DaniWeb Spam Attack
I am sorry to say that DaniWeb is once again under concerted attack by Chinese and Russian spammers. The admin and moderator teams have been working around the clock these last 48 hours to delete spam postings and remove the offending accounts, and will continue to do so until the attackers have been defeated.
However, we are only human and some spam may slip through unnoticed - which is where you come in. Can we please ask the DaniWeb community to be extra vigilant at the moment and use the flag bad post facility to report any postings which are spam so that we can then deal with the accounts in question.
All spam accounts are being banned on the spot, no warnings will be given during this period of sustained attack.
happygeek
Freelance Word Punk
27,454 posts since Mar 2006
Reputation Points: 1,457
Solved Threads: 54
Im sorry that this site is also experiencing this garbage...
Seems like almost EVERY SITE IM ON gets this and its sad :(
The best thing you can do happygeek is put ALL NEW USERS ON MODERATION,meaning nothing they post is visible to anyone but the staff group.. (After a few messages and staff sees they are OK,they add them to the reg member group)
On a couple other sites im onthey do this (Some VBB some other)
Good luck my friend :)
The Dude
Nearly a Senior Poster
3,485 posts since Dec 2005
Reputation Points: 1,054
Solved Threads: 31
That would be impractical as all moderators are volunteers and already devote a huge amount of their free time to keeping the community running smoothly. Throw in having to actively approve everyone who wants to post here, manually, one by one, would be a step too far when there are 100+ new members joining every day. Perhaps the other sites you mention either have fewer new members to deal with or are moderated by paid staff?
happygeek
Freelance Word Punk
27,454 posts since Mar 2006
Reputation Points: 1,457
Solved Threads: 54
I dont know to be honest buddy.......
But seeing you dont have alot of staff maybe it would be too much to deal with :(
On the other hand IT MAY BE WORTH NEW MEMBERS WAITING A FEW DAYS TO BE APPROVED.. (Ya gotta think of it that way my friend.... If they are a GOOD MEMBER they wont mind waiting)
The Dude
Nearly a Senior Poster
3,485 posts since Dec 2005
Reputation Points: 1,054
Solved Threads: 31
diafol
Rhod Gilbert Fan (ardav)
7,735 posts since Oct 2006
Reputation Points: 1,168
Solved Threads: 1,070
If you are after help with a coding problem and it is urgent you won't wait, you will go try find the answer elsewhere.
happygeek
Freelance Word Punk
27,454 posts since Mar 2006
Reputation Points: 1,457
Solved Threads: 54
They need help for their homework or project and waiting a few days is a good thing? How long would you wait when you need help with a problem? I'd expect everyone would just go somewhere else.
WaltP
Posting Sage w/ dash of thyme
10,474 posts since May 2006
Reputation Points: 3,342
Solved Threads: 938
Ya im sorry guys,
Im just thinking about the site and how we can stop the spam......
Have you tried blocking all IPs from russia David?? (Block them @ the server so if they enter www.daniweb.com/forums into thier address bar NOTHING LOADS)
The Dude
Nearly a Senior Poster
3,485 posts since Dec 2005
Reputation Points: 1,054
Solved Threads: 31
I think we are missing the main point here. It's not so much about banning users but rather validating users. And what do most websites use these days? To my knowledge captcha fields and random questions. So perhaps for users who have made less than 60 posts, they need to fill out a captcha field each time they make a post or create a new topic. But after they have made 60 posts then the captcha disappears. I think that would make more sense. :)
cwarn23
Occupation: Genius
3,033 posts since Sep 2007
Reputation Points: 413
Solved Threads: 259
> And what do most websites use these days?
OpenID providers which pretty much brings down the possibility of mass registrations since the spammers would now be up against OpenID providers for spamming rather than Daniweb itself.
~s.o.s~
Failure as a human
11,938 posts since Jun 2006
Reputation Points: 3,281
Solved Threads: 732
Have you tried blocking all IPs from russia David??
That was brought up as an option, but I suspect Dani doesn't want to risk losing legitimate members from an IP range in the name of spam defense.And what do most websites use these days? To my knowledge captcha fields and random questions.
Daniweb has both those on registration as well.So perhaps for users who have made less than 60 posts, they need to fill out a captcha field each time they make a post or create a new topic.
