Thread: Administrative and Maintenance Tools - vbStopForumSpam - known spammer lookup for new registrations
View Single Post
  #875  
Old 01-31-2010, 10:33 PM
skippybosco skippybosco is offline
 
Join Date: Sep 2007
Posts: 117
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

That IP address 192.18.8.1 is in the StopForum database only once so a frequency filter would have prevented this from registering for site admins that are more sensitive to the risk of a "false positive"

That being said, a quick Google search on 192.18.8.1 makes it very clear that IP address, while it may be registered to Sun MicroSystems, is not being used just for business purposes. Given the multiple users that appear to be posting from that IP address to various social forums, my guess was that it is a Proxy server or shell server.

Then I started looking into some of the posts:

Luzhou Guestbook Spam

Quote:
Originally Posted by tolqxkmuksg IP:192.18.8.1 2010-1-16 15:33:59
zL81L8 <a href="http://snmljcfzmtft.com/">snmljcfzmtft</a>, url=http://gzvucjsmhtut.com/]gzvucjsmhtut, =http://kuwbknfzbuwl.com/]kuwbknfzbuwl, nbyroolbkvfc.com
Korean University Forum Spam

Quote:
Originally Posted by (192.18.8.1) 2010-1-19 2:48:35 acomplia
comment6, zyprexa, viagra, phentermine blue, levitra, zyprexa 5mg, protonix pricing, buy lipitor, discount cigarette, advair diskus generic, cheap american cigarettes, exact replica watches,
Thailand Message Board Spam

Quote:
Originally Posted by ความคิดเห็นที่ 2010-01-18 16:13 from 192.18.8.1
zoloft, zyprexa, phentermine diet aid, pfizer viagra, acomplia, buy effexor, cialis, herbal replacement for plavix, klonopin, singulair, advair, rimonabant 180 pills, nexium cost, pill propecia,
Shopping Site Feedback Spam

Quote:
Originally Posted by exact replica watches 2010-01-18 10:56:20 (192.18.8.1)
reductil, buy zoloft, doxycycline online, who makes meridia in mexico, lipitor, cialis bloody nose, plavix, buy discount cialis, discount cigarette, singulair, accutane
...and the list goes on for pages.

And in case you're wondering *why* or *how* this could be happening to an IP address that is registered by Sun MicroSystems and whose employees confirm this?

That is because this is a shell server that was compromised in November 2009 and access to various "Premium Accounts" on it are being sold online to spammers, including the root account.

http://www.neararsan.org/karisik-pre...-t266276.html?

Quote:
root SUN-0E4C8F148DB 2009-05-26 16:47:26 192.18.8.1
darinjanke SUN-0E4C8F148DB 2009-05-26 16:47:26 192.18.8.1
darinjanke SUN-0E4C8F148DB 2009-05-26 16:47:26 192.18.8.1
hd226724 SUN-0E4C8F148DB 2009-05-26 16:47:25 192.18.8.1
....etc
This took roughly 2 minutes of investigation to find this using just Google

Quote:
Originally Posted by imported_skillroad
We apologized and disabled IP checking. I doubt we will turn it on again, and may consider de-installing the mod. False positive blocks are not acceptable to us. The Stop Forum Spam db is polluted.
As I said in previous posts, there is a chance that someone maliciously or accidentally enters a legitimate IP address. There are existing tools to help reduce the risk of false positive on an Admin as well as more long term things such as the reputation system that Pedigree eluded to.

That being said, it is a community of Admins. It is give and take. For the thousands of spammers that don't make it on your site (and the time you save not having to clean up their mess) we ask that you add spammers that do make it back to the database. While there are other sources of the data (honeypots, etc) If Admins deinstalled the mod every time a spammer wasn't in the database the service would shut down and the spammers will have won (oh the humanity!).

The same is true for invalid IP addresses in the database (should there be any). If an admin identifies an erroneous IP, the hope is that they should report it back to Stop Forum Spam to help clean the database up for everyone. While we're working to make that an easier process (and automated validation, etc), again the time you save NOT having to clean up thousands of spammers should more than make up for the time it takes to report a false positive.
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01778 seconds
  • Memory Usage 1,792KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (6)bbcode_quote
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete