Jump to content


Photo

Spam Update: Situation Resolved


  • Please log in to reply
20 replies to this topic

#1 Kaeloree

Kaeloree

    Head Molder

  • Administrator
  • 9198 posts

Posted 13 April 2009 - 01:37 AM

Thanks to the speedy work of our moderators, the latest spambot was caught in its tracks, and didn't send out as many messages before it was cut down.

SConrad and I took immediate action as soon as we found out; all PMs from the user "Jurdreda" have now been deleted. (This means that while you may have received an email saying you have a new PM, it will not appear in your inbox, since it has been deleted). Our sincerest apologies about the inconvenience this has caused to members--both current and previous.

In attempting to solve the problem, we have considered a number of different approaches, and the following approach is the one we believe will work best and which we have implemented.

As of now, any new members must make 5 posts before they are able to send or recieve PMs. This change only applies to members registered after the time of posting. Old and current members are not affected by this change.

New members will also see a new info box at the top of the forums, stating why they can't send or recieve PMs and directing them to the Welcome thread. Currently it is fairly rudimentary, but it will be improved over the next week.

Lastly, I want to stress that SHS is no less secure than other websites and forums. Invision Power Board forums all over the web have had to deal with these bots.

Once again, we apologise for any inconvenience this has caused.

Sincerely,
SHS Administration

#2 quinlan

quinlan
  • Member
  • 1172 posts

Posted 13 April 2009 - 01:45 AM

Here is a new one:
jurdreda

My fantasy story

 

"Man, in his discussions with other men about questions of religion, statecraft, geography, trade, has always reached a point in the discussion where it has seemed wise to reply to his opponent by disemboweling him or knocking his brains out."

 

My name is Thomas Hockenberry, Ph.D., and I think the "Ph.D." stands for "Pouring His Draft."

 

"The study of modern science today is being done by the brain of primitive man."


#3 datiswous

datiswous
  • Member
  • 1 posts

Posted 13 April 2009 - 02:32 AM

It isn't possible to use captcha for pm?

#4 Jarno Mikkola

Jarno Mikkola

    The Imp in his pink raincoat.

  • Member
  • 10911 posts

Posted 13 April 2009 - 03:01 AM

It isn't possible to use captcha for pm?

Well yes, but as the latest spamers wave have already by passed that restrictions, it doesn't help... ironic that an individual with post count of 1 would ask that... are you a AI spammer? ^_^

Deactivated account. The user today is known as The Imp.


#5 Asmodeus

Asmodeus
  • Member
  • 3 posts

Posted 13 April 2009 - 03:20 AM

I don't post here anymore, but I keep getting spam e-mails from here and I'm wondering if it's possible to delete my account. I know it's a small problem and shouldn't happen anymore due to the new restrictions you've placed to prevent the spambots sending e-mails, but yeah.

#6 Kaeloree

Kaeloree

    Head Molder

  • Administrator
  • 9198 posts

Posted 13 April 2009 - 03:45 AM

datiswous:
That would mean for every single PM sent, you would have to enter CAPTCHA. Besides it being a fair amount of work on SConrad's side to code the modification, it would be frustrating to people who use the PM system regularly such as myself and many others. Unfortunately while a good idea in theory, in practice it would prove more trouble than it's worth.

Asmodeus:
Generally we prefer not to delete accounts, but if you feel very strongly about it, I can do so.

Thanks for understanding, all. :)

#7 Icendoan

Icendoan

    "An Infinite Deal of Nothing"

  • Member
  • 1723 posts

Posted 13 April 2009 - 04:07 AM

Would it be possible to have CAPTCHA for members with <100 posts and/or been here for less than a month? Usually, in that time, you would still be getting to know everyone here and wouldn't be sending too many PMs for it to be a hassle.

Icen
Proud member of the 'I HATE Elminster!' Club!

Mods in development: Keeping Yoshimo

#8 Jarno Mikkola

Jarno Mikkola

    The Imp in his pink raincoat.

