Kitz Forum

Announcements => Site Announcements => Topic started by: roseway on November 12, 2008, 11:17:27 AM

Title: Spam storm
Post by: roseway on November 12, 2008, 11:17:27 AM
In recent days the forum has been subject to something of a storm of spammers joining and attempting to post messages. We deal with these nuisances immediately we see them, and delete any spam messages which get through the net. If you do come across one of these messages, please don't give them encouragement by clicking on any links which they include, and we would appreciate it if you advise the moderators in case it's something we haven't spotted.

Many thanks.
Title: Re: Spam storm
Post by: Floydoid on November 12, 2008, 11:19:52 AM
Will do Eic.
Title: Re: Spam storm
Post by: UncleUB on November 12, 2008, 11:28:18 AM
Happy to help Eric.  :)
Title: Re: Spam storm
Post by: scottiesmum on November 12, 2008, 11:34:29 AM
 I've noticed a few, but they are dealt with so quickly  :clap2:     I haven't had chance to "report" them   ....  I'll continue to keep an eye out  :) 
Title: Re: Spam storm
Post by: kitz on November 12, 2008, 03:12:39 PM
An update on this, if anyones interested on whats going on. 


The forums stance on SPAM has not changed.

The Problem

Over the past 24 hours we've seen a huge increase in spam attempts. Mods and Admin have deleted/removed/stopped no less than 20 new accounts that have got through the normal filters.  Much of yesterday was spent adding new filters and measures.. and of course the alertness of the mods for the ones that slipped through.

Forum logs indicate that the preventative measures that we have in place has halted an additional 162 attempts in their tracks since yesterday.

Is it just this forum?

Today it has emerged that we are not the only ones, and many other technical forums are also experiencing what has been described elsewhere as a 'tidal wave' of forum spam attacks.

Much of the attacks have come from russia/latvia/ukraine and as a first stage banning IP ranges + blocks from these regions appeared to be having some success.  However, the bots are now getting cleverer and using open proxies on IP ranges 'closer to home' which is meaning more manual intervention from the Admin/Mods.
Apparently several other forums spent yesterday also IP Block banning, and the consensus is that they were playing cat and mouse trying to keep up with it.

Why its Happening

It would appear a new version of XRumer (http://en.wikipedia.org/wiki/Xrumer) has recently been released.  This program has the ability to automatically:



What happens next?

SMF (The makers of the software on which this forum runs) is alert to the problem. 
Current suggestions are to mostly do what we have already been doing, and I will be looking around later today on installing some additional mods/hacks to see if these help.

SMF developers are also looking into this to see if they can assist and make an upgrade..  but at the moment this will take investigation into the spammers methods and time to implement code for a new release.

SMF is open source, and suggestions have been made to see if any developers can make mods that would say check the stop forum spam database, but again this would need to be implemented by someone with the time and ability to do so.
Title: Re: Spam storm
Post by: Floydoid on November 12, 2008, 03:50:44 PM
Ooh er, time to batten down the hatches methinks.
Title: Re: Spam storm
Post by: UncleUB on November 12, 2008, 04:04:01 PM
 :shoot:   :spam:
Title: Re: Spam storm
Post by: Floydoid on November 12, 2008, 04:39:39 PM
Kitz, is there an option for new memberships to be approved manually by the admins... would create a bit extra work, but might be worth it.
Title: Re: Spam storm
Post by: broadstairs on November 12, 2008, 04:45:53 PM
Kitz, is there an option for new memberships to be approved manually by the admins... would create a bit extra work, but might be worth it.

Another forum (using SMF) I belong to has just had to do this to prevent spammers getting through easily, so I guess the answer is yes its possible.
Title: Re: Spam storm
Post by: mr_chris on November 12, 2008, 04:46:56 PM
Kitz, is there an option for new memberships to be approved manually by the admins... would create a bit extra work, but might be worth it.

Yes there is an option, but we want to use that as a last resort, if at all. It would stop genuine posters from being able to sign up and post immediately, which would be terrible.

So whilst it's an option, it's not really practical.
Title: Re: Spam storm
Post by: Floydoid on November 12, 2008, 04:51:27 PM
I did consider that point Chris, but if push comes to shove...
Title: Re: Spam storm
Post by: oldfogy on November 12, 2008, 08:44:56 PM
Good luck people, will also keep an open for any.

