Spam Account mod?

Mods etc.

Moderator: Integra Moderator

Spam Account mod?

PostAuthor: jwernerny » Thu Sep 14, 2006 1:17 pm

Does anyone know of an IM mod that can be to help get rid of "Spam Accounts". It would be nice to be able to spot spam accounts automatically and flag them in the "Inactive User" screen.

There are a couple of ways I think spam accounts can be detected.
- number of forums they joined (> 200?)
- central reporting spot (like the e-mail blacklists)

Any thoughts or suggestions?

- John

BTW: Here is a long explanation of what I call a Spam Account. I posted it after deleting about 40 of them from one of my forums. It uses a real world account name that you might even have on your own forum now.

In my previous post, I used the term "Spam Account." A Spam Account is what I call an account that is soley created to allow someone to post spam messages on a forum.

Here is one example "rich_oston". A quick [url=http]Google Search for the user name[/url] turns up over 22,000 sites. Either there are a lot of rich_oston's out there, this guy is really busy, or there is something else going on.

A look through the search results reveals this guy is quite a polyglot. I count at least 5 different language sites. His interests also seem to stretch from snow tires to weddings to electronics to ... well just about everything and anything that has a forum.

It is also quite obvious that he is very busy on the internet. I counted over 100 forums that he has joined in just the past week.

Let's look at what he has posted. He must sure have some great thoughts.

Author: rich_oston (217.196.166.---)
Date: 09-06-06 17:45

Hey!

I was just blindly clicking the links and found this website.
sourcing

AugustaM Sourcing will solve your procurement problems with quick and professional service and extremely competitive pricing and quality
Just imagine - a few millions items database

Bye-bye


Hi

It was a real problem for me to find some rare parts until i found this website.
<a> sourcing </a>

AugustaM Sourcing will solve your procurement problems with quick and professional service and extremely competitive pricing and quality
Just imagine - a few millions items database

Cheers


Hey!

It was a real problem for me to find some rare parts until i found this website.
excess inventory

AugustaM Sourcing will solve your procurement problems with quick and professional service and extremely competitive pricing and quality
Just imagine - a few millions items database

Chao


It sure looks like rich_oston is just a spam source, or in my words, a "Spam Account."
Last edited by jwernerny on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
User avatar
jwernerny
Members
Members
 
Posts: 87
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 3:58 am
Cash on hand: 0.00
Location: Fairport, NY

Re: Spam Account mod?

PostAuthor: Helter » Thu Sep 14, 2006 5:25 pm

you must have disabled the profilcp images for registration. That is what they are there for.
Last edited by Helter on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4168
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 187.60
Location: Seattle Wa
IntegraMOD version: IM 3

PostAuthor: jwernerny » Fri Sep 15, 2006 3:53 am

Nope, the profilcp images are still there. (see http://www.snowtire.info/forum/profile. ... efer&mod=0)

That means they are either doing them by hand (which seems unlikely, because of the speed they hit so many sites), or that they have found a way around them. Maybe it is time to look at my logs again....

- John
Last edited by jwernerny on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
User avatar
jwernerny
Members
Members
 
Posts: 87
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 3:58 am
Cash on hand: 0.00
Location: Fairport, NY

Re: Spam Account mod?

PostAuthor: jwernerny » Fri Sep 15, 2006 4:44 am

Okay, I did some more research and found some interesting things.

1. All of the bogus users have no security question.

2. From my logs, it looks like they are doing an end-around insertion

Code: Select all
211.191.97.246 - - [15/Sep/2006] "GET /forum/profile.php?mode=register&agreed=true HTTP/1.1" 302 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"    ***MARK***211.191.97.246 - - [15/Sep/2006:00:05:06 -0400] "POST /forum/profile.php HTTP/1.1" 302 - "http://snowtire.info/forum/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"  


I think this issue really needs to be moved into a bug. Since it is a "hack" against IM, I will log this also in the Security forum.
Last edited by jwernerny on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
User avatar
jwernerny
Members
Members
 
Posts: 87
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 3:58 am
Cash on hand: 0.00
Location: Fairport, NY

Re: Spam Account mod?

