Board index » General » Trial Minutes

Page 1 of 1[ 16 posts ]
 


NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

元・超会社員級の管理人

Gender: Male

Location: Hiding beneath the judge's desk

Rank: Admin

Joined: Tue Feb 27, 2007 7:05 pm

Posts: 3303

We were recently hit with a very large wave of spambot registrations. Though the vast majority weren't able to activate their account, for safety's sake we've removed any unactivated accounts registered from January 1st, 2014 to now.

If you registered but did not activate your account, you'll need to re-register. If you registered but did activate your account, you should be fine, and if you registered before January 1st you should be good to go in any case.

We've updated our anti-spam measures, so hopefully this won't be an issue again in the future. We're really sorry for the inconvenience!
Hi! I've largely stepped back from C-R due to life stuff. Please contact one of the other staff members for help!

Wooster wrote:
If there was such a thing as the "Wooster Seal of Approval", this post would get it.
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

Fate Testarossa

Gender: Male

Location: Uminari City

Rank: Prosecutor

Joined: Thu Feb 19, 2009 2:29 pm

Posts: 901

Out of curiosity, what are the new measures for combatting the spambots?
Image

Fate is made by クロス
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

元・超会社員級の管理人

Gender: Male

Location: Hiding beneath the judge's desk

Rank: Admin

Joined: Tue Feb 27, 2007 7:05 pm

Posts: 3303

On the off-chance there's actually a spam group reading the forums (granted, that's very doubtful; all the evidence we've seen suggested it's automatic, but to be safe) I'd prefer not to go too much into detail, but the key thing is that we've updated the "are you human" questions to be much more difficult to answer automatically, and we've made the system lock you out quicker if you answer wrong many times (to prevent brute-forcing).
Hi! I've largely stepped back from C-R due to life stuff. Please contact one of the other staff members for help!

Wooster wrote:
If there was such a thing as the "Wooster Seal of Approval", this post would get it.
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

What did he do this time...?

Gender: Male

Location: On trial

Rank: Decisive Witness

Joined: Tue Sep 11, 2012 3:05 am

Posts: 285

On a different website that I am apart of, we had an outbreak of spam that was enormous, but we solved it with a simple trick: each new user has to get their first post approved my a moderator. Although it makes many first-time users a bit confused and they end up double-posting their first reply, it got rid of 99% of the spam problems we had. I have no idea if this site can use that ability, and it's just a suggestion. I just hope the spam gets under control.
Want to play my custom-made Ace Attorney case made on Ace Attorney Online? (you must be using Firefox to run it)
Turnabout Destiny
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

Gettin' Old!

Gender: Male

Location: Scotland

Rank: Ace Attorney

Joined: Fri Jul 11, 2008 4:30 pm

Posts: 14363

Danchat wrote:
On a different website that I am apart of, we had an outbreak of spam that was enormous, but we solved it with a simple trick: each new user has to get their first post approved my a moderator. Although it makes many first-time users a bit confused and they end up double-posting their first reply, it got rid of 99% of the spam problems we had. I have no idea if this site can use that ability, and it's just a suggestion. I just hope the spam gets under control.


Probably would work great but I think the mods are lazy want to hold back such draconian measures and keep the site as easy to access as possible.

We are pretty niche already :ron:
Made by Chesu+Zombee
Image

You thought you could be safe in your courts, with your laws and attorneys to protect you. In this world only I am law, my word is fact, my power is absolute.


Last edited by Pierre on Sun Jan 05, 2014 9:49 am, edited 1 time in total.
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

The Minecraft Attorney

Gender: Male

Location: Playing Something Random

Rank: Desk Jockey

Joined: Sun Jun 30, 2013 5:36 am

Posts: 89

That's sounds really painful for some reason... :beef:

I hope you can find a good way to combat these spammers.
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

Art Person

Gender: None specified

Location: Making Sprites

Rank: Ace Attorney

Joined: Thu Sep 30, 2010 11:23 am

Posts: 3288

I clicked 'Register' to see what you meant by increasing the difficulty of the question, and I understand what you mean now.
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

元・超会社員級の管理人

Gender: Male

Location: Hiding beneath the judge's desk

Rank: Admin

Joined: Tue Feb 27, 2007 7:05 pm

Posts: 3303

Pierre wrote:
Danchat wrote:
On a different website that I am apart of, we had an outbreak of spam that was enormous, but we solved it with a simple trick: each new user has to get their first post approved my a moderator. Although it makes many first-time users a bit confused and they end up double-posting their first reply, it got rid of 99% of the spam problems we had. I have no idea if this site can use that ability, and it's just a suggestion. I just hope the spam gets under control.