I think sometimes because we don't see it, we just don't know what really goes on behind the scenes with running and maintaining forums, so people like myself can get or give advice to others.


Thanks to all of you.
Title: Re: Spam storm
Post by: Floydoid on November 12, 2008, 08:54:42 PM
OF, I have been an admin on forums in the past, and believe me there's a lot more goes on in the background than you'd ever imagine.  It's a nightmare.
Title: Re: Spam storm
Post by: kitz on November 12, 2008, 09:12:39 PM
I'm not saying too much for obvious reason, but I did implement something different at about 4pm. Still early days yet... but refusals are racking up.

Re Admin approval - it was something discussed last night.  Its also something that SMF have suggested for smaller forums.  We've decided its probably best as a last resort due to it relies on Admin approval who may not always be around.  (Chris has a new job which means that he now cant access from work) - so that leaves me mostly.. and since theres some family stuff going on right now, it means that some days I may not be around as much. 

At least with the current situation theres normally a mod around before too long to sweep up any that get through, and/or ban before they even post.
Bearing in mind the amount we received* I think they do a damn good job, because AFAIK only 1 actually managed to get through and actually post before it was soon deleted.

So well done guys.  Eric + Dave have been very much on the ball  :thumbs:


* Now more than 200 refused attempts and/or bans placed or deleted
Title: Re: Spam storm
Post by: Yorkie on November 12, 2008, 09:25:58 PM
I realise you don't want to give too much away in an open discussion, but just as a matter of interest if I tried to sign up now would I be refused. I ask because I have a gmail email account, and I know some forums refuse these, in fact I have only be unable to register once with my email address, also I know my ISP allocates the dynamic address from a range that got inadvertently assigned to the Czech Republic before being reallocated to the UK, the VNU site always shows me as being in Czechoslovakia, I can assure you I am in chilly north Yorkshire.
Title: Re: Spam storm
Post by: oldfogy on November 12, 2008, 09:28:27 PM
My account is gmail, so seems it should not be a problem.
Title: Re: Spam storm
Post by: mr_chris on November 12, 2008, 09:30:31 PM
Don't worry ... gmail accounts can still be used for signup
Title: Re: Spam storm
Post by: dave.m on November 12, 2008, 09:30:41 PM
Yorky,
You would not have to show your passport on here to sign up, just a Yorkshire bus pass will do!  ;D
Googlemail, or webmail eg. Yahoo are fine.

Vot happens now izt zat ve fon you up unt check your aczent!  :lol:

dave
Title: Re: Spam storm
Post by: kitz on November 12, 2008, 09:31:54 PM
You'd be fine Yorkie.

btw I can quite clearly see you are in the UK.
Title: Re: Spam storm
Post by: Floydoid on November 12, 2008, 09:46:43 PM
Careful Dave, I'm a proud Yorkshireman too.
Title: Re: Spam storm
Post by: jid on November 12, 2008, 09:51:00 PM
TBH I have never seen spam on the site as you guys are always too quick for me  :clap2:

I will keep my eyes open but it looks that Kitz maybe onto something that she implemented earlier  :)
Title: Re: Spam storm
Post by: dave.m on November 12, 2008, 09:53:55 PM
Careful Dave, I'm a proud Yorkshireman too.

Me too, Mike.

I still like to see the Tykes win!

dave
Title: Re: Spam storm
Post by: Floydoid on November 12, 2008, 10:03:20 PM
I never knew that Dave.

> I still like to see the Tykes win!

That's a sore point at the moment being a Doncaster Rovers fan.
Title: Re: Spam storm
Post by: camallison on November 12, 2008, 11:19:59 PM
I'm in Latvia tomorrow/Friday/Saturday - do you want me to smack a few heads or whip 'em into shape?    :whip:

Colin
Title: Re: Spam storm
Post by: kitz on November 12, 2008, 11:48:56 PM
lol thanks for the offer Colin  ;D

Actually.. Ive been doing a bit of reading on the subject this eve and how this particular bot works.  Even though it may appear to have been originating in Latvia, that this particular bot is simply making use of open proxies.  One of the things I have noticed is that it sometimes 'moves' through countries as you block one country it will find another.... each time getting 'nearer' in the EU if you know what I mean*   I guess the .ru and similar blocks are easier to find proxies so it goes through there first.
SMF forum advice is theres not much point IP blocking as it will only find another....   although I and others have found that it does help quite a bit.  Im currently bouncing off on average at least 10-15 an hour using this method, so its at least keeping some of it at bay.

AFAIK this is the first time a bot has majorly been able to attack SMF big style, and previous bots tended to target other php forums.   Looking at SMF's first reaction yesterday, I dont think even they believed quite what was going on at first, as SMF has always had one of the best php forum reputations for security and anti-bot measures.
I suppose it was only inevitable that as SMF became more popular because of just that reputation, it was a challenge for someone just waiting to happen.  :'(



*one of the things I said to the mods yesterday before we knew the full scale of this attacks was 'persistent little git'.
Title: Re: Spam storm
Post by: UncleUB on November 13, 2008, 06:11:42 AM
Careful Dave, I'm a proud Yorkshireman too.

Well I'm a Sheffielder(thats a posh Yorkshireman)does that count. :D
Title: Re: Spam storm
Post by: Floydoid on November 13, 2008, 06:20:24 AM
As long as you were born within the traditional county boundaries of Yorkshire, it counts.
Title: Re: Spam storm
Post by: UncleUB on November 13, 2008, 09:13:20 AM
TD has just posted on forumites quiz saying he can't log on here, and his he banned because of his email address?????
Edit
He is using pop3 through virgin.net
Title: Re: Spam storm
Post by: Floydoid on November 13, 2008, 10:29:03 AM
Maybe we need a new emo:

(https://forum.kitz.co.uk/proxy.php?request=http%3A%2F%2Fimg.photobucket.com%2Falbums%2Fv250%2FFloydoid%2Fdiespam.gif&hash=15ec77b18b518b4e880b34268b1c63034a0592b0)
Title: Re: Spam storm
Post by: kitz on November 13, 2008, 11:47:04 AM
Quote
TD has just posted

No TDs not banned - Ive just checked his account, which would tell me, and also his email address is absolutely fine...  as is his range of IPs which is in the UK anyhow.

>> he can't log on here

When you say cant log on.. how far can he get?
Does he get any error messages at all?

.. if he's been caught up in any way shape or form with this - he will get a very specific message!

Title: Re: Spam storm
Post by: oldfogy on November 13, 2008, 01:12:39 PM
TD has just posted
Tell him he can join me in the NC. :-X
Title: Re: Spam storm
Post by: mr_chris on November 13, 2008, 05:33:11 PM
Just to clear up the bit about emails, Kitz hasn't implemented ANY bans on certain email addresses.

As I understand things, even if she did implement an email address ban, this would just affect new registrations only. All users who are already signed up, even if they were signed up with a newly 'banned' email address, would still be able to log in as normal.
Title: Re: Spam storm
Post by: Floydoid on November 13, 2008, 05:47:21 PM
Are disposable emails banned from registering (just curious)?
Title: Re: Spam storm
Post by: oldfogy on November 13, 2008, 05:50:13 PM
Apart from your ISP's original allocated email address, surely all others are classed as disposable?

Gmail. Hotmail, etc.
Title: Re: Spam storm
Post by: jeffbb on November 13, 2008, 06:39:22 PM
Hi
Must be affective and QUick never seen any spam ,will keep a lookout . Thanks for all your efforts .
Jeff
Title: Re: Spam storm
Post by: kitz on November 13, 2008, 06:43:44 PM
Quote
Kitz hasn't implemented ANY bans on certain email addresses.

Actually I have..  but it wont affect UK users.
Title: Re: Spam storm
Post by: kitz on November 13, 2008, 06:58:58 PM
Just to clarify....

email blocking isnt whats keeping them at bay now, and every valid user should be perfectly fine.

