Spam, it doesn't taste good even with mustard

jedion357's picture
jedion357
September 14, 2012 - 1:54am
this morning was the second time I nailed a robo spammer in the process; they usually start 5 threads and I had just deleted five by mycheapnike and then answered some email and was considering posting some ideas. When I got back here there was a new spam log in and it had posted its first thread, I managed to delete its login name before it could post another.

I was thinking about the registration procedure for this site in how it asks the question, "Are You human?" and how that is apparently not stopping the machine spammers. One clear way to know if a log in is not a spammer is if they choose an avatar picture. I wonder if posting a statement somewhere in the registration process that says choose an avatar picture would not mess up this process? Don't put it near the field for choosing an avatar and we can include the gray silhouette/no avatar for people to pic but without having taken that step you cannot register.

I was also wondering about some other question like:

"Jack and Jill went up the hill to fetch a pail of ___________?

or
"How much wood would a wood chuck chuck if a wood chuck could chuck _______________?
I might not be a dralasite, vrusk or yazirian but I do play one in Star Frontiers!
Comments:

Shadow Shack's picture
Shadow Shack
September 14, 2012 - 2:24am


If this site uses the allegedly spam proof captcha (and truthfully, this also applies to the basic "are you human" Q), here's the basic problem: It doesn't work against live spammers. 

While nobody in the western world would opt for this route, there are other places in the world where $3/day will put a roof over your head and you'd better believe this is a booming industry in said places. See, the spam-bots look for forums and shoot the URLs over to the live spammers in order to get past the captcha, who in turn post their spam/subscribe to the threads* and then turn the accounts back over to the bots.

Which explains the horrific abuse of the English language in said spam posts. All they have to do is match those funny shapes in the box to corresponding shapes on the keyboards, english mastery be damned...and then use any of the various translator sites to post the spam itself. Hence the typical "if like but and or buy this product by and clicking these link" nature of the spam posts.




Anyone remember me posting "don't reply to spam" warnings in the past? There ya go. Those active threads get noticed by the bots who come back with their valid accounts to go buck wild with more spam, and then "sell" the live URLs to other spam bot owners who, in turn, send the URLs over to their third worlder live spam agents to register new accounts for their bots to post from.
I'm not overly fond of Zeb's Guide...nor do I have any qualms stating why. Tongue out

My SF website

Shadow Shack's picture
Shadow Shack
September 14, 2012 - 2:27am
Dr. Shaduece in his Shack wrote:
I am Spam
Spam I am

That Spam-I-am!
I do not like
that Spam-I-am.

Do you like
green eggs and spam?

I do not like them,
Spam-I-am.
I do not like
green eggs and spam.

I'm not overly fond of Zeb's Guide...nor do I have any qualms stating why. Tongue out

My SF website

jedion357's picture
jedion357
September 14, 2012 - 4:16am
They usually spam in the wee hours of the morning- about 1-2/week I'm deleting 5 or more threads first thing in the moring unless I wake up around 3-4am and check the computer. there is something very satisfactory about deleting a spam account even as its trying to post
I might not be a dralasite, vrusk or yazirian but I do play one in Star Frontiers!

Malcadon's picture
Malcadon
September 14, 2012 - 4:52am
I like the idea of questions. What about:

There once was a lady named Dot
Who lived off of pork-grinds and snot
When she ran out of these
She ate the green cheese
That she grew on the sides of her ____


or:

There once was a man from Montanna
Who said he could play the pianna
His finger slipped
His zipper ripped
And out came a hairy _______

Tongue out

jedion357's picture
jedion357
September 14, 2012 - 5:09am
Well if it is a human doing the captcha and it goes back to a machine, would it be possible to have a captcha come up the first time someone tries to post as a final security feature against robo spam?
I might not be a dralasite, vrusk or yazirian but I do play one in Star Frontiers!

Anonymous's picture
w00t (not verified)
September 14, 2012 - 8:09am
I've added "double lines" and "dots" to the captcha, hopefully that might quell the robotic human spammers. Notice their all humans, not drals, yaz or vrusk. Tongue outFoot in mouth

TerlObar's picture
TerlObar
September 14, 2012 - 9:18am
On my site I had a question like that I required for login and I found that in almost all cases, the spam bots were ignoring it and leaving it as the default, "I'm human".   So I changed the default choice to "I'm a sathar spam-bot" and did not allow registration if that choice was selected.  My rogue computer bot accounts vanished overnight.  Maybe add such a question to the create new account part of the form and see what happens.
Ad Astra Per Ardua!
My blog - Expanding Frontier
Webmaster - The Star Frontiers Network & this site
Founding Editor - The Frontier Explorer Magazine
Managing Editor - The Star Frontiersman Magazine

Anonymous's picture
w00t (not verified)
September 14, 2012 - 10:08am
Shadow Shack wrote:
Anyone remember me posting "don't reply to spam" warnings in the past? There ya go. Those active threads get noticed by the bots who come back with their valid accounts to go buck wild with more spam, and then "sell" the live URLs to other spam bot owners who, in turn, send the URLs over to their third worlder live spam agents to register new accounts for their bots to post from.

