A A A A
Mail.ru, ukr.net and Yandex.com email accounts banned
 
LinkBack Thread Tools Search this Thread
Old 5th January 2011   #1
Velociodonor
 
Velocio's Avatar
Mail.ru, ukr.net and Yandex.com email accounts banned

Yesterday around 20 accounts were opened with mail.ru or yandex.com addresses. All appear to be accounts set up to spam the site.

Thankfully things like the nursery period prevented the site from becoming awash with spam. Anyone curious as to how LFGSS might look if these defences were not in place need only look at the test forum where they are in fact not enabled:
General - LFGSS
. The place is awash with spam, not that it bothers me as I'll delete it once I'm done.

Anyhow... to preclude the possibility of those accounts being used to get past the defences that I've put in place, I'm simply going to ban mail.ru and yandex.com accounts across the entire site. I feel that this is OK as being a London, UK focused site I can have a reasonable level of certainty that a majority of our users aren't from Russia.

However, if you happen to be someone who legitimately has an email address from one of those providers, you will need to let me know your username and the email address for that username... at which point if you also give me a new email address I can change it for you (you won't be able to change your own email address due to being banned).

The easiest way to do this is to email me at david@lfgss.com from your existing mail.ru account and to let me know of the new email address I should use. This would verify that you have access to the mail.ru account, so I will happily update your LFGSS account.

Cheers

David
  quote   reply
Old 5th January 2011   #2
Velociodonor
 
Velocio's Avatar
Oh, and since it appears there were also some fake gmail accounts registered yesterday... please be on the ball about reporting any spam that does get through so that I can nuke it swiftly.
  quote   reply
Old 5th January 2011   #3
ChainBreakerdonor
 
ChainBreaker's Avatar
It will be my pleasure :-)

To the nursery!
  quote   reply
Old 5th January 2011   #4
Velociodonor
 
Velocio's Avatar
Just added ukr.net to the ban list.
  quote   reply
Old 6th January 2011   #5
Velociodonor
 
Velocio's Avatar
The amount of spammers who are registering at the moment may lead me to temporarily disable registration.

Currently 1 in 10 new members is a real person, the other 9 are spam accounts.
  quote   reply
Old 6th January 2011   #6
TheBrick(Tommy)
 
TheBrick(Tommy)'s Avatar
Quote:
...the other 9 are spam accounts.
What is the normal ratio of span to good?
  quote   reply
Old 6th January 2011   #7
andy.wdonor
 
andy.w's Avatar
Does this have anything to do with the Bot attack type thing just before christmas?
  quote   reply
Old 6th January 2011   #8
Velociodonor
 
Velocio's Avatar
Quote:
Originally Posted by TheBrick(Tommy) View Post
What is the normal ratio of span to good?
Normally on LFGSS it's more like 50 people to 1 spammer.
  quote   reply
Old 6th January 2011   #9
Velociodonor
 
Velocio's Avatar
Quote:
Originally Posted by andy.w View Post
Does this have anything to do with the Bot attack type thing just before christmas?
There was a bot attack?

I think it's unrelated... I just think Russian spammers have started the new year with a new found vigour and have changed their targets slightly, which now includes us.
  quote   reply
Old 6th January 2011   #11
andy.wdonor
 
andy.w's Avatar
I don't understand these things so it could have been you computer literate types being funny?
  quote   reply
Old 6th January 2011   #12
Velociodonor
 
Velocio's Avatar
Well, at least the forum servers survived ;) Not much of an attack I guess.
  quote   reply
Old 6th January 2011   #13
Foxdonor
 
Fox's Avatar
Quote:
Originally Posted by Velocio View Post
The amount of spammers who are registering at the moment may lead me to temporarily disable registration.

Currently 1 in 10 new members is a real person, the other 9 are spam accounts.
Wow. Does the sign up process not involve some kind of captcha test? It's been a while.
  quote   reply
Old 6th January 2011   #14
Velociodonor
 
Velocio's Avatar
It does. But they're actually using real people to register accounts. The IP addresses are all from Russia, Ukraine and Belize. I'm half considering bocking those country ip addresses since as we are a localised website this shouldn't impact any of our reals users. Seems a bit drastic though.
  quote   reply
Old 6th January 2011   #15
Señor Bear
 
Señor Bear's Avatar
Not drastic at all.

