.

Jackson
Dark Trooper Phase 2

Joined: 24 Sep 2003

PostPosted: Nov 29, 2006 23:22    Post subject: View user's profile Send private message Send e-mail Reply with quote

The ones you listed I've taken care of now.
I've been leaving Cal72521 alone because, although he hasn't before, his website seems legitimate enough.

Display posts from previous:   
Post new topic   Reply to topic    DF-21 Forums Forum Index -> Feedback All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group