Jump to content

Spam attack


JohnD

Recommended Posts

Anyone who has visited the TRR message board will find it has been and still is under what could be said to be a 'denial of service attack', the number of spam messages drowning out all other posts.   The titles all start with the word "CONTACT".

  I expect and hope that Craig is, rightly, fast asleep right now, but I'll use this post to notify the Mod system.

John

Link to comment
Share on other sites

As a residue of this attack, TRR members have been asked NOT to use the usual Report button for spam, as this " results in a report for every item the spammer has posted, so the same miscreant can result in 20/30 - 40 posts" .  When many board members report, that would flood the inbox for the Mods!  Instead they are asked to PM a Mod, with the forum where the spam has appeared.

  I think that TRR and Sideways use the same board software, so if this happens here, would that be the best way forward?

John

Link to comment
Share on other sites

49 minutes ago, JohnD said:

As a residue of this attack, TRR members have been asked NOT to use the usual Report button for spam, as this " results in a report for every item the spammer has posted, so the same miscreant can result in 20/30 - 40 posts" .  When many board members report, that would flood the inbox for the Mods!  Instead they are asked to PM a Mod, with the forum where the spam has appeared.

  I think that TRR and Sideways use the same board software, so if this happens here, would that be the best way forward?

John

John, the CT board had a series of spammers a while ago, I had the joy of sorting them, but at one point it was a full time job. Then we altered a setting temporarily so just 1 report of spam would freeze the miscreants account. 

For the moment I am manually approving new members to the website, although CT members get pre-approved. Still have teh odd russian trying it on, the asian suncontinent has gone quiet. And the odd one from Florida. Generally if the username smells bad, they don't get approved. 

The clever scam was one that appeared early this year. People (probably just one) sign up, never post on the forum, but were contacting members by personal messages in response to wanted ads. We got reports, sorted that and now impliment a system where noobies cannot initiate private messaging (but can respond). This disappears after a certain post count.

It is all fun and games.

Link to comment
Share on other sites

We have a couple of relatively simple custom settings that let me see most spammers before they get to post.  I won’t reveal them here but they’ve worked well so far.

Our software is pretty good in hunting them down, and if they get banned from another forum, their email address gets flagged here for us.

Its all thanks to the members who put their hands into their pockets and contribute their hard earned in the form of subs, so thanks again to those that do!

  • Like 2
Link to comment
Share on other sites

  • 1 month later...

I received this email last night:

image.png.42dd9a07f2272624dd843dba118d93db.png

Clicking on "Read Voice" takes me to a page that shows  a BTinternet logo, and then a page asking me to log in with my password.    No intervention form my usually vigilant firewall, but I then  chickened out - or else sense prevailed, and I deleted these pages.   As the  email sender was not on BT, I think I should have deleted the message in the first place

Anyone met a "Voicenote" before?   Are they pukka, or bad news?

John

Link to comment
Share on other sites

Thank you DTR.   Not exactly, but very nearly the same, and as they say, it "requests the user to sign in using their email account (i.e., email address and corresponding password)."    Which is exactly what happened when I followed the link.  Then, as they go onto say, "It is a phishing attachment that records entered information and sends it to the scammers."

My scamdar is working!

John

Link to comment
Share on other sites

If I may impart a wee "rule" that I use: Never follow a link from an email, with the sole exception of a password reset that YOU have triggered.

Doesn't matter how safe I consider it, I always go to the relevant page in a browser, and login that way. Then I don't have to worried about small spelling errors etc, that spammers may use for spoofing.

Phil

  • Like 1
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...