Ban the Ruskies!
  quote   reply
Old 6th January 2011   #16
eyebrowsdonor
 
eyebrows's Avatar
there's scorch though, he's from Ukraine.
I'm sure he'd be a bit miffed.
  quote   reply
Old 6th January 2011   #17
Multi Groovesdonor
 
Multi Grooves's Avatar
YES the day has finally come! Can we kick a few other herberts that slipped through the net off, too?

Poll?
  quote   reply
Old 6th January 2011   #18
TheBrick(Tommy)
 
TheBrick(Tommy)'s Avatar
1. Multi Grooves
  quote   reply
Old 6th January 2011   #19
36x18donor
 
36x18's Avatar
The test site looks shite....



Last edited by 36x18; 6th January 2011 at 19:02. Reason: (I mean what they've done to it. Not the site itself. Ha)
  quote   reply
Old 6th January 2011   #20
Velociodonor
 
Velocio's Avatar
I'm going to block:
Belize
Kazakstan
Russian Federation
Ukraine

If scorch is blocked and contacts anyone... get him to visit www.whatismyip.com and have that emailed to me, I will exclude his ISP from the block.
  quote   reply
Old 6th January 2011   #21
cleftydonor
 
clefty's Avatar
you (or someone) should PM Scorch at least VB - his only contact with most people on here is through the forum - which if he can't get to anymore..
  quote   reply
Old 6th January 2011   #22
Velociodonor
 
Velocio's Avatar
Will do... I'll email him now.

Cheers
  quote   reply
Old 6th January 2011   #23
Velociodonor
 
Velocio's Avatar
His last IP was a USA one ;)
  quote   reply
Old 6th January 2011   #24
Velociodonor
 
Velocio's Avatar
Emailed and PM'd... the block is now in place.
  quote   reply
Old 6th January 2011   #25
Velociodonor
 
Velocio's Avatar
IP addresses for country blocks are being supplied by: http://www.countryipblocks.net/

And anyone interested in my block script, I've attached the Varnish VCL ACL.
Attached Files
File Type: txt vclacl.txt (138.1 KB)
  quote   reply
Old 6th January 2011   #26
villa-ru
 
villa-ru's Avatar
Now I really fancy one of those .ru suffixes.
  quote   reply
Old 6th January 2011   #27
Velociodonor
 
Velocio's Avatar
More anti-spam than racist.

It's these last few days... every minute on average another spam attack occurs, every 10 to 15 minutes another spammer registers. It's incredible.

I'll probably unblock the countries in time, but to stem the current attack I can't see what else to do.
  quote   reply
Old 6th January 2011   #28
TheBrick(Tommy)
 
TheBrick(Tommy)'s Avatar
Something on pm in a min about spam levels have dropped recently!?! Maybe this is part of a coordinated backlash, or maybe it is only in referencing to email spam.
  quote   reply
Old 6th January 2011   #29
Velociodonor
 
Velocio's Avatar
I'm seeing 2 types of spam:
1) Fake profiles being registered by real people in the countries mentioned above.
2) Those profiles being user by botnets to try and post spam on the site.

The profiles were just about under control manually, but the botnet attacks were evolving. They hadn't figured out the nursery fully, and we are using Akismet too... but most were trying to start new threads which obviously was failing.

I've never seen such a high level of spam, but this is targeted at a website and not email stuff.
  quote   reply
Old 6th January 2011   #30
Velociodonor
 
Velocio's Avatar
scorch is taken care of, his ISP has been unblocked.
  quote   reply
Old 6th January 2011   #31
Velociodonor
 
Velocio's Avatar
This country block thing appears to be working... sure it's only 30 minutes, but alerts about the bot net, and spam registrations have all ceased.

Here's hoping it does actually work and this isn't just some strange silence.
  quote   reply
Old 6th January 2011   #32
andy.wdonor
 
andy.w's Avatar
  quote   reply
Old 6th January 2011   #33
sumo
 
sumo's Avatar
wow, that test LFGSS site is like a petri dish for the internet
  quote   reply
Old 6th January 2011   #34
wibble
 
wibble's Avatar
now that this forum is a target for masses of spambots, does that mean we've arrived on the internet?
  quote   reply
Old 6th January 2011   #35
n3il
 
n3il's Avatar
It means the bubble is about to burst...
  quote   reply
Old 6th January 2011   #36
wibble
 
wibble's Avatar
Quote:
Originally Posted by sumo View Post
wow, that test LFGSS site is like a petri dish for the internet
//Showing threads 1 to 25 of 6723//

Some threads on the first page a have 3+ pages of posts as well..

