AlliedModders

AlliedModders (https://forums.alliedmods.net/index.php)
-   Off-Topic (https://forums.alliedmods.net/forumdisplay.php?f=15)
-   -   is this site get hacked? an invalid thread and user appears in Sourcemod - General (https://forums.alliedmods.net/showthread.php?t=344895)

little_froy 12-18-2023 03:29

is this site get hacked? an invalid thread and user appears in Sourcemod - General
 
1 Attachment(s)
the user named "validhack"
I think this site is very old, should improve the security.

mlibre 12-18-2023 08:08

Re: is this site get hacked? an invalid thread and user appears in Sourcemod - Genera
 
are spambot

DarkDeviL 12-18-2023 16:35

Re: is this site get hacked? an invalid thread and user appears in Sourcemod - Genera
 
Quote:

Originally Posted by little_froy (Post 2814604)
the user named "validhack"

Please just use the Report Post (https://forums.alliedmods.net/images/buttons/report.svg) button below the user's profile.

Both when you see stuff like this, but also if there are other posts that you feel may be in violation with the AlliedModders Rules.

Quote:

Originally Posted by mlibre (Post 2814614)
are spambot

Correct.

Quote:

Originally Posted by little_froy (Post 2814604)
I think this site is very old

The problem, regardless the age of the site, is that these spam bots are getting more and more "sophisticated":

I once saw something that looked like a spam bot, so therefore I triggered an infraction causing a ban, with a reason like "Spam bot? - Appeal via Contact Us, if you're real.".

I was surprised to see that potential spam bot return and spam again, but it appeared that it had been appealing about the ban, and due to the appeal, it was apparently considered real by someone else.

Quote:

Originally Posted by little_froy (Post 2814604)
should improve the security.

Although you can get a long way, with a lot of effort, the result you eventually notice, isn't going to be the same forever.

Changing to another kind of forum isn't going to help, or magically fix the problem either.

Spam bots are learning your layers of defence, which means to be pro-active, it requires you to be constantly on guard, and be adapting to new things.

That rarely works that well, together with things driven by volunteers.

There is simply no permanent fix to the problem, regardless what you do (or don't do).

mlibre 12-21-2023 15:16

Re: is this site get hacked? an invalid thread and user appears in Sourcemod - Genera
 
a simple captcha in the login or in the comment boxes would be enough, I bet these bots are so noob that they couldn't overcome the challenge.

Ryan2 12-22-2023 02:25

Re: is this site get hacked? an invalid thread and user appears in Sourcemod - Genera
 
Quote:

Originally Posted by mlibre (Post 2814780)
a simple captcha in the login or in the comment boxes would be enough, I bet these bots are so noob that they couldn't overcome the challenge.

I posted about this at the beginning of the year.

https://forums.alliedmods.net/showthread.php?t=341302

Most of the spam accounts are hijacked accounts with legit post history etc. This forum needs to reset everyone's password if they want to stop this.

Of course a year past almost and nothing has been done.

mlibre 12-23-2023 07:08

Re: is this site get hacked? an invalid thread and user appears in Sourcemod - Genera
 
fixed :idea:

Quick Reply
Message: Hello friends, I bring you an incredible special offer, you cannot miss it...
Rant:
3x-8=x?
  • 1
  • 4
  • 7

Post Quick Reply | Go Advanced

Jhob94 12-23-2023 13:20

Re: is this site get hacked? an invalid thread and user appears in Sourcemod - Genera
 
Quote:

Originally Posted by mlibre (Post 2814828)
fixed :idea:

Quick Reply
Message: Hello friends, I bring you an incredible special offer, you cannot miss it...
Rant:
3x-8=x?
  • 1
  • 4
  • 7

Post Quick Reply | Go Advanced

That would block more real users that suck at math and some spambots would still bypass it :lol:

DarkDeviL 12-23-2023 14:16

Re: is this site get hacked? an invalid thread and user appears in Sourcemod - Genera
 
Quote:

Originally Posted by mlibre (Post 2814780)
a simple captcha in the login or in the comment boxes would be enough

No, unfortunately not.

Quote:

Originally Posted by mlibre (Post 2814780)
I bet these bots are so noob that they couldn't overcome the challenge.

While some bots may be "so noob", as you explain, many of them aren't.

Quote:

Originally Posted by Ryan2 (Post 2814788)
I posted about this at the beginning of the year.

The issue you posted about, was regarding existing - but hijacked accounts.

This thread is about new spam bot registrations.

Account 355909 (literally named "validhack") was created on 2023-12-18, and posted it's junk on on 2023-12-18 06:54 (CET, +0100).

Quote:

Originally Posted by Ryan2 (Post 2814788)
Most of the spam accounts are hijacked accounts with legit post history etc.

That one is actually false.

It does happen like that, but it definitely isn't the most of it that has an existing legit post history and/or old account creditability, in the way as you say.

Quote:

Originally Posted by Ryan2 (Post 2814788)
This forum needs to reset everyone's password if they want to stop this.

I don't really agree with the "everyone's" part though, however, something like that may also become useful, in regards to stopping the problem with the existing - but hijacked accounts.

Having a mandatory password reset, such as if you've been gone from the forums for e.g. 3 months, or 12 months, before you can access the forums again, could be a way of reducing the impact of that specific issue.

But again, a such thing won't prevent the kind of junk that this specific thread is targetting.

Quote:

Originally Posted by Ryan2 (Post 2814788)
Of course a year past almost and nothing has been done.

What exactly do you expect to be done, explained down to the smallest detail?

Quote:

Originally Posted by mlibre (Post 2814828)
fixed :idea:

A such kind of captcha, or any other kind of captcha, even if you create your own customized one, it will proving it's effect for a very limited amount of time.

As I said above:

Quote:

Originally Posted by DarkDeviL (Post 2814638)
Spam bots are learning your layers of defence, which means to be pro-active, it requires you to be constantly on guard, and be adapting to new things.

Quote:

Originally Posted by DarkDeviL (Post 2814638)
There is simply no permanent fix to the problem, regardless what you do (or don't do).

That being said, I will be more than happy to admit that I also believe more things could be tried, in order to act more pro-actively to the issues.

But two questions comes up again and again, in regards to that:
  1. How many false positives do we want?
  2. What is most important?
    a) Effective spam bot defence
    b) That we are not limiting the ability for regular users to use the forums.

WATCH_D0GS UNITED 12-24-2023 06:20

Re: is this site get hacked? an invalid thread and user appears in Sourcemod - Genera
 
Very simple solution:

In order to sign-up at AlliedModders.net, please send $3 to the following address..."

Mordekay 12-24-2023 06:53

Re: is this site get hacked? an invalid thread and user appears in Sourcemod - Genera
 
Quote:

Originally Posted by WATCH_D0GS UNITED (Post 2814858)
Very simple solution:

In order to sign-up at AlliedModders.net, please send $3 to the following address..."

:mrgreen:

That would stop them all at once.
But to be fair to users out of not so rich countries, it should be any currency and a low number.


All times are GMT -4. The time now is 01:42.

Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.