Dr. Umesh Jain is now exclusively responsible for TotallyADD.com and its content

Better site security?

Better site security?2011-09-03T21:21:37+00:00

The Forums Forums Ask The Community Better site security?

Viewing 0 posts
Viewing 15 posts - 1 through 15 (of 22 total)
  • Author
    Posts
  • #89990

    Anonymous
    Inactive
    Post count: 14413

    It seems to me that this site has been the target of multiple cyber attacks lately. Is there anything can be done? Can the registration process be improved to filter out more of the non-human posts? Just wondering.

    REPORT ABUSE
    #107968

    Anonymous
    Inactive
    Post count: 14413

    I used to moderate several groups on Yahoo, and I think the only way to do it is to moderate new members. They don’t get to post until a human moderator has verified them. For example, if someone said “I just had/am going to have ____ surgery and I’d like to talk to others and find out more”, then they got approved. But if they said “please let me join”, then no. And their first few posts were moderated. If they checked out ok, then they were released from moderation and allowed to post freely.

    I’m sure there would be more than a few members here who would volunteer to help moderate the forums if asked.

    REPORT ABUSE
    #107969

    Anonymous
    Inactive
    Post count: 14413

    Yeah, but there are so many days that I forget to visit this site!

    REPORT ABUSE
    #107970

    Anonymous
    Inactive
    Post count: 14413

    I thought you were just ignoring me, game guy :(

    REPORT ABUSE
    #107971

    Anonymous
    Inactive
    Post count: 14413

    It’s not you, it’s everyone! It becomes too much of a chore to sift through some of the threads. Sorry!

    REPORT ABUSE
    #107972

    Anonymous
    Inactive
    Post count: 14413

    I was only kidding, game guy! and I agree, it’s a chore to even find past threads.

    REPORT ABUSE
    #107973

    billd
    Member
    Post count: 913

    I run a forum – car related. I’m the admin and a moderator. These aren’t “cyber-attacks” they are “forum spammers”.

    They get paid for every post they put up in forums.

    some sneak in – come in trying to look like regular members, posting things ALMOST related tot he forum topics and try to look half-way legit, then suddenly start posting spam. Or, where allowed, go back and edit all their prior posts putting links in them.

    Others come in and join and start posting spam immediately.

    Forum spammers. COMMON every where – even support forums like McAfee, Symantec, etc have to deal with them. moderators or volunteers help a lot. Our forum has “report post” buttons that send email to the moderators (and me) and the person who clicks the report link can put in a comment such as “more spam” etc.

    There are a lot of articles on the topic – and the outfit we buy our forum software from has some good measures in the software, and good suggestions to help reduce this issue (can’t be fully removed, but can be reduced)

    For our forum, it’s requires a human to input characters, and to respond to an email to verify the membership. New members have limited rights. I’ve also put anti-spam measures in place like only so many private messages can be sent to members in a 5 minute period. Members can only post so many messages in a 60 second time period, etc.

    Our members are great at pulling the “report post” trigger and use it pretty much only to report spam – and it goes to 5 of us, one of which is usually around to deal with it. We can then block the person by suspending them and blocking IP addresses or ranges. IF we suspend them, they can’t sign up again with the same email address, they have to get a new one (simple today with gmail, yahoo, etc.)

    We’re at http://theamcforum.com/forum

    Try posting spam and see how long it lasts…. ;-)

    REPORT ABUSE
    #107974

    Anonymous
    Inactive
    Post count: 14413

    These sound like good measures to put in place here, billd. I didn’t know they get paid to post, that makes sense.

    REPORT ABUSE
    #107975

    Anonymous
    Inactive
    Post count: 14413

    i don’t get how they make money that way. There must be a certain percentage of people to respond per expense to post ratio??? I personally feel anger and might not buy said product in spite. I certainly do not click on suspicious links. I have reformatted this hard drive way too many times!

    REPORT ABUSE
    #107976

    billd
    Member
    Post count: 913

    You’ve probably all seen those Google ads? Sponsored results, etc.? Pay per click…..

    Those are legit versions, but work in a similar way – you pay based on how many clicks the ad gets.

    So in the not so legit world, if a spammer, scammer, phisher whatever has people sitting in dingy offices, back rooms, abandonded cars or whatever posting links on forums, sending email, it only takes a small percentage of a percent for them to profit. In the case of malware, the producers of malware now PAY people to get their malware posted or links to it.

    It’s a huge business, often handled by organized crime at the top.

    There are so many versions – some exist to gather your personal information (PII), some exist to install stuff on your computer – malware or ADware, and some exist to setup botnets that are activated later for DoS attacks, or whatever.

    ( I work network and web security………. it’s not just a job, it’s an adventure, and getting harder to keep ahead of the bad guys)

    A computer virus used to be put out in the world for fun – like kids smashing mailboxes, busting windshields, and so on. Let’s see how many we can hit, can we make the news, or how long will it take to work around the world and get back to me sort of thing.

    Now it’s business. It’s not script-kiddies trying to out-do each other, it’s for profit – it involves professionals.

    REPORT ABUSE
    #107977

    Anonymous
    Inactive
    Post count: 14413

    i don’t think i could love myself if i spent my life trying to trick and hurt others for a living!

    REPORT ABUSE
    #107978

    Patte Rosebank
    Participant
    Post count: 1517

    They might think twice about doing it if there were quick, serious, legal and physical repercussions. Like having their computer smashed in front of them, and a couple of fingers chopped off. It’s mighty hard to type when you’re missing several digits. And people who text while driving should lose their phones and their thumbs.

    Alas, we’re far too civilized for that sort of thing…

    REPORT ABUSE
    #107979

    Anonymous
    Inactive
    Post count: 14413

    I’d settle for banning the IP address and possibly getting their ISP to drop them.

    REPORT ABUSE
    #107980

    Anonymous
    Inactive
    Post count: 14413

    I tried that, notified the authorities and the individual’s ISP in the US about some jerk who was harvesting complete profile data from another website and then allowing people to “rate” you. Nothing happened.

    I think this site needs to be actively moderated.

    REPORT ABUSE
    #107981

    billd
    Member
    Post count: 913

    Alas – we in the states have legalized spam. Yes, it’s free speech. Most of the world’s spam, according to researchers in Europe, comes from the states. In fact after we passed a bill basically calling it legal, the EU, Australia and others were rather miffed – and are still today because we do not make efforts to stop or control it.

    I can legally send you spam if I furnish an opt out method in the spam. However, how many will do that? In part because it verifies to the spammer that your address is good – and verified – and they can then sell their lists as verified live lists. Plus, if you DO unsubscribe, they can change the message, change the source, and spam you again as the counter starts over.

    REPORT ABUSE
Viewing 15 posts - 1 through 15 (of 22 total)