PDA

View Full Version : Latest SPAM Attack



Rick
April 4th, 2013, 11:01 AM
Just wanted to update those who care on the latest efforts I have taken to protect the forum from the latest round of attacks.

Unless you look at the bottom of the forum and see the members who visited list, you probably don't realize what happened the past 24-48 hours. The other day, I opened the forum's Robots.txt to allow Google and other search engines access to the forum so that we show up on search engines. That also opened the forum up to SPAMbots looking to push their scams.

The names in pink are ones who were able to register and I had to search the IP address to make sure they were legitimate, and if not, ban them, then manually block them from the server. The Old Programmer has been a great help with this when he notices them, he deletes them with a quickness. Thank you very much TOP for all the help.

The old anti-spam mod seemed to no longer be able to stop them, so I found one that seems to be working much better. It is called Spam-O-Matic and in about 12 hours, it has stopped 45 malicious registrations. This mod has several layers of protection. It will not only check the IP address against a database, it will look at posts that new members make to see if they post links or text that is listed in another database, then ban them. Two got through overnight, but didn't post anything.
3398

Hopefully, this will help protect the forum from these annoyances and sometimes, potentially harmful websites.

Thanks for your patience.

Rick

Night Owl
April 4th, 2013, 11:36 AM
Thanks Rick. Just a note, why is Scarlett highlighted as a spammer?:)):))

Rick
April 4th, 2013, 11:40 AM
It's the software that makes the determination, I have no control over that...haha

Scarlett
April 4th, 2013, 11:41 AM
You deserved the button this time....LOL
:07:

Night Owl
April 4th, 2013, 12:02 PM
I must admit I couldn't resist.:))

IronErnin
April 4th, 2013, 12:29 PM
Awww, Scarlett's name doesn't show up in pink. Her name shows up in RED.

Rick
April 4th, 2013, 12:34 PM
No #### Sherlock!

Scarlett
April 4th, 2013, 12:35 PM
I must admit I couldn't resist.:))

You make me more and more excited about our upcoming date...LOL

ClickaNerd
April 4th, 2013, 1:40 PM
Here is a chunk of code we use for spammers.
Hope it helps

'Record login attempts and trap ip address and record in table

dim login_ipaddress
dim login_device
login_ipaddress = Request.ServerVariables("HTTP_PROXY_IP")
login_device = Request.ServerVariables("HTTP_USER_AGENT")
Response.Buffer = true
Set db = Server.CreateObject("ADODB.Connection")
db.Open "Driver={Microsoft Access Driver (*.mdb)}; DBQ=" & Server.MapPath(session("dataBaseLocation"))
set rsobj = Server.CreateObject("ADODB.RecordSet")
sqlstr="insert into login(ipaddress, device) values('"&login_ipaddress&"','"&login_device&"')"
rsobj.Open sqlstr,db
rsobj.Open "SELECT max(id) as lastId from login",db

' if all the proper credentials are met and ipaddress is trapped in login table then redirect
response.redirect("allowed-entry-point.asp")
end if

' if all the proper credentials are NOT met and ipaddress is trapped in login table then redirect
response.redirect("http://http://www.shemaleplus.com/")
end if

Night Owl
April 4th, 2013, 2:14 PM
Awww, Scarlett's name doesn't show up in pink. Her name shows up in RED.

:dohYou keep proving time and again you have NO CLUE!!!!!:doh

Night Owl
April 4th, 2013, 2:15 PM
You make me more and more excited about our upcoming date...LOL

Trying to increase the anticipation.:)

Scarlett
April 4th, 2013, 2:23 PM
Trying to increase the anticipation.:)

That really doesn't take much....

Rick
April 4th, 2013, 9:42 PM
You make me more and more excited about our upcoming date...LOL
Who are you and why are you using Scarlett's account?

They say that opposites attract, but damn! :bluerofl

Rick
April 5th, 2013, 3:26 PM
It's been a long time since there has been no pink in the list! :thumbsup
3401

Night Owl
April 5th, 2013, 3:33 PM
But there is RED !!!:))

xzochye
April 5th, 2013, 6:01 PM
It's been a long time since there has been no pink in the list! :thumbsup
3401

Uhmmm, I still want my name in purple!!!

Rick
April 5th, 2013, 6:05 PM
Got cash?

xzochye
April 5th, 2013, 6:12 PM
Got cash?

No, but I can send someone over for some free labor!

xzochye
April 5th, 2013, 8:43 PM
NO, I'm not sure why you are laughing. If Rick said it's a deal I was going to pm you his address!

stormy
April 8th, 2013, 1:52 PM
Uhmmm, I still want my name in purple!!!

Now wait a second...I'm purple...8-;

xzochye
April 8th, 2013, 1:54 PM
Now wait a second...I'm purple...8-;

All AWESOME people should be in purple. :-) But I will settle for fuschia or lavender.

kantwin
April 8th, 2013, 1:59 PM
Should only allow colors in a Crayola 16 box. LOL

Mestral
April 12th, 2013, 5:31 AM
I glanced at the "currently active users" this morning and saw 10 members and 83 guests. Now, I know a half dozen of those are users who operate cloaked (I do this, but no longer have a reason) but, since (at least it used to be the case) this board limits reading until someone becomes a member, I was wondering if this is an indication of a spam attack?

Rick
April 12th, 2013, 9:18 AM
Ya. the guests exploded when I opened up the robots.txt. When I was testing this software with the Facebook or Twitter interface, I noticed that they increased almost immediately after I posted a message. Most of them are harmless search engine bots. Once in a while, a couple try to register and once in a while, some get through. 629 have been denied registration since I installed the Spam a matic mod.

Ludwig
April 12th, 2013, 11:13 AM
I learned to dislike Spam as a child, when it was served as a meat and tasted like salty soap. However, I picked up one of those Spam Meals for 1, the.Spam & Sausage Jambalaya, and found it to be quite tasty.

Mestral
April 12th, 2013, 11:45 AM
I learned to dislike Spam as a child, when it was served as a meat and tasted like salty soap. However, I picked up one of those Spam Meals for 1, the.Spam & Sausage Jambalaya, and found it to be quite tasty.Yes, somethings made with spam are tasty, but the InterNet version was named after the stuff that tastes like salty soap, and is liked about as much.

Rick
April 12th, 2013, 8:19 PM
Go to Hawaii, they serve Spam at McDonalds for breakfast.

sojourner truth
April 12th, 2013, 8:31 PM
Spam was the "breakfast meat du jour" at my house every morning until I left home. Fried spam, over easy eggs, jelly toast and corn flakes. Mmmmmmmmmmmmmmmmm.

Rick
April 13th, 2013, 7:46 AM
Since I'll be away from my computer most of the weekend, I have set the software to where I have to manually approve all new registrations as opposed to the email verification. This way, I shouldn't have to worry about the spambots trashing the forum.

I'll approve new valid registrations when I get a chance.

Rick
April 16th, 2013, 6:04 PM
I'm kind of liking the manual user registration. It'll be more inconvenient for new users, but it helps me weed out the spambots before they can post.

Another thing I did was set the software to not allow new users with hotmail email addresses. I did this since most of the spambots list hotmail as their email address. If you currently have one, it'll still send and receive notifications as normal.