Hacking the unRaid site?


SSD

Recommended Posts

I click on the list of users at the bottom of the screen which shows what messages different users are reading / posting.

 

I have noticed recently a number of users with 0 posts identified as crearing a new poll in the Announcements area.

 

There do not seem to be new polls created, so I can only assume that it is some sort of hacking going on.

 

There were actually 2 of these happening when I just checked.

 

See the screenshots for an example (user AAavethidevem):

 

(that hyperlink called "Michigan Moving Truck Rental" is a link to www . musicxclusive . net (spaces to preent this becoming a hyperlink))

 

baduser1wp4.jpg

 

baduser2uz1.jpg

 

 

Link to comment

I click on the list of users at the bottom of the screen which shows what messages different users are reading / posting.

 

I have noticed recently a number of users with 0 posts identified as crearing a new poll in the Announcements area.

 

There do not seem to be new polls created, so I can only assume that it is some sort of hacking going on.

 

There were actually 2 of these happening when I just checked.

 

See the screenshots for an example (user AAavethidevem):

 

(that hyperlink called "Michigan Moving Truck Rental" is a link to www . musicxclusive . net (spaces to preent this becoming a hyperlink))

 

baduser1wp4.jpg

 

baduser2uz1.jpg

 

 

 

I've actually noticed the same thing.... I just figured that it some computer somewhere was trying to spam the forum but that Tom had somehow filtered them out (or prevented them from being saved to the database in the first place).

 

Matt

Link to comment

Just a bot. I run a fairly busy forum and you see attempts 24*7 usually caught by normal user and forum security. Occasionally a bot turns up that knows about a means to cause problems before the forum code does but thats just life.

 

With Apache and some tinkering theres way to lessen the impact but its a constant battle usually not worth the effort.

 

A quick trawl in google cache shows what this particialr bot does if successful:

 

http://74.125.77.132/search?q=cache:xrMyoDZBWLgJ:forum.projects-abroad.net/showthread.php%3Fp%3D26671+www+.+musicxclusive+.+net&hl=en&ct=clnk&cd=1

Link to comment
  • 2 weeks later...

One of them finally succeeded in creating a poll in the Announcements forum.  And another created a post in the Forum Feedback forum.  With over 3000 'users' currently listed, I estimate that legitimate users are now outnumbered by spammers by over a 2 to 1 margin.  Since some time in December, there has been a huge influx of spammers, with the user count rising from the 900's to over 3000.  I have to give a lot of credit to Tom and the board software, that we haven't had more problems before now.  But I do think it is time for more active moderation, additional or more active moderators.

 

I have to say I'm proud of the lack of replies to either spam message.  Let's keep ignoring them, until someone can remove them.

 

For an easy way to see the User List, sorted by most recent, go to http://lime-technology.com/forum/index.php?action=mlist;sort=registered;start=0;desc.  It is only too easy to definitively detect which ones are obvious spammers.  About (perhaps over) 99.9% of users with web sites listed are spammers.

 

NAS:  there's a little more wiki cleanup for you if you are interested.  All but one of the pages on Orphaned Pages are spam pages.  There is a new user who has used their personal page for a few links at the bottom, that look like possible spam to me.  I have to say though, that I'm not in favor of doing anything about it, because I think that what one does on their personal page is probably their own right, short of outright abuse, as long as it meets the approval of the wiki 'owner'.  I think it should be monitored though.  I recognize there may be differing opinions.

Link to comment

And it would appear we have another post up now.

 

I sent a PM to tom about a week ago with an inquiry about getting some Moderators in here just in case something like this happened.  I have not received a reply as of yet.

 

thats a good idea.... more maintenance staff though than moderators. I help maintain the wiki but I would never moderate it with my option. Subtle but distinct difference IMO.

 

Great idea though count me in.

Link to comment

thats a good idea.... more maintenance staff though than moderators. I help maintain the wiki but I would never moderate it with my option. Subtle but distinct difference IMO.

 

Great idea though count me in.

 

I agree, this board does not need Moderators per-say.  I was thinking of moderators in the sense that these people would eb able to move threads around (to the appropriate forum), make some stickies for appropriate threads, and perhaps put up some "Read Me" type stuff.

Link to comment

An update. you cant delete users from mediawiki using the GUI and doing it via SQL(which i dont have access to it is not recommended). I can block users but it takes (and i kid you not) about 6 clicks per user and there no direct link from any user list.

 

This means to block all the obvious spam accounts i need to open 2 or 3 web pages and click like absolute mad. Will take forver.

 

If anyone sees any spam I am about to create a post for reporting it.

Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.