How long has that one been going VB?
  quote   reply
Old 6th January 2011   #37
Diggerdonor
 
Digger's Avatar
I feel safe and warm and protected, Well Done VB!
  quote   reply
Old 6th January 2011   #38
wiganwill
 
wiganwill's Avatar
LFGSS: It's all about the ride
Attached Thumbnails
screenshot-1.png  
  quote   reply
Old 6th January 2011   #39
coppiThat
 
coppiThat's Avatar
after dipping into the general pool i feel a bit stained.
  quote   reply
Old 6th January 2011   #40
Velociodonor
 
Velocio's Avatar
Quote:
Originally Posted by wibble View Post
//Showing threads 1 to 25 of 6723//

Some threads on the first page a have 3+ pages of posts as well..

How long has that one been going VB?
Oh, since just before the Bike Show... so, September?
  quote   reply
Old 6th January 2011   #41
wibble
 
wibble's Avatar
so over 1,000 new threads per month just from spammers?
  quote   reply
Old 6th January 2011   #42
eyebrowsdonor
 
eyebrows's Avatar
some pretty good avatar action going on there though.
  quote   reply
Old 7th January 2011   #43
sumo
 
sumo's Avatar
Quote:
Originally Posted by soperRiva View Post
some pretty good avatar action going on there though.
yeah, it's like they expect you to look at the avatar and think "a computer can't have done this, it must be a genuine post" then read through 50 lines of random words.
  quote   reply
Old 7th January 2011   #44
Velociodonor
 
Velocio's Avatar
I"m wrong, blocking countries hasn't worked.

They're now using proxies in Belarus, Luxeumbourg and Denmark, and I'm pretty certain if I blocked those that they would switch to proxies in the USA.

So country banning helped, but hasn't solved it.

I have discovered from several admin forums that this is a very large problem that only appeared in the last 48/72 hours. So it's nice to know it's not just us. They've also shared that there are some solutions that are working better than others, and one of them is a system that spots spammers across multiple sites during registration and blocks registration if identified.

Basically it's a system in which all forum admins bang their heads together to try and stop the spammers and it apparently works pretty well.

So... as of tomorrow morning I'm going to try adding code to do that. It will be a change in the T&C's of the site, in that during registration *ONLY* your IP address and some other metadata about you will be looked up in a database held elsewhere to determine whether you are on a spam blacklist. After registration, this never happens, so it's a one-off thing for new members that we check whether they look like an obvious spammer.
  quote   reply
Old 7th January 2011   #45
Velociodonor
 
Velocio's Avatar
For kicks I'll install this on the test forum too to see just how effective it is.
  quote   reply
Old 7th January 2011   #46
wibble
 
wibble's Avatar
to go to such lengths to do it, spamming must be an enormously profitable endeavour.
  quote   reply
Old 7th January 2011   #47
hippy
 
hippy's Avatar
Quote:
Originally Posted by Tiswas View Post
How about using captchas during registration? Are they (cost) effective?
They're free to implement (well, VB's time). They can be got around but it should slow them down a bit. Like bike locks..
  quote   reply
Old 7th January 2011   #48
TheBrick(Tommy)
 
TheBrick(Tommy)'s Avatar
spammers just employ people to sit there doing captchas, not that they are useless but as Hippy says easy to get round with cheap / slave labour.

Velocio what extra feature do you have on this site to the test site such that the test site is receiving more spam? Do you have a function turned off on the B.B forum or is it an extra bolt on you have on the main forum?
  quote   reply
Old 7th January 2011   #49
hippy
 
hippy's Avatar
Just stop letting people register, delete anyone with a user id above 1000. Make the whole thing private. Job done.
  quote   reply
Old 7th January 2011   #50
EEIdonor
 
EEI's Avatar
Quote:
Originally Posted by soperRiva View Post
there's scorch though, he's from Ukraine.
I'm sure he'd be a bit miffed.

+1
  quote   reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads
Thread Thread Starter Forum Replies Last Post
Blue Hair Net 31t®um Miscellaneous & Meaningless 20 17th November 2009 01:57
Offered: Net Gear wireless modem? dayno Components, clothing and miscellany 13 3rd September 2009 18:54
ping.chartbeat.net? willo Miscellaneous & Meaningless 3 14th August 2009 14:02
Behance.net anyone? matt (baddesigner) Miscellaneous & Meaningless 7 5th November 2008 12:26
Net at Home dogsballs Miscellaneous & Meaningless 55 3rd April 2008 14:50

All times are GMT. The time now is 14:46.
Creative Commons License, BY-SA v2.0
no new posts