Spammers *war* next phase...

Spammers *war* next phase...
Article
Post Spammers *war* next phase... 
 
Hi, I'm here entertaining you with some new boring technical data   of what will be my strategy and the next changes on the site.

Actually each page of the site has a couple of "booby traps" for spammers, they are links that can't be seen by a "human" but that a non human bot will follow going to the spammer honey pot. If the bot is from a search engine nothing will happen, if the ip address is not from a search engine the information will go to "project honey pot" giving to the ip address the rank of "harvester or spammer bot", the result is that if this bot go to a lot of honey pots installed on different sites, its rank as offending IP address increases and here comes the second part:

If it's a known IP, already ranked at project honey pot, it can't access the site, the spammer go to a dedicated page instead, a document explaining theat spamming and harvesting on the site is not allowed.

offending IPs targeting PF can be seen here : http://www.projecthoneypot.org/bsh_...J5PTE.?rf=42267
 
(the italian one is the IP of Alcide , due to his particular network here in Italy , I had to specifically exclude it from the function and it's the reason why I sent that email to the active users because it could happen to legitimate users too)

All these countermeasures will ease a lot my daily work in checking the credential of new registrations but it won't stop ALL the attempts. but however, I'll see how the situation evolves in the next weeks, if the rate of the spammers decreases a lot my project is to:

-uninstall the actual "approval" mod for new users that is no more working properly
-install a mod that disallow posting of attachments and external links to new users or users not in a certain group
-go back to the simpler "activation by email" method instead of the actual "admin activation"
-rest on the sofa watching TV  

The actual way the site is set is causing some troubles, because people has to wait me for the approval (and i can be sleeping , at work or away) and someone become angry because they have to be approved a second time when the begin to post, so I have to change strategy.

The goal of the comment spammers is to place links to the sites they are advertising on all the possible places , all these links go on sites that sell Viagra, porn or online gambling/casino site. Why ? because people want to go there, you can read an interview with one of those individuals here : http://www.theregister.co.uk/2005/01/31/link_spamer_interview/ , and what they do is LEGAL unless elsewhere stated, this is the reason why I changed the agreement for that one has to agree during the registration process.

We have also some tries to hack the site with some code "injection" , they are stopped by the crackertracker and logged so that I can ban the IP address, good news is that those "hackers" are using the same open proxies of the spammers so they should fall in the honey pot too.



 
 Tormie [ 04 Feb 2008 17:35 ]


Spammers *war* next phase...
Comments
Post Re: Spammers *war* next phase... 
 
After a week I'm glad to say that about the 90% of spam traffic has been cought by the traps The rest has been stopped by the antispam filter So this system is working and the site is returned simple to register as it was in the past...

I've also installed a "claymore" trap invented by myself   , the spammer bots don't read the "terms and conditions" of the registration page... Mmmmh... Ok NO ONE does, however the difference is that a human has to click the "accept" button while the bot gives to the site the direct link to the following page , something with "register?agreed=true" at the end of the address, so now when one clicks the button the link has changed to somehting different (with "registar" instead of "register" in the link...) while if the site receives the old link it's obvious that it's a bot, so it is pulled directly in the honey pot, the claymore ignites and it goes directly into the big black list ...


( )



 
 Tormie [ 11 Feb 2008 22:58 ]
Post Re: Spammers *war* next phase... 
 
Smarty, eh?   



 
 ahjah [ 11 Feb 2008 23:02 ]
Post Re: Spammers *war* next phase... 
 
Great news!  



 
 JanReinar [ 11 Feb 2008 23:15 ]
Post Re: Spammers *war* next phase... 
 
Just in case your spammers boobie traps miss the mark, I've added some additional security in the clubhouse.
Be careful about where you sit, I've added exploding woopie cushions in some of the chairs.
I've recorded tormies cat meowing like a lion on fire (after he's smelled tormies old dirty slippers one too many times), this will be played whenever someone tries to come in a locked window.
Also watch where you step, I've put "penguin" land minds around the permiter of the clubhouse (they stink worse than tormies farts!)
Speaking of Tormies farts, I've sucesfully bottled them and have set them up as boobie traps at all entry doors.
If that isn't enough, I have one last secret weapon, I"ve place a giant poster sized picture of my ex-husband on the door to the safe which should pretty much scare or kill any intruders that happen by

Hope this helps tormie



 
 guiltypleasures [ 13 Feb 2008 02:39 ]
Post Re: Spammers *war* next phase... 
 
I've added exploding woopie cushions in some of the chairs


Thats our Guilty!   



 
 tda42 [ 13 Feb 2008 02:58 ]
Post Re: Spammers *war* next phase... 
 
lol, yep that's me!
Oh and I forgot, I also put some tuna oil on all the door knobs, that should do the trick too



 
 guiltypleasures [ 13 Feb 2008 03:01 ]
Post Re: Spammers *war* next phase... 
 
Not to mention really smelly hands too.



 
 tda42 [ 13 Feb 2008 03:06 ]
Post Re: Spammers *war* next phase... 
 