  • Member
  • 10911 posts

Posted 13 April 2009 - 04:21 AM

I don't post here anymore, but I keep getting spam e-mails from here and I'm wondering if it's possible to delete my account. I know it's a small problem and shouldn't happen anymore due to the new restrictions you've placed to prevent the spambots sending e-mails, but yeah.

You can go into your "My Controls" tab after you have logged in and push "Email Settings" and untag the "Send a notification email when I receive a new private message", and that's it, you won't from that point on get any PM Emails.


Would it be possible to have CAPTCHA for members with <100 posts and/or been here for less than a month? Usually, in that time, you would still be getting to know everyone here and wouldn't be sending too many PMs for it to be a hassle.

That would also be even more work...

Deactivated account. The user today is known as The Imp.


#9 -Robert Lewis-

-Robert Lewis-
  • Guest

Posted 13 April 2009 - 08:10 AM

Thanks to the speedy work of our moderators, the latest spambot was caught in its tracks, and didn't send out as many messages before it was cut down.

SConrad and I took immediate action as soon as we found out; all PMs from the user "Jurdreda" have now been deleted. (This means that while you may have received an email saying you have a new PM, it will not appear in your inbox, since it has been deleted). Our sincerest apologies about the inconvenience this has caused to members--both current and previous.

In attempting to solve the problem, we have considered a number of different approaches, and the following approach is the one we believe will work best and which we have implemented.

As of now, any new members must make 5 posts before they are able to send or recieve PMs. This change only applies to members registered after the time of posting. Old and current members are not affected by this change.

New members will also see a new info box at the top of the forums, stating why they can't send or recieve PMs and directing them to the Welcome thread. Currently it is fairly rudimentary, but it will be improved over the next week.

Lastly, I want to stress that SHS is no less secure than other websites and forums. Invision Power Board forums all over the web have had to deal with these bots.

Once again, we apologise for any inconvenience this has caused.

Sincerely,
SHS Administration



#10 -Robert Lewis-

-Robert Lewis-
  • Guest

Posted 13 April 2009 - 08:32 AM

Apologies for repeating the first post, not sure how I did that...

Anyway, thanks for dealing with the spam in a timely manner. It was annoying, but thankfully not dangerous. In truth, the annoyance was greatly minimized, because it also reminded me about the existence of this site...glad to see that Spellhold is still around and active; and Baldur's Gate Mods are still available (it's still one of the best RPGs ever made, and this site has helped keep it alive). Are "works In Progress" still being worked on? Is mod work still being done? I have BG2 loaded on my new computer, in hopes of new and/or updated material.

Anyway, it's great to see that Spellhold is still up and running.

Thanks!

#11 Choo Choo

Choo Choo

    AIR CONDITIONER GRILL

  • Modder
  • 3001 posts

Posted 13 April 2009 - 09:33 AM

Apologies for repeating the first post, not sure how I did that...

Anyway, thanks for dealing with the spam in a timely manner. It was annoying, but thankfully not dangerous. In truth, the annoyance was greatly minimized, because it also reminded me about the existence of this site...glad to see that Spellhold is still around and active; and Baldur's Gate Mods are still available (it's still one of the best RPGs ever made, and this site has helped keep it alive). Are "works In Progress" still being worked on? Is mod work still being done? I have BG2 loaded on my new computer, in hopes of new and/or updated material.

Anyway, it's great to see that Spellhold is still up and running.

Thanks!


The modding part of the community is still very much alive and kicking. :)

theacefes: You have to be realistic as well, you can't just be Swedish!


#12 -Robert Lewis-

-Robert Lewis-
  • Guest

Posted 13 April 2009 - 09:56 AM

The modding part of the community is still very much alive and kicking. :)
[/quote]


Great News!
Thanks, Choo Choo!

#13 SConrad

SConrad

    I swear to drunk I'm not God

  • Administrator
  • 11148 posts

Posted 13 April 2009 - 04:59 PM

For those of you suggesting CAPTCHA for PMs, you're probably overlooking the fact that these spambots already have cracked the CAPTCHA when registering. It doesn't matter if we throw a hurdle at spambots a 100 times if they can overcome it.

quinlan: Thank you for reporting it, but it has already been dealt with. If you take a closer look, you'll notice that the jurdreda incident happened before this topic was posted--we applied this fix just after it happened. You'll also note that all of the PMs it sent out are gone.