Its now well over 24 hours since I made some changes and although the bot attempts are still continuing - touchwood none have got through.  :fingers:

Obviously I'd be rather stupid if I said in the open forums just what measures Ive implemented, and what Ive allowed and what I havent. 
Suffice to say if you are human and you can read - you will know if youve been blocked through the anti-spam measures.
Title: Re: Spam storm
Post by: jazz on November 14, 2008, 10:19:35 AM
Things like this are a useful reminder of what a lot goes on in the background to keep this forum running smoothly.  Thank you to all involved.
Title: Re: Spam storm
Post by: dave.m on November 14, 2008, 07:00:52 PM
The Tsunami now appears to have reduced to a trickle.

Thanks, everyone for helping us with it and also for the complements.

Cheers,

Admin and Mods.  ;)
Title: Re: Spam storm
Post by: UncleUB on November 14, 2008, 07:02:37 PM
Good to hear Dave.  :)

And well done to all those involved.  :clap2:
Title: Re: Spam storm
Post by: jid on November 14, 2008, 08:58:00 PM
Good to hear Dave.  :)

And well done to all those involved.  :clap2:

ditto  :)
Title: Re: Spam storm
Post by: camallison on November 16, 2008, 11:13:40 AM
I'm in Latvia tomorrow/Friday/Saturday - do you want me to smack a few heads or whip 'em into shape?    :whip:

Colin

I asked the whole population of Latvia, and they both said they don't know anything about it.   :P   :lol:
Title: Re: Spam storm
Post by: kitz on November 19, 2008, 01:16:53 AM
Well they wouldnt would they?   :lol: :lol:
Title: Re: Spam storm
Post by: oldfogy on November 30, 2008, 10:00:04 PM
4 for more just arrived but removed with 5 minute.

Good for you pppl.
Title: Re: Spam storm
Post by: dave.m on November 30, 2008, 10:12:56 PM
Thanks Phil.

Just removed the posts and slapped a ban on her.

dave
Title: Re: Spam storm
Post by: oldfogy on November 30, 2008, 10:23:12 PM
Thanks.
Thought I would use this post as an alert knowing that "mods" would be alerted (possibly quicker)
Title: Re: Spam storm
Post by: kitz on December 01, 2008, 11:40:46 AM
ty guys.

As the mods already know - we seem to have 2 different types of spammers, the automated bot type.. and then theres those that are more 'humanoid' type spam.
Touch wood we seem to have have arrested the bot type attack that started last month.  The logs show that for the past couple of months theres been 146 pages (x15) of unsuccessful attempts. There will also be some which wont record to the log, so for the odd 1 or 2 to get through from the 'humanoids' aint too bad, I suppose..  particularly when the mods are pretty quick with their dusters :)
Title: Re: Spam storm
Post by: UncleUB on December 01, 2008, 12:04:30 PM
Nice one guys.  :)

Kitz sweeping up the spam.

(https://forum.kitz.co.uk/proxy.php?request=http%3A%2F%2Fdl6.glitter-graphics.net%2Fpub%2F595%2F595426om7plh9hpc.gif&hash=f97558bed9924e38b9827b66affaf3baa3646d33) (http://www.glitter-graphics.com)
Title: Re: Spam storm
Post by: kitz on December 01, 2008, 12:30:23 PM
naw - credit goes to Eric and Dave for most of that - since they do most of the cleaning up.

Thats why they get one of these to wear.

(https://forum.kitz.co.uk/proxy.php?request=http%3A%2F%2Fwww.kitz.co.uk%2Ftemp%2Fmods_pinny.jpg&hash=dd90c5d4fe35d7d5976dbbf5541f82b801c62c6a)
Title: Re: Spam storm
Post by: roseway on December 01, 2008, 01:57:29 PM
I look nice in my pinny :lol:
Title: Re: Spam storm
Post by: dave.m on December 01, 2008, 02:04:26 PM
I don't mind the pinny BUT I do draw the line at PINK Marigolds.  :no:
dave
Title: Re: Spam storm
Post by: jid on December 01, 2008, 03:57:39 PM
I don't mind the pinny BUT I do draw the line at PINK Marigolds.  :no:
dave
:lol:
Title: Re: Spam storm
Post by: kitz on December 01, 2008, 05:38:40 PM
I don't mind the pinny BUT I do draw the line at PINK Marigolds.  :no:
dave

Sorry dave - I was going to buy blue ones to match the pinny, but they were out of stock, so pink it had to be.


