View Full Version : Got heavily spammed today, need advice!
matthewd5
01-21-2014, 02:15 AM
Hello
Didn't check on my forum all day, I got home and logged in and there were about a dozen guests
I immediately noticed that I had almost a thousand new posts!
It was an a-z of spam ads
I immediately shut down the forums while I irradiated the spam.
It grew to the point of 30 connections at once, they were coming from four or five different providers, including amazons hosting division...
I blocked the class c address blocks of the offenders, then I turned on moderation for new people...
I don't run my own server but the server I'm on has anti spamming software setup and it's active for my forum...
I guess I'm trying to see if there is something I could have done to minimize the chance of this happening again, and wish I could go back to just doing the email verification vs the fully moderated mode.
Matthew
ozzy47
01-21-2014, 02:18 AM
You should read the post on my site, I have followed it, and so fare no spam. I know a few other sites that have been following the same thing, for quite some time, and no spam. http://ozzmodz.com/showthread.php/506-The-Era-Of-Big-Spam-Is-Over
matthewd5
01-21-2014, 02:43 AM
You should read the post on my site, I have followed it, and so fare no spam. I know a few other sites that have been following the same thing, for quite some time, and no spam. http://ozzmodz.com/showthread.php/506-The-Era-Of-Big-Spam-Is-Over
Thank you. Those sound great...being on a shared server can I still install mods like that?
Matthew
ozzy47
01-21-2014, 02:45 AM
Yes, there should be no problems running those in a shared environment, I would download the lists in that thread, and use those in the mods. :)
matthewd5
01-22-2014, 05:07 AM
You should read the post on my site, I have followed it, and so fare no spam. I know a few other sites that have been following the same thing, for quite some time, and no spam. http://ozzmodz.com/showthread.php/506-The-Era-Of-Big-Spam-Is-Over
Ok I'll have those four mods installed probably by the end of the day tomorrow...
Do I dare go back to up moderating users and just trusting the mods+the email reply system?
I hate the moderated mode because I feel that a large percentage of users will never come back...
Matthew
ozzy47
01-22-2014, 10:20 AM
I so far have not had the need to moderate users.
ForceHSS
01-22-2014, 10:52 AM
This is a good one https://vborg.vbsupport.ru/showthread.php?t=294633
ozzy47
01-22-2014, 10:56 AM
Yes that is one of the mods in the post I linked him to. :)
ForceHSS
01-22-2014, 10:58 AM
See it now what about spam o matic dont see it in your list
ozzy47
01-22-2014, 11:00 AM
I have not had a need for that mod, with the ones that are installed, there is nothing for Spam O Matic to do.
ForceHSS
01-22-2014, 11:04 AM
I use it not just for spam but to put new users into a group and after 10 posts it moves them to registered users
ozzy47
01-22-2014, 11:06 AM
True, but could you just not use the promotion system for that?
ForceHSS
01-22-2014, 11:14 AM
Yes i could but as i also use it for spammers as well no need to
matthewd5
01-27-2014, 12:04 AM
You should read the post on my site, I have followed it, and so fare no spam. I know a few other sites that have been following the same thing, for quite some time, and no spam. http://ozzmodz.com/showthread.php/506-The-Era-Of-Big-Spam-Is-Over
Hello
I had all 4 mods installed and its been about a week...
It's happening less often but spammers are still getting through, about one or two per day...can I do more, short of licking down all new members to be moderated?
It's a new online community and trying to not repel legitimate users
Matthew
ozzy47
01-27-2014, 12:07 AM
Did you use the lists in the mods that were in the thread I pointed you to?
RichieBoy67
01-27-2014, 12:10 AM
Spammers can always get through if they want to join your site and verify email manually no matter what spam protection you have.
I would not allow new members to post links and use spam o matic in addition to the other mods to help you create a new usergroup where no linking is allowed just for new members. You can use the promotion system instead if you want as Ozzy mentioned.
## If you see a few ip's spamming the hell out of you go and ban them from your server completely. There are some things you can do with your robots.txt file and your htaccess as well to help.
Not sure if it is listed on Ozzies page but I would also use a mod that is here to block Tor access. I am not sure if spammers use it at all but most hackers do so why not block them too?
--------------- Added 26 Jan 2014 at 20:11 ---------------
Did you use the lists in the mods that were in the thread I pointed you to?
Great list Ozzy! I use almost everyone of those.
