We haf returned! (New Spam Thread)

Post here if you have a problem with your account.
Kison
.GIFted
 
User avatar
Joined: January 22, 2007
Location: San Diego, CA

Post Post #550  (ISO)  » Sat Dec 23, 2017 12:30 pm

Enabled the Nuke extension & added you to the admin & nuke user groups. You can mass delete here.

We'll need to figure out how to prevent these from occurring in the first place. They are getting in through the forum registration despite turning on reCAPTCHA a few weeks ago.

callforjudgement
Mafia Scum
 
User avatar
Joined: September 01, 2011

Post Post #551  (ISO)  » Sat Dec 23, 2017 2:18 pm

Hundreds of spam pages deleted. I did some searches to make sure I didn't miss any ("number" is a good search term, that's in the title of basically every spam page) and cleaned up a few stragglers; I've also checked the entire length of Recent Changes expanded to its maximum size.

This particular spam attack appears to be using humans to bypass the CAPTCHA (we've used some really unusual CAPTCHA solutions on other wikis and it's still been solved). Perhaps requiring posts on the forum before posting would work, but I fear that it would instead tend to lead the spammers to post junk posts in Queue just to get round the restriction. Some solutions that have seemed to help on other wikis: requiring edits to existing pages before new pages can be created (e.g. Wikipedia requires ten, but even one seems to work); and a regex-based title blacklist (searching for 10 digits preceded or succeeded by "number" is unlikely to have many if any false positives, and would match almost all (all?) the spam pattern we've seen. The former can be done with a configuration change (set "autoconfirmed" to 1 edit and 0 days, then remove the ability for non-autoconfirmed users to make pages). The latter can, AFAIK, only be done with the help of an extension; my preferred extension for that is AbuseFilter, as it's incredibly flexible and can be configured to implement more or less any spam-fighting rule you'd want.

(Just for some context, I'm currently an admin on some fairly small wikis, and was an admin at Wikipedia for a while, so I'm fairly experienced with this sort of spamfighting. I'll have to remember to check Recent Changes more often, though.)
scum · scam · seam · team · term · tern · torn · town

Kison
.GIFted
 
User avatar
Joined: January 22, 2007
Location: San Diego, CA

Post Post #552  (ISO)  » Sat Dec 23, 2017 5:33 pm

Alright, added AbuseFilter. You should have access to it.

callforjudgement
Mafia Scum
 
User avatar
Joined: September 01, 2011

Post Post #553  (ISO)  » Sat Dec 23, 2017 5:44 pm

Hmm, something seems wrong with how it's installed, I get an Internal Server Error trying to do anything with it. (For example, the "check syntax" button on the filter creation screen.)
scum · scam · seam · team · term · tern · torn · town

Kison
.GIFted
 
User avatar
Joined: January 22, 2007
Location: San Diego, CA

Post Post #554  (ISO)  » Sat Dec 23, 2017 6:00 pm

Give it a shot now. Looks like the version we had wasn't compatible with our version of mediawiki.

callforjudgement
Mafia Scum
 
User avatar
Joined: September 01, 2011

Post Post #555  (ISO)  » Sat Dec 23, 2017 6:11 pm

OK, I've added an Abuse Filter rule that, out of the ~400 or so edits I tested it against (via batch testing, not individually), should stop all the spam we've seen so far and yet have no influence on legitimate changes.

I've only set the rule to prevent the edits, not to apply any further consequences, so that if I've made a mistake and there are false positives, the worst that will happen is that the edit won't go through; there won't be any automatic blocks or the like applied yet.

If the rule turns out to be successful, I can expand it to block users if they appear to be spamming as their first edit.
scum · scam · seam · team · term · tern · torn · town

Kison
.GIFted
 
User avatar
Joined: January 22, 2007
Location: San Diego, CA

Post Post #556  (ISO)  » Sat Dec 23, 2017 6:24 pm

Awesome, thanks a ton for the help!

animorpherv1
Honey Trap
 
User avatar
Joined: April 12, 2008
Location: Untraveled Road
Pronoun: He

Post Post #557  (ISO)  » Thu Feb 22, 2018 11:16 pm

I'm a jack of all trades and a master of one. I may not be the best but I can still whoop ass.

Get to know an ani!

Klick
 
User avatar
Joined: September 01, 2012

Post Post #558  (ISO)  » Mon Mar 05, 2018 12:48 am

In post 5, angelahall wrote:Your version is pretty interesting too! I will try to play it with my friends in the nearest time. I hope that this will be funny

This has been here for a little while. Clever spam account. Link is in the sig.

MathBlade
Survivor
 
User avatar
Joined: September 09, 2013
Location: Western US
Pronoun: He

Post Post #559  (ISO)  » Fri May 04, 2018 10:34 am

viewtopic.php?f=5&t=76173

Please ban this bot/user for advertising.
ScumBlade's eloquent performance left me utterly disoriented, debased, depraved and sent me spiraling into a horrific murky abyss with emotional turmoil and immense despair as my only companions until slowly I suffocate in my own gloom, surrounded by failure. I will never recover. -- Zachstralkita about Mini 1841
GTKAS -- MathBlade

singletonking
Townie
 
User avatar
Joined: June 06, 2018
Pronoun: He

Post Post #560  (ISO)  » Thu Jun 07, 2018 6:32 am

Alt of BulletNLynchproof. To eventually replace BNL as the main account.
GTKAS

Klick
 
User avatar
Joined: September 01, 2012

Post Post #561  (ISO)  » Wed Sep 05, 2018 8:52 am


Previous
[ + ]

Return to Help!