Probably would work great but I think the mods are lazy want to hold back such draconian measures and keep the site as easy to access as possible.

We are pretty niche already :ron:


Shh... :karma:

In all seriousness, the option has been brought up before, but it's a bit discouraging to new users to get their posts approved. If the spambots overcome these latest changes, we might wind up doing just that, but we'd prefer not to for the moment.
Hi! I've largely stepped back from C-R due to life stuff. Please contact one of the other staff members for help!

Wooster wrote:
If there was such a thing as the "Wooster Seal of Approval", this post would get it.
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

Chaos wolf

Gender: Male

Location: London, England

Rank: Moderators

Joined: Tue Feb 27, 2007 9:09 pm

Posts: 631

Next step would be banning free email providers for example (which we've done over on one other forum I help admin/mod) and the amount of spam is practically zero. Hopefully it doesn't have to come to that!
Lie with passion and be forever damned...

360 gamertag: Mayhem64
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

Fate Testarossa

Gender: Male

Location: Uminari City

Rank: Prosecutor

Joined: Thu Feb 19, 2009 2:29 pm

Posts: 901

But... Doing that would ban a lot of real members from joining as well. (Like, do most people even have a paid email any more?)
Image

Fate is made by クロス
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

wings of justice

Gender: Female

Location: Amsterdam, Netherlands

Rank: Suspect

Joined: Mon Jan 06, 2014 11:50 am

Posts: 8

I definitely sympathize with spambot problems. :sadshoe: A forum that I help moderate has a kind of tricksy question in place where the answer to the question is not the actual answer but a certain word that's updated my the admin in a sticky thread in one of the public forums, and now we maybe get one bot every couple weeks to a month, as opposed to the several we were getting a day. At one point we actually had to close registration entirely (it was so bad the admin and I were both banning new bots as fast as we could and couldn't catch up), but the new measures seem to have helped prevent it almost entirely. The question you guys have up now seems like it should hopefully help, though. It was easy enough for me to understand and register, but hard for automated software to read. You'll probably get human spammers through it, still, but those are much fewer.
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

ZAWA ZAWA

Gender: Female

Location: Bristol, Rhode Island

Rank: Decisive Witness

Joined: Tue May 14, 2013 10:21 pm

Posts: 173

Ha! I was really curious as to what the new "are you human?" questions could be. Very smart, as you would have to have actually played the games and be able to read l33t speak.
kwando1313 wrote:
But... Doing that would ban a lot of real members from joining as well. (Like, do most people even have a paid email any more?)

No, I don't think really anybody does. Most use gmail (like me), yahoo, and other free ones. Who really wants to pay when you can get it for free?
Of course there are some people who do, and that's totally fine, but I believe most use free providers.
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

Quiet, please, it's snack time!

Gender: Female

Location: Melbourne

Rank: Suspect

Joined: Wed Jan 08, 2014 11:38 am

Posts: 35

Man, I can sympathise. I recently re-opened my forum after a month of downtime and it was a complete spam magnet, with about 50 spam registrations on the first day. >.<'

What I use at the moment, which has cut them down significantly is:
- Stop Forum Spam plugin (available for PhpBB, and I highly recommend you use if you don't already)
- Email filters. You'll find that a lot of the time you'll get a lot of registrations from some email addresses with domain names that are clearly spam (we were getting a lot from places like *@mail.ru)
- Questions on the registration page
- Captcha
- Email validation

I think the last spam account we got was yesterday (even after all that), but that was the first time in at least a week which is a huge improvement over 50 a day.

Unfortunately, you'll never be able to block every spam account. For instance, there's a new thing where humans get paid to register on forums with anti-bot protection, who then give the account details to the spambot to use.

I wouldn't be surprised if somebody soon develops a program that can solve the questions on the registration pages either by using some kind of phrase checking algorithm. I've seen a lot of arithmetic questions around (ie: "What is 2 + 2") which would likely be incredibly easy to identify and break.

