Forum spam attack

Choidebu

"Banned"
Original poster
Aug 16, 2017
1,198
1,205
What was that?
I'm really interested in these sort of cyber forensic stuff... anything on the log? Reckon we need captcha before posting a new thread?
 

PlayfulPhoenix

Founder of SFF.N
SFFLAB
Chimera Industries
Gold Supporter
Feb 22, 2015
1,052
1,990
Yes.. perhaps a captcha at user registration step?

We've actually already implemented this. So this may be an instance in which a person is manually making the accounts, but then uses automation to post spam. (Or perhaps does this manually as well, to an extent).

We can only do so much to block spammers from creating accounts - this part is really hard to distinguish - so most of the preventative work we do is in catching and preventing spammy posts as they are submitted. Without going into too much detail, our solution for this is a rules set that analyzes the content of the posts to see if it matches certain criteria. This set is regressive, so we can enhance it each time spam is posted with data seeded from what came through, in order to ensure that the same (and broadly similar) spam can't be re-posted. It actually works pretty well - we are positively hammered with spam attempts, and the great majority of them are blocked - but it's not perfect.

The most recent examples users have seen all made it through primarily because they were in Korean, which is not a language that our anti-spam measures have been tuned for (given that it's not what we've encountered in the past). I've just made some changes that I think will help us do a much better job of automatically preventing these Korean posts from appearing, though. We shall see.

My apologies for these posts cluttering up the forum, though. No amount of spam is acceptable to us.
 

VegetableStu

Shrink Ray Wielder
Aug 18, 2016
1,949
2,619
We've actually already implemented this. So this may be an instance in which a person is manually making the accounts, but then uses automation to post spam. (Or perhaps does this manually as well, to an extent).

I know there are lurkers, but is it possible to delete all users with 0 posts for now (while releasing the names to re-apply)? I mean if they're legitimate we could tell them to re-register again

EDIT: scratch that. didn't read the part about manual account creation ._.
 
  • Like
Reactions: Biowarejak

ignsvn

By Toutatis!
SFFn Staff
Apr 4, 2016
1,711
1,650
Manual account creation + automatic spam posts = sucks.

Does this forum has option to ban post / users based on certain keywords (just copy paste from the Korean spams)?
 

jØrd

S̳C̳S̳I̳ ̳f̳o̳r̳ ̳l̳i̳f̳e̳
sudocide.dev
SFFn Staff
Gold Supporter
LOSIAS
Jul 19, 2015
818
1,359
There problem is that the second you start talking in anything that even resembles specificity about your anti-spam measures your as-good-as nullifying them. You kind of have to just take it on good faith that its essentially an arms race w/ both sides constantly evolving their tool set.
 

robbee

King of Cable Management
n3rdware
Bronze Supporter
Sep 24, 2016
861
1,349
How about only allowing X posts per minute/hour/day (or a combination)? The previous attacks were so big that the forum was hardly usable, at least that could be improved a little bit by limiting the allowed posts/topics. Even a high number that no user would ever reach might help things a bit :)
 
  • Like
Reactions: Biowarejak

jØrd

S̳C̳S̳I̳ ̳f̳o̳r̳ ̳l̳i̳f̳e̳
sudocide.dev
SFFn Staff
Gold Supporter
LOSIAS
Jul 19, 2015
818
1,359
The ideal solution is to improve the rulesets & tools that detect spam and stops you guys from seeing it. Solutions that degrade the experience for everyone raise the barrier for entry to legitimate new users. Converting passers by to active accounted users is the holy grail for basically any forum and small barriers to entry here can have quite large long term impacts on new user signup / new user activity.

EDIT: to be clear i speak from past experience dealing w/ this shit. I have no insight, impact or say in how its done at SFFn. Im not site staff.
 

jØrd

S̳C̳S̳I̳ ̳f̳o̳r̳ ̳l̳i̳f̳e̳
sudocide.dev
SFFn Staff
Gold Supporter
LOSIAS
Jul 19, 2015
818
1,359
Using the report function really does make a big difference. It surfaces things in a way that means moderators / staff dont need to go hunting for problem content or find it in the normal course of reading the forums, enables a range of effective intervention to be taken much more quickly than they otherwise would, makes it much easier to spot patterns in the types of spam & their contents and see any weaknesses in the automated systems that are in place.
 

ignsvn

By Toutatis!
SFFn Staff
Apr 4, 2016
1,711
1,650
Find a Korean user & make him/her admin/moderator. He/she understands Korean, and active on Asian timezones LOL.

Anyway.. there should be some spam blockers for forums, right? Like what @jØrd said before:

The ideal solution is to improve the rulesets & tools that detect spam...
 
  • Like
Reactions: Biowarejak

jØrd

S̳C̳S̳I̳ ̳f̳o̳r̳ ̳l̳i̳f̳e̳
sudocide.dev
SFFn Staff
Gold Supporter
LOSIAS
Jul 19, 2015
818
1,359
Find a Korean user & make him/her admin/moderator. He/she understands Korean, and active on Asian timezones LOL.

Anyway.. there should be some spam blockers for forums, right? Like what @jØrd said before:

there are tools and rulsets in place that are constantly being evolved. The thing is no one can talk about them publicly w/out essentially nullifying them in the process. All I can really say here is that you have to take it on faith that as new spam attacks emerge and make it through to the forums where you guys can see them that there is work happening behind the scenes to make sure that that approach wont be successful in the future. Dealing w/ spam is an arms race at the end of the day.