Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length

 
Advanced search

891371 Posts in 33540 Topics- by 24777 Members - Latest Member: Amy

June 19, 2013, 03:35:03 PM
TIGSource ForumsPlayerGeneral35000+ members holy shit they must all be legitimate
Pages: [1] 2 3 ... 15
Print
Author Topic: 35000+ members holy shit they must all be legitimate  (Read 15241 times)
FARTRON
Level 4
****


the last man in space


View Profile WWW
« on: September 28, 2010, 12:39:44 PM »

I tried getting in touch with derek about this, but he never responded, so here it is in public.

About 90% (totally unresearched #) of the new signups for this board are spam accounts that just want to get links on tigsource.com to other sites so as to leach our popularity and increase their PageRank.

I've frequently complained about the quality of the board software in terms of usability, but now the crappiness is being leveraged by scammers to make money.

Anyone who cares to see for themselves can either just watch the number of registered users increase absurdly fast, or go into the member list and start randomly clicking names.

Here's the list alphabetically and if you click around on some you'll find they have never posted and have links in their signatures to prescription drugs and cubic zirconia and shit like that.

If you check the list sorted by most recent registrations the problem rapidly becomes much clearer.
Logged

Everything that was once directly lived has receded into a representation. - debord
Hangedman
Level 10
*****


Two milkmen go comedy


View Profile WWW
« Reply #1 on: September 28, 2010, 01:08:47 PM »

Is there even a captcha during registration?

There's a new one every few minutes.
Logged

AUST
ITIAMOSIWE (Play it on NG!) - Vision
If this is the life why does it feel so good to die today
bento_smile
Guest
« Reply #2 on: September 28, 2010, 01:11:08 PM »

Unfortunately a captcha won't keep them all out, as a bunch of them are probably humans and not robots. Sad
Logged
Hangedman
Level 10
*****


Two milkmen go comedy


View Profile WWW
« Reply #3 on: September 28, 2010, 01:13:20 PM »

Do what a lot of forums do and ask them an easy question that nevertheless requires extra effort. I know such a construct exists.

"Name Derek Yu's roguelike platformer."
Logged

AUST
ITIAMOSIWE (Play it on NG!) - Vision
If this is the life why does it feel so good to die today
Rm88~
Level 10
*****


☆☆☆☆☆

rm88___@hotmail.com
View Profile Email
« Reply #4 on: September 28, 2010, 01:22:34 PM »

Oh yes I like this game it's my favorite ever click here to buy prescription drugs.

No, but really, those are a lot of spam accounts.
Logged

█▀▀ ▄▄▄▄ ▀█▀ ▄█▀ ▀█▄ ██ ▀▀█
C.A. Sinner
man of wealth & taste
Global Moderator
Level 10
******


dmloish srs cultru


View Profile WWW
« Reply #5 on: September 28, 2010, 01:23:26 PM »

Do what a lot of forums do and ask them an easy question that nevertheless requires extra effort. I know such a construct exists.

"Name Derek Yu's roguelike platformer."
Already exists, just checked a minute ago. Doesn't seem to help though.  Sad
Logged

Cthulhu32
Level 6
*


Brawp


View Profile WWW Email
« Reply #6 on: September 28, 2010, 01:29:33 PM »

Do what a lot of forums do and ask them an easy question that nevertheless requires extra effort. I know such a construct exists.

"Name Derek Yu's roguelike platformer."

If you can gather all of the possible captchas, it is very easy to create an auto joiner. As for the captcha avoidance, its pretty easy to get around the letter based captchas. All you need is a clever way to identify the area letters are in, estimate what parts of the darkened color are letters and what are not, then throw it into an open source hand-writing recognition software like Java OCR: http://sourceforge.net/projects/javaocr/

What we need because this forum has gotten popular enough to hit this many spam accounts is something like ASIRRA ( http://research.microsoft.com/en-us/um/redmond/projects/asirra/ ) Its free, it should stop the MAJORITY of spam accounts, and they have examples for every language to setup.
Logged

Christian Knudsen
Level 10
*****



View Profile WWW Email
« Reply #7 on: September 28, 2010, 01:30:17 PM »

Most forums have mods that allow you to delete all members with zero posts that haven't logged in for a while. Here's one that does part of it:

http://custom.simplemachines.org/mods/index.php?mod=995

Otherwise, just access the database itself and run a script to drop all members that haven't posted or logged in since registering.
Logged

Laserbrain Studios
Currently working on Hostile Takeover (TIGSource DevLog)
Paul Eres
Level 10
*****


Also known as RinkuHero.

RinkuHero
View Profile WWW Email
« Reply #8 on: September 28, 2010, 01:30:22 PM »

it's a security flaw in this forum's version of smf, update the forum software to the latest version and the problem will be fixed
Logged

Christian Knudsen
Level 10
*****



View Profile WWW Email
« Reply #9 on: September 28, 2010, 01:36:35 PM »

Which flaw specifically are you referring to?
Logged

Laserbrain Studios
Currently working on Hostile Takeover (TIGSource DevLog)
Paul Eres
Level 10
*****


Also known as RinkuHero.

RinkuHero
View Profile WWW Email
« Reply #10 on: September 28, 2010, 01:41:01 PM »

Quote
(17:33:40) Cthulhu32: RinkuHero: post the flaw you're talking about
(17:39:24) RinkuHero: the current version of smf is
(17:39:26) RinkuHero: 2.0
(17:39:31) RinkuHero: and they're using 1.1.11
(17:39:56) Cthulhu32: yeah that shouldn't open up their registering system
(17:40:01) Cthulhu32: I thought you meant you saw a specific version
(17:40:13) RinkuHero: no but i had the same problem
(17:40:26) Cthulhu32: ahh
(17:40:26) RinkuHero: when i was using 1.1.11 on my forums i got tons of registrations randomly with spam links
(17:40:32) RinkuHero: and when i updated to 2.0 they stopped
(17:40:36) Cthulhu32: you should mention that
(17:40:39) RinkuHero: so i assume it's some flaw in the software
(17:40:45) RinkuHero: even though i don't know the details of it
Logged

increpare
Guest
« Reply #11 on: September 28, 2010, 01:43:36 PM »

I get it still with some 2.x SMF forums I run.  They seem to have slowed down now that I've added a zillion authentication layers :/
Logged
Paul Eres
Level 10
*****


Also known as RinkuHero.

RinkuHero
View Profile WWW Email
« Reply #12 on: September 28, 2010, 01:50:22 PM »

perhaps we should put it on manual approval for a while, and require someone to email derek to prove they're human
Logged

bento_smile
Guest
« Reply #13 on: September 28, 2010, 01:51:32 PM »

Wouldn't that be a lot of work?
Logged
Christian Knudsen
Level 10
*****



View Profile WWW Email
« Reply #14 on: September 28, 2010, 01:57:28 PM »

I guess the Anti-Spam Verification Questions mod isn't installed correctly? Was it installed manually since this board has a custom theme?

If the anti-spam is installed correctly, I see only two possible ways for the spammers to register: they're either humans doing it manually, or they're bypassing the registration and accessing the database directly. I'd love to have a look at the register.php file, or whatever it's called on an SMF board.

EDIT: This anti-bot mod sounds very interesting and clever. Perhaps worth a try?
« Last Edit: September 28, 2010, 02:21:03 PM by chrknudsen » Logged

Laserbrain Studios
Currently working on Hostile Takeover (TIGSource DevLog)
Pages: [1] 2 3 ... 15
Print
Jump to:  

Theme orange-lt created by panic