Posted Image Khadion NPC mod - Team leader, head designer
Posted Image Hubelpot NPC mod - Team leader, coder
Posted Image NPC Damage - Coder
Posted Image PC Soundsets - Coder, voice actor
Posted Image Brythe NPC mod - Designer
Posted Image DragonLance TC - Glory of Istar - Designer
Posted Image The NPC Interaction Expansion Project - Writer for Cernd, Sarevok
Posted Image The Jerry Zinger Show - Producer

Iron Modder 5 - Winner


#14 Petrell

Petrell
  • Member
  • 2 posts

Posted 13 April 2009 - 10:56 PM

Well, it gave me reason to log in to my account. After so many years of just lurking I had even forgotten I had an account here :P

Edit: Aparently I'm proffessional lurker as this seem to be my first post having been member for 4 and half years :D

Edited by Petrell, 13 April 2009 - 11:07 PM.

Petrell's Domain Webmaster


#15 Kulyok

Kulyok
  • Modder
  • 2450 posts

Posted 13 April 2009 - 11:19 PM

I'm afraid spam keeps arriving to my SHS PM box. Maybe G3 way(they forbid sending more than one PM in five minutes) is worth it: I haven't received a single spam PM at G3 since.

#16 Neferit

Neferit

    In the name of Gaider, we fight!

  • Member
  • 414 posts

Posted 13 April 2009 - 11:23 PM

Yeah, there is another spam message in my message box. This time by user "terkovskyr". :huh:
Heck no, b - I used the word the way I use things like "twitter", and "iPod" - my first inclination is to ask "what birdcall are you studying?" and I think of "I pod, You (singular) pod, He pods, She pods, They pod, You (plural) pod, We pod..."

 

Writings ►☼◄ Visual Shiny Pretties ►☼◄ Another Writings

 

►☼◄


You think you still have some brain in your head?

 


►☼◄►☼◄

 

 


#17 Jarno Mikkola

Jarno Mikkola

    The Imp in his pink raincoat.

  • Member
  • 10911 posts

Posted 13 April 2009 - 11:24 PM

I got another suspicious PM from terkovskyr 'Win prizes.' <_<

Deactivated account. The user today is known as The Imp.


#18 Petrell

Petrell
  • Member
  • 2 posts

Posted 13 April 2009 - 11:48 PM

I got another suspicious PM from terkovskyr 'Win prizes.' <_<


same here

Petrell's Domain Webmaster


#19 Kaeloree

Kaeloree

    Head Molder

  • Administrator
  • 9198 posts

Posted 14 April 2009 - 02:33 AM

Thanks all; as explained here:

The reason this one got through is that our countermeasures only affect all new users as of yesterday. There must be several sleeper accounts already registered. SConrad and I are just about to spend some time fixing the issue, and I'll post when it's been solved.

Apologies again for the spam; all PMs from terkovskyr have now been deleted.


What we've done is to extend the new PM changes to anyone registered in the month of April, as the spambots seem to have registered within this period. With any luck that'll be the last we'll see of them.

A note to those wondering why we haven't gone with the "official solution"--this "patch" is nothing more than a stopgap. It will slow down spambots, but it doesn't prevent them from sending PMs--in fact, they can still send a PM every 5 minutes, meaning that they could send up to 288 messages a day. We put a lot of thought into how we would solve the problem, and we believe that we've chosen the best method.

Once again, I'm sorry for the inconvenience this has caused everyone--it's been a frustrating few days for everyone!

#20 HERD

HERD
  • Modder
  • 283 posts

Posted 15 April 2009 - 03:27 AM

Hi, I 've read posts about spam,
and I am not sure if these messages that I am getting is a part of the solution or ...
I sent a PM to a member of SHS long time ago and now whenever I not even log in, but just check the SHS site it sends me the same reply over and over and over. I know it is not spam, but it appeares every time I click on SHS link.
Could it be my settings?