PostAuthor: Dragonsys » Wed Sep 20, 2006 5:52 am

sounds like a type of SQL injection.

Have you updated to the latest patch release of 2.0.21 and installed the latest Security Fixes?

patches - http://integramod.com/forum/dload.php?a ... &cat_id=29

Security Fixes - http://integramod.com/forum/viewtopic.php?p=14453
Last edited by Dragonsys on Wed Sep 20, 2006 5:55 am, edited 1 time in total.
Image
User avatar
Dragonsys
Sr Integra Member
Sr Integra Member
 
Posts: 326
Likes: 0 post
Liked in: 0 post
Joined: Mon Apr 10, 2006 6:45 am
Cash on hand: 0.00
Location: Springtown, TX

PostAuthor: jwernerny » Wed Sep 20, 2006 5:55 am

I have the latest security fixes installed, but I don't have 2.0.21 in there yet, just 2.0.20. I have been waiting for IM 141.

I may try putting 2.0.21 in tonight and see if it solves anything.
Last edited by jwernerny on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
User avatar
jwernerny
Members
Members
 
Posts: 87
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 3:58 am
Cash on hand: 0.00
Location: Fairport, NY

PostAuthor: Dioncecht » Sat Sep 23, 2006 12:28 pm

I have .21 and the patches and getting same issue. The account names are starting to get quite colorful to. Already offended one of my members...
Last edited by Dioncecht on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
'We keep moving forward, opening new doors, and doing new things, because we're curious and curiosity keeps leading us down new paths.' - Walt Disney

[img=left]http://rpghq.org/banner2.jpg[/img]
[url=http]The RPG Headquarters. The RPG capitol of the net![/url]
User avatar
Dioncecht
Sr Integra Member
Sr Integra Member
 
Posts: 244
Likes: 0 post
Liked in: 0 post
Joined: Sun Apr 09, 2006 4:23 pm
Cash on hand: 0.00

Re: Spam Account mod?

PostAuthor: Helter » Sat Sep 23, 2006 1:33 pm

try this...looks like an easy install
It is called, Visual Confirmation on Posting
Attachments
VC.zip
(14.62 KiB) Downloaded 169 times
Last edited by Helter on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4168
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 187.60
Location: Seattle Wa
IntegraMOD version: IM 3

Re: Spam Account mod?

PostAuthor: Dioncecht » Sun Sep 24, 2006 4:22 pm

"This modification integrates the phpBB visual confirmation system with posting to require newly registered members to enter a code before their post is entered in your database."

None of them actually post anything, they just create accounts which displays in the Newest Members area
Last edited by Dioncecht on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
'We keep moving forward, opening new doors, and doing new things, because we're curious and curiosity keeps leading us down new paths.' - Walt Disney

[img=left]http://rpghq.org/banner2.jpg[/img]
[url=http]The RPG Headquarters. The RPG capitol of the net![/url]
User avatar
Dioncecht
Sr Integra Member
Sr Integra Member
 
Posts: 244
Likes: 0 post
Liked in: 0 post
Joined: Sun Apr 09, 2006 4:23 pm
Cash on hand: 0.00

Re: Spam Account mod?

PostAuthor: Helter » Sun Sep 24, 2006 4:41 pm

so are they registering via sql injection to bypass the profilcp images?

you could set registration to Admin Aproval to see if they get past that
Last edited by Helter on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4168
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 187.60
Location: Seattle Wa
IntegraMOD version: IM 3

PostAuthor: jwernerny » Tue Sep 26, 2006 3:31 am

On my site, I still get a message to approve them, but no one else sees them.

The bypass they are using also seems to bypass the security question.

For the other people who are having this problem -- did you previously have a plain phpBB site? I did, and I keep wondering if there is some old file hanging around that they are using.

