Forums attacked by spamers???

Discussion in 'Security and Legal' started by Sylvain, Mar 2, 2014.

  1. Sylvain

    Sylvain Regular Member

    Joined:
    Mar 15, 2013
    Messages:
    140
    Likes Received:
    17
    My Xenforo forum has been attacked by massive spamming today.

    All the threads were started by MartyAge, FredHolnes or DamienGangl

    I googled few of the thread titles and many forums have been attacked...


    Anyone heard about this?
     
  2. AWS

    AWS Administrator

    Joined:
    Feb 1, 2010
    Messages:
    1,612
    Likes Received:
    695
    Location:
    Joliet, IL U.S.A.
    First Name:
    Bob
    Yep. They use a hacked server in the U.S. to create the account and then use India IP's to post the spam. I have India blocked so while they can register they can't post. Look for registration from a server in U.S. You'll able to tell it's a server when you check the IP.
     
  3. Sylvain

    Sylvain Regular Member

    Joined:
    Mar 15, 2013
    Messages:
    140
    Likes Received:
    17
    How did you block India?
     
  4. pixelek

    pixelek Regular Member

    Joined:
    Oct 9, 2013
    Messages:
    229
    Likes Received:
    85
    Location:
    Torun, Poland
    I guess he blocked IP zones and or/streams. Am I right AWS?
     
  5. AWS

    AWS Administrator

    Joined:
    Feb 1, 2010
    Messages:
    1,612
    Likes Received:
    695
    Location:
    Joliet, IL U.S.A.
    First Name:
    Bob
    I block by IP and Country code.
     
    pixelek likes this.
  6. Sylvain

    Sylvain Regular Member

    Joined:
    Mar 15, 2013
    Messages:
    140
    Likes Received:
    17
    You use an addon ???

    BTW, the link in the email notification doesn't work, it misses a . between admin-talk and com
     
  7. Cerberus

    Cerberus Admin Talk Staff

    Joined:
    May 3, 2009
    Messages:
    1,031
    Likes Received:
    500
  8. DriveHosting

    DriveHosting Regular Member

    Joined:
    Jun 11, 2014
    Messages:
    121
    Likes Received:
    9
    Wouldn't banning a whole country code effect users in that area?
     
  9. Big al

    Big al Regular Member

    Joined:
    May 14, 2013
    Messages:
    1,093
    Likes Received:
    415
    Location:
    OZ
    I would say yes. Unfortunately stopping spammers can be a matter of compromise. Blocking a country will affect the spammers but may also affect any genuine potential member.

    If you are getting many spammers from say Ukraine and the potential for getting a genuine new member from there is very low, then it may make sense to block that whole country. Not ideal but it may be necessary.
     
  10. Lee G

    Lee G Regular Member

    Joined:
    May 2, 2014
    Messages:
    165
    Likes Received:
    33
    Location:
    Costa Blanca Spain
    First Name:
    Lee
    Anyone with a minimal knowledge of any kind link building will use proxies
    Asia tend to do it by hand and beat most authentication systems
    You can buy proxies for as little as $10 for 10 for a month and choose the geographic location, ie America, Europe etc
    Most automated link building software will have a proxy option

    From time to time I use the likes of hide my arse to gain access to UK and American TV, which block my countries ip

    Your best methods at beating them are simple enough
    Use stop forum spam and remember to submit to it when you either ban or delete the accounts
    There is also the option to have your site listed on Stop Forum Spam as a contributor

    Questions and answers on sign up.
    Use questions like "whats the name of this forum"
    Questions like "add one and one" are beaten by automated software

    Also look for the email accounts used
    I personally block any kind of disposable email
    trash-mail.com
    spambog.com
    spamavert.com
    Are just a few
     
  11. Jack Rouse

    Jack Rouse Regular Member

    Joined:
    Jun 8, 2014
    Messages:
    147
    Likes Received:
    19
    Here are two files that may be of use if you are getting blitzed by spam bots, or want to block them just in case.

    Between them there are about 1000 spambots listed with e-mail adresses, not my work, courtesy of OzzMODs. Supplied as text files, but laid out in XHTML format so you should be able to convert them back, or if you need them as CSV they should convert easily.
     

    Attached Files:

Share This Page