Omnimaga

Omnimaga => Site Feedback and Questions => Topic started by: DJ Omnimaga on November 16, 2012, 05:32:29 pm

Title: Extreme spambot rush last night
Post by: DJ Omnimaga on November 16, 2012, 05:32:29 pm
Hmm Netham45, do you know if any of your anti-spams were down last night? Because there were like 100+ new registrations and an unusual amount of spam posts. Normally since the new anti-spam measures last Spring there are only 2-4 registrations a day... O.O

TI-Freakware was hit as well it seems, but I'm unsure if they use the same anti-spam.
Title: Re: Extreme spambot rush last night
Post by: Eeems on November 16, 2012, 05:38:18 pm
If it was down our site would be down. You go through cloudflare to get to Omnimaga itself. Cloudflare has pretty much no downtime at all.
It must just be a new set of bots out there that found our site and have not been blocked by cloudflare yet. The ones I looked at don't even have an ip address apparently x.x
Title: Re: Extreme spambot rush last night
Post by: Netham45 on November 16, 2012, 05:39:40 pm
All the anti-spam should have been up, I'm not sure what was up with all the spambots.
Title: Re: Extreme spambot rush last night
Post by: DJ Omnimaga on November 16, 2012, 05:43:03 pm
Actually Eeems if it's StopForumSpam that is down the site will still work. It will simply let you register anyway regardless of if you are a bot or not (unless you changed it to set members on approval)
Title: Re: Extreme spambot rush last night
Post by: Eeems on November 16, 2012, 05:47:15 pm
Quote
Actually Eeems if it's StopForumSpam that is down the site will still work. It will simply let you register anyway regardless of if you are a bot or not (unless you changed it to set members on approval)
I wasn't talking about StopForumSpam, I was talking about CloudFlare which blocks a lot more then StopForumSpam does.
Title: Re: Extreme spambot rush last night
Post by: DJ Omnimaga on November 16, 2012, 05:51:40 pm
Yeah I know, I was just saying since Omnimaga has 3 different anti-spams :P (including those two and also the registration questions)
Title: Re: Extreme spambot rush last night
Post by: DJ Omnimaga on November 19, 2012, 02:58:00 am
In the admin CP, could you check the Stop Spam settings and see if there's a small red warning saying it can't connect to SFS or something similar? I had this happen once on 1and1 due to server misconfiguration and it would basically let anyone in due to being unable to check their IP/e-mail. If that's the case, then maybe that could explain the recent wave of bots.

Otherwise, maybe it's time to bring back the infamous old board anti-spam? D: It worked perfectly on the old board, but it was annoying and put us at risk of deterring some impatient users from finalizing their registration (plus as seen in the screenshot below, some people don't know how to read):
Title: Re: Extreme spambot rush last night
Post by: aeTIos on November 19, 2012, 04:57:08 am
Well we could also make an extra anti-spam filter just like revsoft's. (linking calcs with manufacturers)
Title: Re: Extreme spambot rush last night
Post by: TIfanx1999 on November 19, 2012, 07:10:03 am
@DJ: Oh wow, I remember that. It actually did seem to be fairly effective too.
Title: Re: Extreme spambot rush last night
Post by: flyingfisch on November 19, 2012, 07:44:29 am
Hmm Netham45, do you know if any of your anti-spams were down last night? Because there were like 100+ new registrations and an unusual amount of spam posts. Normally since the new anti-spam measures last Spring there are only 2-4 registrations a day... O.O

TI-Freakware was hit as well it seems, but I'm unsure if they use the same anti-spam.

Don't know if its related, but UCF has been hit by quite a few bots recently too.
Title: Re: Extreme spambot rush last night
Post by: Jim Bauwens on November 19, 2012, 08:34:53 am
Maybe it was because Slashdot linked to us?
Title: Re: Extreme spambot rush last night
Post by: Eeems on November 19, 2012, 11:05:23 am
I'm pretty sure its because of slashdot.
We are connected to stopforumspam.com so that is not the issue. We just have a lot more traffic then normal from new bots.
Title: Re: Extreme spambot rush last night
Post by: shmibs on November 19, 2012, 11:59:06 am
Well we could also make an extra anti-spam filter just like revsoft's. (linking calcs with manufacturers)

making things too difficult for new people to register isn't a good idea, but maybe something similar, to that effect, could help.
Title: Re: Extreme spambot rush last night
Post by: DJ Omnimaga on November 19, 2012, 01:07:21 pm
I'm pretty sure its because of slashdot.
We are connected to stopforumspam.com so that is not the issue. We just have a lot more traffic then normal from new bots.

Nah, because the spam influx started the night before Omni got Slashdotted. Netham45 last night suspected that the bots finally got around CloudFlare, rendering CloudFlare innefective for spam protection.