 :D
Title: Re: Spam storm
Post by: Floydoid on December 01, 2008, 07:41:27 PM
Nice one guys.  :)

Kitz sweeping up the spam.

(https://forum.kitz.co.uk/proxy.php?request=http%3A%2F%2Fdl6.glitter-graphics.net%2Fpub%2F595%2F595426om7plh9hpc.gif&hash=f97558bed9924e38b9827b66affaf3baa3646d33) (http://www.glitter-graphics.com)

Kitz feeling pleased after the spam cleaning

(https://forum.kitz.co.uk/proxy.php?request=http%3A%2F%2Fimg.photobucket.com%2Falbums%2Fv250%2FFloydoid%2Felegant.gif&hash=809f1af3a7db6105d41a61b0a9323af916bbba51)
Title: Re: Spam storm
Post by: kitz on December 01, 2008, 07:47:12 PM
 :D
Title: Re: Spam storm
Post by: oldfogy on December 01, 2008, 10:03:22 PM
My god that was a quick hair doo.
Title: Re: Spam storm
Post by: roseway on December 01, 2008, 10:37:32 PM
:lol:
Title: Re: Spam storm
Post by: UncleUB on December 02, 2008, 11:42:24 AM
Kitz and all the mods celebrating after a successful spam sweep.


(https://forum.kitz.co.uk/proxy.php?request=http%3A%2F%2Fdl2.glitter-graphics.net%2Fpub%2F748%2F748162u3u8f79xza.gif&hash=b44352f0ba5f5a0c39ae98f6c8b504004ba7653e) (http://www.glitter-graphics.com)
Title: Re: Spam storm
Post by: roseway on December 02, 2008, 11:55:51 AM
Wonderful :lol:
Title: Re: Spam storm
Post by: kitz on December 02, 2008, 12:47:05 PM
awww cute.

The blonde with the purple collar in the middle is me :)
Title: Re: Spam storm
Post by: jeffbb on December 02, 2008, 06:51:21 PM
very nice too! ;D
Title: Re: Spam storm
Post by: Imagine. on December 02, 2008, 07:32:59 PM
Hmm seems spammers are getting hi-tek now  8) Shall Imagine warm up his advanced tracking tools  ;)  >:D
Title: Re: Spam storm
Post by: oldfogy on December 02, 2008, 09:31:02 PM
See, always said these mods were a load of pussycats.
(But nice ones though) :crazy:
Title: Re: Spam storm
Post by: jabns on December 13, 2008, 09:26:51 AM
I wonder how much bandwidth this will be consuming(and CPU usage)? Was there a spike when the bots started?

I am just thinking of the costs for you because I can already imagine it won't be the cheapest of sites to host. I suppose if it got to much of a resource hog you could put a firewall in front of the site and then any IP's your homebrew bot detectors find add to a 24h blocklist.
Title: Re: Spam storm
Post by: kitz on December 13, 2008, 01:11:04 PM
Hard to say really.
no to spiking though as regards to the 'all out attack' on forums the other week, then I could imagine there was a strong possibility that some servers could have come under CPU pressure and may have caused some slow downs.

I havent noticed a spike in usage through it - the forum traffic is minor compared to the main site, so in the grand scheme of things its not made any difference to bandwidth
I also have a couple of lines of 'defence' some are logged - Those that are stopped at the first hurdle arent, but I should imagine if I could be bothered to go through the traffic logs (which Im not going to!) they will all originate from either beijing or eastern block type countries.  Theres still some that are getting to stage 2 which are logged, as an indication theres been 16 of those in the past 12 hours which have been stopped and logged.  I think you can gather from that, that I'm already using some pretty large IP blocks - which I maintain and add to myself.
Title: Re: Spam storm
Post by: jabns on December 13, 2008, 01:58:39 PM
Yeh I thought you would have had some already I was just curious as to whether these sort of attacks had any other impacts other than being annoying and time consuming.
Title: Re: Spam storm
Post by: kitz on December 13, 2008, 02:53:48 PM
>> being annoying and time consuming.

Thats about the gist of it for me (and the mods).
I could imagine it would have larger impacts on smaller sites as regards to their bandwidth though :/