       I want someone of those exploding woopie cushions , rofl  



 
 Tormie [ 13 Feb 2008 08:42 ]
Post Re: Spammers *war* next phase... 
 
A little update: all my boopie traps and the poo poo in the garden are keeping out spammers . It's a kind of fun to read the log, one can see the strategy used: everyone of this spammers uses an open proxy, I got tired to ban all that addresses, it's useless because they are thousands and the site seems to resist to Denial Of Service attacks.

However here is some of the tries in the last week, most of them coming from Poland

Code: [Download] [Hide] [Select]
ID      User      IP      Time      Action      Proxy      Country      Error      Browser      
347     fht5hjrgfd     82.177.193.25     2008 Jun 25 23:23     New registration (with website: www.g-g.seokatalogi.waw.pl/kategoria_25.html)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
346     jhfdgf324     89.161.208.96     2008 Jun 24 23:22     New registration (with website: www.samopomoc-zycie.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
345     qwe23r2ea     82.177.193.25     2008 Jun 24 23:09     New registration (with website: www.wiersze.seonet.az.pl/index.php?pozycja=w)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
344     fdhgfdq32     89.161.208.96     2008 Jun 24 00:14     New registration (with website: www.trendblog.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
343     hgstfrd45     89.161.208.96     2008 Jun 24 00:03     New registration (with website: www.pre-ink.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
342     kgdasfd435     89.161.208.96     2008 Jun 24 00:01     New registration (with website: www.solodruk.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
341     hgfjd54365     89.161.208.96     2008 Jun 23 23:58     New registration (with website: www.solektor.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
340     gfdhs354     89.161.208.96     2008 Jun 23 23:56     New registration (with website: www.automatysamotuszujace.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
339     546wsdgd     89.161.208.96     2008 Jun 23 23:54     New registration (with website: www.usbstick.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
338     6547wsgfd     89.161.208.96     2008 Jun 23 23:53     New registration (with website: www.tylkokulturystyka.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
337     546fdgas     89.161.208.96     2008 Jun 23 23:51     New registration (with website: www.trybunarobotnicza.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
336     fjsdfjh     89.161.208.96     2008 Jun 23 23:48     New registration (with website: www.venomcarz.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
335     6573443rstg     89.161.208.96     2008 Jun 23 23:45     New registration (with website: www.zaplanujrodzine.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
334     fhs25     89.161.208.96     2008 Jun 23 23:43     New registration (with website: www.warez.biz.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
333     gfhtrs     89.161.208.96     2008 Jun 23 23:41     New registration (with website: www.wsanok.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
332     rfdgrd4325324     89.161.208.96     2008 Jun 23 23:40     New registration (with website: www.taniebranie.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
331     78tyjghdfg234     82.177.193.25     2008 Jun 23 23:30     New registration (with website: www.opy.seonet.bytom.pl/kategoria_14.html)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
330     hddsh1324     89.161.208.96     2008 Jun 23 23:27     New registration (with website: www.salzburgerland.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
329     tv-tron     82.160.94.10     2008 Jun 22 23:22     New registration (with website: transmet.net.pl)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
328     likantropus_dei_01     82.160.94.10     2008 Jun 21 23:17     New registration (with website: haa.pl/okna-pcv/)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
327     erg4hrthregsdf     82.177.193.25     2008 Jun 20 23:06     New registration (with website: www.gg.seoonet.info/kategoria_31.html)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
326     erg4hrthregsdf     82.177.193.25     2008 Jun 20 23:06     New registration (with website: www.gg.seoonet.info/kategoria_31.html)     -     PL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
325     B4R3K     88.198.8.17     2008 Jun 20 20:17     New registration (with website: sbiznes.pl/)     -     DE     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
324     B4R3K     88.198.8.17     2008 Jun 20 17:33     New registration (with website: pomagamy.org)     -     DE     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
323     javox111     83.149.125.34     2008 Jun 20 03:31     New registration (with website: arthan.pl)     -     NL     -     Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)     
      
Page Page: profile.php
Parameters: cpl_mode=all&agreed=true&CONFIRM=CONFIRM&acceptterms=true&greed=true&YesIAgree=Accept&Yes_I_agree=true&tobeagreed=true&AgrEEmENT=true&aGReED=true
http_referer:
[Ban user] [Exclude User] [Ban IP address] [Exclude IP] [Probe] [Exclude Browser]
    
322     020705mt     89.161.163.203     2008 Jun 20 01:32     New registration (with website: www.gry.tm.pl)     -     PL     -




 
 Tormie [ 26 Jun 2008 18:38 ]
Post Re: Spammers *war* next phase... 
 

Wow!

Tormie's got skills!! (spammers beware!)  








 
 Whazizname [ 27 Jun 2008 13:14 ]
Display posts from previous:
HideWas this topic useful?
Page 1 of 1
 
 

Users browsing this topic: 0 Registered, 0 Hidden and 1 Visitor
Registered Users: None