I just joined your site. :)
ozzy47
01-27-2014, 12:34 AM
Yeah they are pretty extensive lists. But I personally would not ban IP's, spammers and hackers can spoof the IP's, so you may actually be blocking potential users. Also IP's can change from time to time, so todays spammer IP, can very well be tomorrows legitimate users IP.
Welcome to the site Rich. :)
Max Taxable
01-27-2014, 12:37 AM
Spammers can always get through if they want to join your site and verify email manually no matter what spam protection you have.I haven't had even one make it through in almost two years now. Not even one. And that's vs. 1000s of attempts. I've also secured three new boards in the last six months including Ozzy's, and none of those three have ever had a spammer successfully register. Ever.
This idea of "spammers can always get through" is actually, why they do.
Hello
I had all 4 mods installed and its been about a week...
It's happening less often but spammers are still getting through, about one or two per day...can I do more, short of licking down all new members to be moderated?
It's a new online community and trying to not repel legitimate users
MatthewSet your registration timer to 25 seconds. I think the default might be 15 or 20, for the timer mod recommended.
Not sure if it is listed on Ozzies page but I would also use a mod that is here to block Tor access. I am not sure if spammers use it at all but most hackers do so why not block them too?All ToR nodes are blocked, via one of the plugins recommended at OzzModz.:D
RichieBoy67
01-27-2014, 08:52 AM
I haven't had even one make it through in almost two years now. Not even one. And that's vs. 1000s of attempts. I've also secured three new boards in the last six months including Ozzy's, and none of those three have ever had a spammer successfully register. Ever.
This idea of "spammers can always get through" is actually, why they do.
I have blocked spam on many sites as well and am usually successful but it depends on the topic and the permissions on the site.Some niche topics drive spam made by site owners and not really professional spammers. In addition, when able to apply permissions that moderate posts with links or block links they rarely if ever get through but on those sites where links are allowed there is no way to stop someone if they manually create a new account, verify email, etc. Some clients want to keep those permissions open and that is an issue and a motivation.
Hopefully those get taken out by a moderator so they do not last long but can get through.
On my main site we have had spammers join the site and make 10 decent posts just to be able to get permissions to post a link. I'm not sure if these would be concidered spam but my definition is if someone joins a site just to promote something without permission that is spam. The only way to get rid of this type is spam is to wait for it to happen and delete it.
Max Taxable
01-27-2014, 04:00 PM
I have blocked spam on many sites as well and am usually successful but it depends on the topic and the permissions on the site.Some niche topics drive spam made by site owners and not really professional spammers. In addition, when able to apply permissions that moderate posts with links or block links they rarely if ever get through but on those sites where links are allowed there is no way to stop someone if they manually create a new account, verify email, etc.
Yep, there is but it is in beta and I am still trying to convince Ozzy to code it and release it as a Mod.
I have all permissions open, use NO human verification that is native, allow links in first posts, no accounts are moderated... No spam.On my main site we have had spammers join the site and make 10 decent posts just to be able to get permissions to post a link. I'm not sure if these would be concidered spam but my definition is if someone joins a site just to promote something without permission that is spam. The only way to get rid of this type is spam is to wait for it to happen and delete it.That's a function of the "gotcha" type nature of the post count requirement for posting links. Of course we have all seen this before as well.
RichieBoy67
01-27-2014, 04:08 PM
Yep, there is but it is in beta and I am still trying to convince Ozzy to code it and release it as a Mod.
I have all permissions open, use NO human verification that is native, allow links in first posts, no accounts are moderated... No spam.That's a function of the "gotcha" type nature of the post count requirement for posting links. Of course we have all seen this before as well.This was what I meant when saying we will never stop it 100% if they are willing to take the time. Sure we can stop the auto bots pretty much 100% and we can stop people from posting links at least in the beginning but if someone is determined enough they can sneak in something even if only is left there for a few minutes.
Other than an interview or moderating members I cannot imagine any way to stop this type of thing. A lie detector plug in? Does Ozzy have a lie detector plug in? haha
Max Taxable
01-27-2014, 04:12 PM
This was what I meant when saying we will never stop it 100% if they are willing to take the time. Sure we can stop the auto bots pretty much 100% and we can stop people from posting links at least in the beginning but if someone is determined enough they can sneak in something even if only is left there for a few minutes.
