Welcome, Guest. Please login or register.

Login with username, password and session length

 
Advanced search

1411493 Posts in 69372 Topics- by 58428 Members - Latest Member: shelton786

April 25, 2024, 06:07:28 AM

Need hosting? Check out Digital Ocean
(more details in this thread)
TIGSource ForumsPlayerGeneral35000+ members holy shit they must all be legitimate
Pages: [1] 2 3 ... 11
Print
Author Topic: 35000+ members holy shit they must all be legitimate  (Read 23322 times)
FARTRON
Level 4
****


the last man in space


View Profile WWW
« on: September 28, 2010, 12:39:44 PM »

I tried getting in touch with derek about this, but he never responded, so here it is in public.

About 90% (totally unresearched #) of the new signups for this board are spam accounts that just want to get links on tigsource.com to other sites so as to leach our popularity and increase their PageRank.

I've frequently complained about the quality of the board software in terms of usability, but now the crappiness is being leveraged by scammers to make money.

Anyone who cares to see for themselves can either just watch the number of registered users increase absurdly fast, or go into the member list and start randomly clicking names.

Here's the list alphabetically and if you click around on some you'll find they have never posted and have links in their signatures to prescription drugs and cubic zirconia and shit like that.

If you check the list sorted by most recent registrations the problem rapidly becomes much clearer.
Logged

Everything that was once directly lived has receded into a representation. - debord
Hangedman
Level 10
*****


Two milkmen go comedy


View Profile WWW
« Reply #1 on: September 28, 2010, 01:08:47 PM »

Is there even a captcha during registration?

There's a new one every few minutes.
Logged

AUST
ITIAMOSIWE (Play it on NG!) - Vision
There but for the grace of unfathomably complex math go I
bento_smile
Guest
« Reply #2 on: September 28, 2010, 01:11:08 PM »

Unfortunately a captcha won't keep them all out, as a bunch of them are probably humans and not robots. Sad
Logged
Hangedman
Level 10
*****


Two milkmen go comedy


View Profile WWW
« Reply #3 on: September 28, 2010, 01:13:20 PM »

Do what a lot of forums do and ask them an easy question that nevertheless requires extra effort. I know such a construct exists.

"Name Derek Yu's roguelike platformer."
Logged

AUST
ITIAMOSIWE (Play it on NG!) - Vision
There but for the grace of unfathomably complex math go I
[RM8]
Level 10
*****


☆☆☆☆☆


View Profile
« Reply #4 on: September 28, 2010, 01:22:34 PM »

Oh yes I like this game it's my favorite ever click here to buy prescription drugs.

No, but really, those are a lot of spam accounts.
Logged
s0
o
Level 10
*****


eurovision winner 2014


View Profile
« Reply #5 on: September 28, 2010, 01:23:26 PM »

Do what a lot of forums do and ask them an easy question that nevertheless requires extra effort. I know such a construct exists.

"Name Derek Yu's roguelike platformer."
Already exists, just checked a minute ago. Doesn't seem to help though.  Sad
Logged
Cthulhu32
Level 6
*


Brawp


View Profile WWW
« Reply #6 on: September 28, 2010, 01:29:33 PM »

Do what a lot of forums do and ask them an easy question that nevertheless requires extra effort. I know such a construct exists.

"Name Derek Yu's roguelike platformer."

If you can gather all of the possible captchas, it is very easy to create an auto joiner. As for the captcha avoidance, its pretty easy to get around the letter based captchas. All you need is a clever way to identify the area letters are in, estimate what parts of the darkened color are letters and what are not, then throw it into an open source hand-writing recognition software like Java OCR: http://sourceforge.net/projects/javaocr/

What we need because this forum has gotten popular enough to hit this many spam accounts is something like ASIRRA ( http://research.microsoft.com/en-us/um/redmond/projects/asirra/ ) Its free, it should stop the MAJORITY of spam accounts, and they have examples for every language to setup.
Logged

Christian Knudsen
Level 10
*****



View Profile WWW
« Reply #7 on: September 28, 2010, 01:30:17 PM »

Most forums have mods that allow you to delete all members with zero posts that haven't logged in for a while. Here's one that does part of it:

http://custom.simplemachines.org/mods/index.php?mod=995

Otherwise, just access the database itself and run a script to drop all members that haven't posted or logged in since registering.
Logged

Laserbrain Studios
Currently working on Hidden Asset (TIGSource DevLog)
ஒழுக்கின்மை (Paul Eres)
Level 10
*****


Also known as रिंकू.


View Profile WWW
« Reply #8 on: September 28, 2010, 01:30:22 PM »

it's a security flaw in this forum's version of smf, update the forum software to the latest version and the problem will be fixed
Logged

Christian Knudsen
Level 10
*****



View Profile WWW
« Reply #9 on: September 28, 2010, 01:36:35 PM »

Which flaw specifically are you referring to?
Logged

Laserbrain Studios
Currently working on Hidden Asset (TIGSource DevLog)
ஒழுக்கின்மை (Paul Eres)
Level 10
*****


Also known as रिंकू.