Yeah, no, that's punishing everyone for the misdeeds of a minority. Though thereare regular registration practices that Daniweb doesn't do, which I feel are a primary reason for why these attacks are so painful. Sadly, Dani doesn't seem to agree.
Narue
Bad Cop
15,460 posts since Sep 2004
Reputation Points: 6,464
Solved Threads: 1,401
Are the spams in Russian and Chinese (language)? I reported a couple of French and Russian spams a few days ago. Perhaps identifying Cyrillic or Chinese characters on post submission could stop the post in its tracks?
Or at least they could be flagged as dodgy - "Post waiting for moderation" or similar. Although, that would probably make life just as awkward for mods. Or there again, perhaps not. Do these concerted attacks last for long periods? Do spammers get p'd off after a certain time? Or do they keep on going until they kill the site? Seems a bit silly to me if they do - like a pathogen killing its host.
What about disabling or automatically snipping links in noob posts? Or prevent the insertion of a url in the edit box. OK, it doesn't stop the spam post, but it may stop the usefulness to the spammer. If they care that is.
diafol
Rhod Gilbert Fan (ardav)
7,735 posts since Oct 2006
Reputation Points: 1,168
Solved Threads: 1,070
Language varies, patterns are spotted in such things as IP grouping, registration details, username etc and that helps us eliminate pools of spambot created accounts.
This particular attack, which we have beaten from the perspective of stopping new registrations but are still fighting with regards to clearing up spam (I estimate there are a couple of hundred accounts yet to post) has lasted over a week now. I would say 7-10 days from start to finish of the main attack phase is pretty average, but the drip effect continues long after.
happygeek
Freelance Word Punk
27,454 posts since Mar 2006
Reputation Points: 1,457
Solved Threads: 54
Ya i know bud....
Scammers are the scum of the internet... I WOULD HAVE THE MOST SPAMMERS COME FROM THE USA!
I am glad its calmed down a little,im sorry you ever had to deal with this :(
The Dude
Nearly a Senior Poster
3,485 posts since Dec 2005
Reputation Points: 1,054
Solved Threads: 31
What are you yelling about? That statement makes no sense at all! I though you were a native English speaker.
WaltP
Posting Sage w/ dash of thyme
10,474 posts since May 2006
Reputation Points: 3,342
Solved Threads: 938
captcha has long ago been cracked and is no longer reliable. At most it provides a very minor speedbump to amateurs, but it can do nothing to stop these concerted attacks.
Indeed the only way to do it is to require posts to be pre-approved by moderators, which is simply not an option for high volume sites like Daniweb (though a system of community moderation, where people with say 1000 posts and at least 2 years' membership can see such posts and get an "approve" button could possibly work to at least get the bulk approved).
Switching to openID for account management might be an option, but merging existing accounts will be a major pain (and openID isn't perfect by far, I've several times lost accounts there when they once again did something to their systems, and unable to either recreate them with the same name or recover them by any means, so apparently the name is still claimed but can no longer be accessed, thank providence for a personal domain and being able to create email addresses on the fly).
jwenting
duckman
8,392 posts since Nov 2004
Reputation Points: 1,662
Solved Threads: 337
Those spammers are really ' hardworking ' after all. They actually bother to change the language every time they spam.
jingda
Industrious Poster
4,698 posts since Mar 2011
Reputation Points: 182
Solved Threads: 142
Well looks like we can see what the main feature of dooms day (the end of the world) will be. The internet being bumped offline due to spammers sending so much spam to every forum and every blog. G' how I hate spammers. But I guess they are what add security to the online market. :)
cwarn23
Occupation: Genius
3,033 posts since Sep 2007
Reputation Points: 413
Solved Threads: 259
Spammers are but a small part of the ITSec market, to be honest - even if you look at them purely from the perspective of malware distribution they are just a speck on the screen.
happygeek
Freelance Word Punk
27,454 posts since Mar 2006
Reputation Points: 1,457
Solved Threads: 54
What are you yelling about? That statement makes no sense at all! I though you were a native English speaker.
Sorry buddy,im not yelling...
I meant to say "I figured all spammers come from the USA"
The Dude
Nearly a Senior Poster
3,485 posts since Dec 2005
Reputation Points: 1,054
Solved Threads: 31