Well we could also make an extra anti-spam filter just like revsoft's. (linking calcs with manufacturers)

making things too difficult for new people to register isn't a good idea, but maybe something similar, to that effect, could help.
True, especially considering Omnimaga is not only calc-related, so sometimes we get members who absolutely know nothing about calcs, such as TIMGUL refugees.
Hmm Netham45, do you know if any of your anti-spams were down last night? Because there were like 100+ new registrations and an unusual amount of spam posts. Normally since the new anti-spam measures last Spring there are only 2-4 registrations a day... O.O

TI-Freakware was hit as well it seems, but I'm unsure if they use the same anti-spam.

Don't know if its related, but UCF has been hit by quite a few bots recently too.
Didn't it also get hacked by the way? That was a bit scary when I got that e-mail. >.< I know TI-Freakware was hit by the spambot wave too, and on SMF, someone said he noticed a huge spike in spam in the last few days.
Title: Re: Extreme spambot rush last night
Post by: Eeems on November 19, 2012, 01:13:33 pm
I just checked the cloudflare analytics. it's threat hit count hasn't changed enough to make it seem that they found a way around it. I'd assume that these are just new bots that cloudflare hasn't encountered yet.
Title: Re: Extreme spambot rush last night
Post by: DJ Omnimaga on November 19, 2012, 04:17:54 pm
What I think is that it's the same software but updated, but some bots users haven't updated to the latest version yet. It definitively seems weird, though. I wonder if you would be able to report those bots to CloudFlare?
Title: Re: Extreme spambot rush last night
Post by: Yeong on November 20, 2012, 10:47:53 am
pr0nbot just hit omni O.O
Title: Re: Extreme spambot rush last night
Post by: Eeems on November 20, 2012, 11:51:40 am
Now if only people would report the post as more then just "spam". I was unprepared, and at work.... yeah awkward.
Title: Re: Extreme spambot rush last night
Post by: Juju on November 20, 2012, 12:03:42 pm
Well, there was "18+" in the title, but unless you speak Russian it still doesn't say if there's actual porn pics in the post or just links to porn.

Eeems hope you don't get fired x.x
Title: Re: Extreme spambot rush last night
Post by: Eeems on November 20, 2012, 12:05:12 pm
I wasn't looking at the title lol, I just read the reason for the report and clicked the link. I should pay more attention I guess.
Title: Re: Extreme spambot rush last night
Post by: DJ Omnimaga on November 20, 2012, 02:17:14 pm
pr0nbot just hit omni O.O

Did it post lobster/calc adult stuff?? O.O

Also lol at school they had strict rules against porn, but they tolerated when they saw pop ups appear with adult pics, knowing very well that back then, pop up blockers didn't exist and that even site like Newgrounds had adult site ads. Just as long as we tried to close them immediately (usually impossible due to extreme lag) >.<
Title: Re: Extreme spambot rush last night
Post by: DJ Omnimaga on November 22, 2012, 11:04:14 pm
The number of registrations per day is dropping drastically. I'm blaming Hackaday feature.
Title: Re: Extreme spambot rush last night
Post by: _Nicco_ on November 23, 2012, 01:24:02 am
Why would the Hackaday feature bring registrations down?
Title: Re: Extreme spambot rush last night
Post by: DJ Omnimaga on November 23, 2012, 02:46:32 am
I meant the opposite ???

Shortly after they featured the Linux Nspire stuff, registrations went from 2-3 to 100+. Slashdot didn't affect them much. They eventually dropped a few days later (I guess the article is far from Hackaday front page now). Otherwise it could be that CloudFlare was updated or something.
Title: Re: Extreme spambot rush last night
Post by: flyingfisch on November 23, 2012, 09:47:15 am
...
Quote
Don't know if its related, but UCF has been hit by quite a few bots recently too.
Didn't it also get hacked by the way? That was a bit scary when I got that e-mail. >.< I know TI-Freakware was hit by the spambot wave too, and on SMF, someone said he noticed a huge spike in spam in the last few days.

Well, it got hacked a while back, but since the hacker only stole information, and didn't do any damage, we didn't know about it until 2072 went through the logs recently.

He didnt get any actual passwords, just the MD5 hashes. So 2072 just had everyone reset their passwords and that should be fine.
Title: Re: Extreme spambot rush last night
Post by: annoyingcalc on November 23, 2012, 06:13:24 pm
Well I dont know if this works, but I read a post (I think it was Sorunomes) that putting hidden text boxes in the registration that when typed in dont allow you to be registered worked very well. I dont know just a suggestion
Title: Re: Extreme spambot rush last night
Post by: DJ Omnimaga on November 23, 2012, 07:07:24 pm
Yeah I saw some sites do that before. I  don't remember if it was effective, though, since some bots could detect them or retry by omitting info in some boxes.

SOmething I wonder: Would replacing "password" with "securityKey" or something like that (even purposely mispelling "password") cause bots to not be able to find the password fields?