View Profile WWW
« Reply #10 on: September 28, 2010, 01:41:01 PM »

Quote
(17:33:40) Cthulhu32: RinkuHero: post the flaw you're talking about
(17:39:24) RinkuHero: the current version of smf is
(17:39:26) RinkuHero: 2.0
(17:39:31) RinkuHero: and they're using 1.1.11
(17:39:56) Cthulhu32: yeah that shouldn't open up their registering system
(17:40:01) Cthulhu32: I thought you meant you saw a specific version
(17:40:13) RinkuHero: no but i had the same problem
(17:40:26) Cthulhu32: ahh
(17:40:26) RinkuHero: when i was using 1.1.11 on my forums i got tons of registrations randomly with spam links
(17:40:32) RinkuHero: and when i updated to 2.0 they stopped
(17:40:36) Cthulhu32: you should mention that
(17:40:39) RinkuHero: so i assume it's some flaw in the software
(17:40:45) RinkuHero: even though i don't know the details of it
Logged

increpare
Guest
« Reply #11 on: September 28, 2010, 01:43:36 PM »

I get it still with some 2.x SMF forums I run.  They seem to have slowed down now that I've added a zillion authentication layers :/
Logged
ஒழுக்கின்மை (Paul Eres)
Level 10
*****


Also known as रिंकू.


View Profile WWW
« Reply #12 on: September 28, 2010, 01:50:22 PM »

perhaps we should put it on manual approval for a while, and require someone to email derek to prove they're human
Logged

bento_smile
Guest
« Reply #13 on: September 28, 2010, 01:51:32 PM »

Wouldn't that be a lot of work?
Logged
Christian Knudsen
Level 10
*****



View Profile WWW
« Reply #14 on: September 28, 2010, 01:57:28 PM »

I guess the Anti-Spam Verification Questions mod isn't installed correctly? Was it installed manually since this board has a custom theme?

If the anti-spam is installed correctly, I see only two possible ways for the spammers to register: they're either humans doing it manually, or they're bypassing the registration and accessing the database directly. I'd love to have a look at the register.php file, or whatever it's called on an SMF board.

EDIT: This anti-bot mod sounds very interesting and clever. Perhaps worth a try?
« Last Edit: September 28, 2010, 02:21:03 PM by chrknudsen » Logged

Laserbrain Studios
Currently working on Hidden Asset (TIGSource DevLog)
ஒழுக்கின்மை (Paul Eres)
Level 10
*****


Also known as रिंकू.


View Profile WWW
« Reply #15 on: September 28, 2010, 02:31:27 PM »

perhaps they just brute forced the solution and used it over and over. change the question?
Logged

Christian Knudsen
Level 10
*****



View Profile WWW
« Reply #16 on: September 28, 2010, 02:57:40 PM »

Yeah, but it's not the capthcha that seems to have been circumventeed (well it has, but that's almost to be expected), it's the question verification thingie. And I don't think somebody on another random site will now what the G in TIGForums stands for. Wink

It could be brute force, but wouldn't all the brute force attempts show up in the log? Possibly even hurt the forum performance considerably? I can't even image the number of attempts at trying to brute force three questions! That's three strings of undetermined length that can contain any characters...
Logged

Laserbrain Studios
Currently working on Hidden Asset (TIGSource DevLog)
randomshade
Level 1
*

Fastzelda


View Profile
« Reply #17 on: September 28, 2010, 03:30:00 PM »

Most forums have mods that allow you to delete all members with zero posts that haven't logged in for a while. Here's one that does part of it:

http://custom.simplemachines.org/mods/index.php?mod=995

Otherwise, just access the database itself and run a script to drop all members that haven't posted or logged in since registering.

Sadly, that would have deleted my [real...I think] account, which was rarely logged into for a couple of years when I was crunching like mad. But if cutting corner cases like me help the community, so be it.

Someone also mentioned manual checking: they did this, with a minimum post count before the user's posts showed up, on the indie gamer forums and it's horrible. The board gets more "why can't I post/pm/do jack shit" posts than spam, and threads become weird when hidden replies magically start showing up in the middle of conversations.

Edit: Just noticed the newest member (in the span of me writing this post) is "credit12approval"...yikes.
Logged
Cthulhu32
Level 6
*


Brawp


View Profile WWW
« Reply #18 on: September 28, 2010, 04:00:33 PM »

I really think a better captcha system would work:
http://research.microsoft.com/en-us/um/redmond/projects/asirra/

Its easy to add, no hassle to the admins.
Logged

J. R. Hill
Level 10
*****

hi


View Profile WWW
« Reply #19 on: September 28, 2010, 04:14:59 PM »

Ban everyone and start over.
Logged

hi
Pages: [1] 2 3 ... 11
Print
Jump to:  

Theme orange-lt created by panic