- John
Last edited by jwernerny on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
User avatar
jwernerny
Members
Members
 
Posts: 87
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 3:58 am
Cash on hand: 0.00
Location: Fairport, NY

PostAuthor: Dioncecht » Tue Sep 26, 2006 5:16 am

"jwernerny";p="15865" wrote:On my site, I still get a message to approve them, but no one else sees them.

The bypass they are using also seems to bypass the security question.

For the other people who are having this problem -- did you previously have a plain phpBB site? I did, and I keep wondering if there is some old file hanging around that they are using.

- John



Nope.. I did a fresh install of IM 1.4.0
Last edited by Dioncecht on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
'We keep moving forward, opening new doors, and doing new things, because we're curious and curiosity keeps leading us down new paths.' - Walt Disney

[img=left]http://rpghq.org/banner2.jpg[/img]
[url=http]The RPG Headquarters. The RPG capitol of the net![/url]
User avatar
Dioncecht
Sr Integra Member
Sr Integra Member
 
Posts: 244
Likes: 0 post
Liked in: 0 post
Joined: Sun Apr 09, 2006 4:23 pm
Cash on hand: 0.00

PostAuthor: ZacFields » Tue Nov 28, 2006 10:32 pm

i had to bring this topic back up.

I'm having a horrible problem with spammers on my forum. Like 5-10 spammers join the site everyday and about 3-4 of them post some junk spam crap on the forums.

I have the visual code thing enabled on the forum. I'm not sure if these are real people or if they're getting around it somewhere. If it were an SQL injection, wouldn't PHPBB Security catch that?

Also, does anyone have any suggestions? My forums are based locally in the US so I have banned the email providers of the people (all from foreign email providers like mail.ru and web.de) and I think that will stop about half of them, but the other half I am clueless about...and why is it that I've been targeted with this?

Zac
Last edited by ZacFields on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

ZacFields
Sr Integra Member
Sr Integra Member
 
Posts: 426
Likes: 0 post
Liked in: 0 post
Joined: Wed May 24, 2006 10:14 pm
Cash on hand: 0.00

PostAuthor: ZacFields » Tue Nov 28, 2006 10:33 pm

Also, wasn't there talk once about creating a public blacklist of spammers and hackers' IP addresses? I think this would be an effective way of preventing a lot of this.

Zac
Last edited by ZacFields on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

ZacFields
Sr Integra Member
Sr Integra Member
 
Posts: 426
Likes: 0 post
Liked in: 0 post
Joined: Wed May 24, 2006 10:14 pm
Cash on hand: 0.00

PostAuthor: jwernerny » Wed Nov 29, 2006 5:34 am

"ZacFields";p="17924" wrote:I have the visual code thing enabled on the forum. I'm not sure if these are real people or if they're getting around it somewhere. If it were an SQL injection, wouldn't PHPBB Security catch that?

Take a look at your Users database. (You can do this through phpmyadmin in the Admin / General section. It is called phpbb_users.) If you find registered users without a security question, and you have required that they have one (this is the defaul), then it is probably an SQL injection. The checks for these fields are pretty well hard coded in the user profile code.
Also, does anyone have any suggestions? My forums are based locally in the US so I have banned the email providers of the people (all from foreign email providers like mail.ru and web.de) and I think that will stop about half of them, but the other half I am clueless about...and why is it that I've been targeted with this?

Zac


You were most likely targeted because they have triggered off of phpBB or Integramod on your pages.

My steps to help with this are band-aides, but here they are.
- turn on admin approval for registration
- turn on approval for all open forums
- when a new user is created, check for the security question. If it isn't there, delete the user (you could try banning instead)
- when in doubt, I run the new user's name through a Google search. If I get a lot of hits from other forums (like > 1000), I get really suspicious.
Last edited by jwernerny on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
User avatar
jwernerny
Members
Members
 
Posts: 87
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 3:58 am
Cash on hand: 0.00
Location: Fairport, NY

Next

Return to IntegraMOD Modifications

Who is online

Registered users: Bing [Bot], Helter, Majestic-12 [Bot]