Mayhem wrote:
Next step would be banning free email providers for example (which we've done over on one other forum I help admin/mod) and the amount of spam is practically zero. Hopefully it doesn't have to come to that!

I hope by free email providers you don't mean Gmail, Hotmail and alike because you're probably locking out a vast majority of human registrations as well.

Baia_74 wrote:
kwando1313 wrote:
But... Doing that would ban a lot of real members from joining as well. (Like, do most people even have a paid email any more?)

No, I don't think really anybody does. Most use gmail (like me), yahoo, and other free ones. Who really wants to pay when you can get it for free?
Of course there are some people who do, and that's totally fine, but I believe most use free providers.

Well, I have an email address that uses my domain name (dashingforums.com) because I loved the novelty of it all. When I eventually get my online portfolio set up, I'll likely get a domain name for it with my name or something, and then I can make an email address that really stands out from all the Gmails out there. :P
Image
Image
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

Gettin' Old!

Gender: Male

Location: Scotland

Rank: Ace Attorney

Joined: Fri Jul 11, 2008 4:30 pm

Posts: 14363

Man I didn't even know you could pay for email providers. Though looks like the recent upgrade seems to have stemmed the tide for a little bit just now so lets not bring it up again, I'm sure folks won't resort to something that would essentially stop C-R from being a free website.
Made by Chesu+Zombee
Image

You thought you could be safe in your courts, with your laws and attorneys to protect you. In this world only I am law, my word is fact, my power is absolute.
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

Quiet, please, it's snack time!

Gender: Female

Location: Melbourne

Rank: Suspect

Joined: Wed Jan 08, 2014 11:38 am

Posts: 35

Pierre wrote:
Man I didn't even know you could pay for email providers.

Though I should make it clear, I'm not paying for the email provider, I'm just paying for the domain name (ie: the bit after the @ symbol in the email address). [TechGibberish] As for how we actually send and receiver emails, we have a free Mail Transfer and Mail Delivery Agent on the server to take care of that, and then I use Mozilla Thunderbird for the interface because I prefer it over the command line. [/TechGibberish]

I think paid email providers mainly exist for businesses who want added security for their company emails. Unless there's a very edge-case where a forum user really wants added security, then it's a pretty safe bet that he or she is using a free one.

Pierre wrote:
Though looks like the recent upgrade seems to have stemmed the tide for a little bit just now so lets not bring it up again, I'm sure folks won't resort to something that would essentially stop C-R from being a free website.

I would never recommend setting a paid subscription service for a forum because you still need to compete with every other forum in your niche - most of which would be free - and having to pay would be a major turn-off. The only subscription-based forum that actually works AFAIK is Something Awful.

Having said that, there are plenty of anti-spam measures you can put in place and still keep the forum free. It's just that, like I said before, you're never going to stop all of them, especially when there are humans around who can just sign up and give the details to a bot.
Image
Image
Re: NOTICE: Spambot-Related RollbackTopic%20Title
User avatar

Chaos wolf

Gender: Male

Location: London, England

Rank: Moderators

Joined: Tue Feb 27, 2007 9:09 pm

Posts: 631

fantanoice wrote:
I hope by free email providers you don't mean Gmail, Hotmail and alike because you're probably locking out a vast majority of human registrations as well.

Yes, Hotmail and GMail. We were getting 50 spams for every legit signup. We've tempered some of this currently, and between a wealth of other checks we had already implemented (many you mentioned), we've curtailed a lot of the spam thankfully. But for a while, we really did have to nuke being able to signup with Hotmail and GMail because they were still getting through, despite most of the checks. Yahoo and AOL are perma-banned regardless, and anything from China and Russia is too.

The most effective part is definitely the Q&A, so anyone else who has issues, put that plug-in and configure some questions for n00bs to answer. Actual fans WILL know the answers. Spammers generally won't, unless they try to Google them I suppose.

I don't pay for my email hosting per se, but as I have my own web hosting, then mailboxes come as part of that, so I use those for places where "free" signups are restricted.
Lie with passion and be forever damned...

360 gamertag: Mayhem64
Page 1 of 1 [ 16 posts ] 
 
Display posts from previous:  Sort by  

 Board index » General » Trial Minutes

Who is online
Users browsing this forum: No registered users and 33 guests

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum
Jump to:  
News News
Powered by phpBB

phpBB SEO