I do and it was good advice. With Tom^2 helping me remove spam on this site we shouldn't have too many issues. Most of us know not to click on spam links. We had a spammer on the DwD site that was responding to post but buried links in their replies. That has to be human driven. :-)

Tom S. - the version of captcha on this site uses image or math, no questions. We'll have a better version on StarFrontiers 2.0 



jedion357's picture
jedion357
September 14, 2012 - 10:17am
TerlObar wrote:
On my site I had a question like that I required for login and I found that in almost all cases, the spam bots were ignoring it and leaving it as the default, "I'm human".   So I changed the default choice to "I'm a sathar spam-bot" and did not allow registration if that choice was selected.  My rogue computer bot accounts vanished overnight.  Maybe add such a question to the create new account part of the form and see what happens.


That would be nice, how hard is it to do this?
I might not be a dralasite, vrusk or yazirian but I do play one in Star Frontiers!

Rotten's picture
Rotten
September 14, 2012 - 10:29am
I am new here and not a spammer.  Thank you for your efforts.

*Confirming my humanity* 

TerlObar's picture
TerlObar
September 14, 2012 - 10:29am
It is just a custom user profile field that was required at login and checked before allowing the registration to continue.  I think it can be done in Drupal but I'm not sure about the old Drupal 5 that this site is written in.  On the .info site I'm using phpBB3 not Drupal and it was easy enough to set up. 
Ad Astra Per Ardua!
My blog - Expanding Frontier
Webmaster - The Star Frontiers Network & this site
Founding Editor - The Frontier Explorer Magazine
Managing Editor - The Star Frontiersman Magazine

Shadow Shack's picture
Shadow Shack
September 14, 2012 - 1:50pm
jedion357 wrote:
Well if it is a human doing the captcha and it goes back to a machine, would it be possible to have a captcha come up the first time someone tries to post as a final security feature against robo spam?

No, because the human spammer overseas is doing the initial posting. Only after posting/subscribing does he turn it over to the bot.

One board I help moderate used to have a great measure, but it pissed off everyone that joined. Basically you couldn't post links and pics until a certain time period and post count requirement was met. It staved off all but the most resilient of spammers, and really...the broken english from the translator software tipped us off to watching those few that were resilient.

But boy howdy did the complaints come in for "why don't you use captcha instead?" 

And we reluctantly switched, and now we spend more time dealing with spam than discussing the board topics. I hate captcha. More than I hate the sathar.
I'm not overly fond of Zeb's Guide...nor do I have any qualms stating why. Tongue out

My SF website

jedion357's picture
jedion357
September 14, 2012 - 4:57pm
Re: shadow's comments on the non captcha screen

Well, Really, lets talk about this, a big majority of people register and dont post, a slice more register and post a time or two and a select few register and jump right in because they decide that this site is the greatest thing since rolled toillet paper. But really, how often do we post links? Yeah, Yeah, I know, I just posted a few but its the exception not the rule. I think we could tighten up things to make it a pian for the spammers to bug us rather then the spammers making it a pain for us to delete their crap.

1. leave in the captcha for registration
2. switch the default answer for "are you human"
3. and not allow new registrants to post a link for a trial period of time. Now I know that shadow mentioned that this went hand in hand with a requirement to have posted a certian number of times and if that was put in place you could use the rankings that some forums use: Midshipman, Jr Lt, Lt, Captain, etc. a New registrant starts with the title of Probie and after 5 posts they become a Midshipman or whatever the title will be and then then the system allows only midshipman to post links.

Frankly, I find the spammers seriously obnoxious and really love it if we were a little more proactive against those bastards. Yes, I used vulgarity because I'm ticked.
I might not be a dralasite, vrusk or yazirian but I do play one in Star Frontiers!

Stelk's picture
Stelk
September 15, 2012 - 1:04am

I was going to throw in my 2 cents but I was unsure of the exchange rate to credits
in the SF's universe so i am going to remain silent.
I do agree that spam is not the health food that some claim it to be and it can really
mess things up.

The down fall to the different levels of rating people by the # of posts is, it forces or
influences a sorta spam all of its own because of the 'cool new title" I get when I hit
a certain amount of posts.

Some people will post pseudo-spam, if you will, just to hit that next level.
Cogito ergo sum; I think therefore I am.

Batty
[Blade Runner]
I've seen things you people wouldn't believe. Attack ships on fire off the shoulder of Orion. I watched C-beams glitter in the dark near the Tannhauser gate. All those moments will be lost in time... like tears in rain... Time to die.

jedion357's picture
jedion357
September 15, 2012 - 4:17am
Stelk wrote:

Some people will post pseudo-spam, if you will, just to hit that next level.


Ok so no titles but I still like the idea of you have to wait to post a link- 5 post and or 3 days, its not really an inconvience for 99% of the members unless you are a spammer. And getting a new member posting is actually healthy for the forum.
I might not be a dralasite, vrusk or yazirian but I do play one in Star Frontiers!

OnceFarOff's picture
OnceFarOff
September 15, 2012 - 8:01am
I just joined RPG net and had to wait until I had 10 posts before my account was valiated. It wasn't that much of a hassle.