I have recently been getting spammers that are somehow able to send PM's to other users BEFORE the accounts of the spammers are active and while they are still in the "Users awaiting email confirmation" usergroup. I have double checked to make sure that PM's are disabled for that usergroup. The spam users do not belong to any other secondary usergroups. Moreover, they are able to send to many users at one time even though I have that disabled as well.
The message usually says something like "Hello friend..." then includes a link to a site that tries to load a virus on your machine. I can't figure out how they are able to send these PM's. Once we are aware of the spammer, we delete all PM's sent by the user and then nuke the account. At NO TIME was their account ever active though.
I use the image verification. It is worthless. The spammers go right past it with no problems at all. I also have multiple questions they are required to answer, but that does not come into play until AFTER they have clicked the link in the confirmation email and their accounts are waiting for final moderation. They are spamming me before they get to that step.
--------------- Added [DATE]1263507927[/DATE] at [TIME]1263507927[/TIME] ---------------
Figured it out.
I forgot that after the users click the confirmation link in the email, they change usergroup again to "(Coppa) Users awaiting confirmation". It was while they were in this step, but before we scanned the list of new accounts, that they were able to send out PM's. I did not realize that this one usergroup did not have the PM's disabled... DOH! It is now disabled and hopefully that will stop this particular form of spam.
These spammers are relentless. I regularly delete 5-7 spam accounts every single day.
|