Other than an interview or moderating members I cannot imagine any way to stop this type of thing. A lie detector plug in? Does Ozzy have a lie detector plug in? hahaI PM'd you. Yes we can and do stop 100% of it 100% of the time. That was the premise started with, instead of the normal defeatist one.
We believe we are smarter, more creative, better looking, and just overall superior to any botnet admin, spammer supervisor, or spammer alive. This is why they are bottom feeders to start with.
Disco_Stu
01-27-2014, 09:11 PM
Hello
...can I do more, short of licking down all new members to be moderated?
Matthew
Now THAT'S what I call a typo!!!:D
RichieBoy67
01-27-2014, 10:24 PM
Now THAT'S what I call a typo!!!:D
Yeah, I would not suggest it unless maybe your forum is for the Victoria secret models. :)
I PM'd you. Yes we can and do stop 100% of it 100% of the time. That was the premise started with, instead of the normal defeatist one.
We believe we are smarter, more creative, better looking, and just overall superior to any botnet admin, spammer supervisor, or spammer alive. This is why they are bottom feeders to start with.Good talk! No more defeatism from me. :up: And we always have to do what we can by reporting spammers, spammer ips, domains, etc.
vbresults
01-27-2014, 11:15 PM
<a href="https://vborg.vbsupport.ru/showthread.php?t=289463" target="_blank">https://vborg.vbsupport.ru/showthread.php?t=289463</a>
ozzy47
01-27-2014, 11:25 PM
Kevin's version is better in My opinion of the above mod. Which is why it is in the thread I linked to.
Max Taxable
01-27-2014, 11:28 PM
Kevin's version is better in My opinion of the above mod. Which is why it is in the thread I linked to.I could have had that spam in my signature here, for a fee!:D
matthewd5
01-28-2014, 03:27 PM
Did you use the lists in the mods that were in the thread I pointed you to?
Hello.
Things are a little bit better, 2 hours ago I had 90 spammers connected, but none were able to. Login and post anything.
I had my hosting provider install the 4 recommended mods
The spider blocking one definitely has the long list of known bad spiders, that's the good news, when I activate it everything goes off the deep end, and my screen goes black with a long error code scrolling repeatedly...
https://vborg.vbsupport.ru/external/2014/01/6.jpg
If someone can help me figure out this one I sure would appreciate it...
I think I need someone more knowledgable about these mods to login to my system and check the settings.
Matthew
ozzy47
01-28-2014, 03:38 PM
If you want pm me a admin account and I can look into it when I get home. Also which mod is it that is causing the errors.
vbresults
01-28-2014, 05:03 PM
Kevin's version is better in My opinion of the above mod. Which is why it is in the thread I linked to.
The mod I linked to is better hands down. Rather than us going back and forth, the OP can try that 1 mod for themselves. No reason to run 4 impotent mods when he can run a simpler single, more effective mod.
With the mod I linked to he doesn't need to upload any files or rename anything, or even deal with their host -- it's nothing more than a simple XML import. I suspect the reason you didn't link to it has nothing to do with the actual plugin itself.
Look at this:
...when I activate it everything goes off the deep end, and my screen goes black with a long error code scrolling repeatedly...
https://vborg.vbsupport.ru/external/2014/01/6.jpg
... Matthew
matthewd5
01-28-2014, 06:23 PM
Spammers can always get through if they want to join your site and verify email manually no matter what spam protection you have.
I would not allow new members to post links and use spam o matic in addition to the other mods to help you create a new usergroup where no linking is allowed just for new members. You can use the promotion system instead if you want as Ozzy mentioned.
## If you see a few ip's spamming the hell out of you go and ban them from your server completely. There are some things you can do with your robots.txt file and your htaccess as well to help.
Not sure if it is listed on Ozzies page but I would also use a mod that is here to block Tor access. I am not sure if spammers use it at all but most hackers do so why not block them too?
--------------- Added 26 Jan 2014 at 20:11 ---------------
Great list Ozzy! I use almost everyone of those.
I just joined your site. :)
Thanks for your reply, I don't know what Tor is?
Matthew
cellarius
01-28-2014, 08:24 PM
<a href="http://lmgtfy.com/?q=tor" target="_blank">http://lmgtfy.com/?q=tor</a>
Right at the top.
ozzy47
01-28-2014, 09:33 PM
Errors on the site have been sorted, it was a setting that was entered wrong. :)
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.