Author Topic: How does spambot posting on GH?  (Read 2263 times)

0 Members and 1 Guest are viewing this topic.

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
How does spambot posting on GH?
« on: Sun, 03 April 2011, 10:59:43 »
Two bots posted on GH in the past couple weeks.

http://geekhack.org/showthread.php?t=16842

And can't find the other... Probably nuked by the admin.

Are they getting "smarter"?

Is it time to upgrade our boarding engine?
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
How does spambot posting on GH?
« Reply #1 on: Sun, 03 April 2011, 11:05:49 »
Quote from: ripster;323766
You push the little red triangle on the left.  Type "Spam".  Send.


Ok bot how do they get there in the first place?
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline Lpb45

  • Posts: 481
How does spambot posting on GH?
« Reply #2 on: Sun, 03 April 2011, 11:10:08 »
they even make profiles and upload pics.
Topre - 86U   |   Filco - Tenkeyless Linear Red
Filco - Tenkeyless Blue       |   Filco - Fullsize Non NKRO Blue (Work)

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
How does spambot posting on GH?
« Reply #3 on: Sun, 03 April 2011, 11:14:37 »
I just logged Out and went to the registering process. We don't use any "protection" like reCAPTCHA or alike. At least not as as far as I went in the registering process. I didn't make a complete submission.
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline panda-R

  • Posts: 721
How does spambot posting on GH?
« Reply #4 on: Sun, 03 April 2011, 12:05:46 »
Quote from: ripster;323779
You should start your own keyboard forum.

Like Runeazn's.    The Russian Porn there is pretty impressive.

PandaR didn't call him "Princess" for nothing!


lulz poor runeazn, i miss that little princess guy thing. Whatever happened to her?
DO YOU FEEL THE BEAT? I DO.
One Keyboard to DOOM them all, REALFORCE.

Offline panda-R

  • Posts: 721
How does spambot posting on GH?
« Reply #5 on: Sun, 03 April 2011, 12:34:36 »
PETER CHAO my hero!
DO YOU FEEL THE BEAT? I DO.
One Keyboard to DOOM them all, REALFORCE.

Offline iMav

  • geekhack creator/founder
  • Location: Valley City, ND
  • "Τα εργαλεία σας είναι σημαντικά."
How does spambot posting on GH?
« Reply #6 on: Sun, 03 April 2011, 13:01:09 »
Quote from: BucklingSpring;323759
Two bots posted on GH in the past couple weeks.

http://geekhack.org/showthread.php?t=16842

And can't find the other... Probably nuked by the admin.

Are they getting "smarter"?

Is it time to upgrade our boarding engine?


We have a, fairly simple, question.  I am looking to implement something else (more sophisticated then captcha), but have yet to do so....spambot annoyance here at GH is pretty light.

Offline iMav

  • geekhack creator/founder
  • Location: Valley City, ND
  • "Τα εργαλεία σας είναι σημαντικά."
How does spambot posting on GH?
« Reply #7 on: Sun, 03 April 2011, 14:57:17 »
Ok.  New Human Verification System is in place.  ;)

Offline Hak Foo

  • Posts: 1272
  • Make America Clicky Again!
How does spambot posting on GH?
« Reply #8 on: Sun, 03 April 2011, 16:59:45 »
IME, a simple random-math thing like this is a surprisingly effective deterrent:

$a = rand(1,10);
$b = rand(1,10);
?>
< input type="hidden" name="a" value="< ?php echo $a;?>">
< input type="hidden" name="b" value="< ?php echo $b;?>">
Please add < ?php echo $a;?> + < ?php echo $b;?>

then in the processing code

if(!$_POST["a"] || !$_POST["b"] || $_POST["c"]!=$_POST["a"]+$_POST["b"]) die("please fill out the damned captcha so we don't have to do the scrambled letter ones!");


Yeah, if it was WORTH the effort to target the site and realize "fields A, B, and C must be set together in specific ways", you could defeat it, but I doubt there's enough value in doing so.  And you could just replace the + with a - and/or rename fields and stymie them again.
Overton130, Box Pale Blues.

Offline iMav

  • geekhack creator/founder
  • Location: Valley City, ND
  • "Τα εργαλεία σας είναι σημαντικά."
How does spambot posting on GH?
« Reply #9 on: Sun, 03 April 2011, 17:08:55 »
For the most part, I believe the "spambots" are actually registering manually (real person).  We'll see what rate we get them now with the new verification in place.

Offline kill will

  • Posts: 231
    • http://www.jerseyshoredailies.com
How does spambot posting on GH?
« Reply #10 on: Sun, 03 April 2011, 17:16:56 »
i liked the one bot that posted about air jordans in nonsensical engrish.  he seemed like a cool robot.
I <3 BS

Offline Ekaros

  • Posts: 942
How does spambot posting on GH?
« Reply #11 on: Sun, 03 April 2011, 17:21:48 »
Ok, that's one cool captcha ;D
So I should add something useless here yes? Ok, ok...
Filco 105-key NKRO MX Browns Sw/Fi-layout|IBM Model M 1394545 Lexmark 102-key Finnish-layout 1994-03-22|Cherry G80-3000LQCDE-2 with MX CLEAR
[SIGPIC][/SIGPIC]
Dell AT102W(105-key SF) (Black ALPS)|Steelseries Steelkeys 6G(MX Black) ISO-FI-layout|Cherry G84-4400 G84-4700 Cherry MLs

Offline mr_a500

  • Posts: 401
How does spambot posting on GH?
« Reply #12 on: Sun, 03 April 2011, 17:34:50 »
Gah! Flash based "captcha"! If geekhack had that crap back when I first came here, I never would have been able to become a member. I use alternative operating systems (Amiga, BeOS, Haiku, soon MorprhOS).

Flash is evil - a CPU sucking evil proprietary curse that's ruining the internet experience for anybody not using Windows, MacOS or Linux.

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
How does spambot posting on GH?
« Reply #13 on: Mon, 04 April 2011, 11:24:24 »
Quote from: iMav;323854
Ok.  New Human Verification System is in place.  ;)


Cool... Let see if the bad ass smart Russians will crack the code.

:-)
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
How does spambot posting on GH?
« Reply #14 on: Mon, 04 April 2011, 11:29:03 »
Quote from: mr_a500;323949
Gah! Flash based "captcha"! If geekhack had that crap back when I first came here, I never would have been able to become a member. I use alternative operating systems (Amiga, BeOS, Haiku, soon MorprhOS).


Some others can't be resolved by color blind people. It's always a matter of weighting the annoyance of the spam problem vs the annoyance you impose on your users to prevent it.

As iMav is pointing it out, this is not a big problem here.
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline digitalleftovers

  • Posts: 645
How does spambot posting on GH?
« Reply #15 on: Mon, 04 April 2011, 11:36:56 »


I think this was an excellent choice.  It doesn't alienate colorblind people, and it  seems to not only be difficult to crack, but I have never seen it before (rare is better than common).

If you had not posted this, I was going to suggest the cat/dog identification captcha.
Keyboards:
Filco 104 MX Brown (Otaku) - FKBN104M/NPEK 黒い空
Ducky TKL MX Brown/Blue 80% (White) - 1087-F 白の空
KBC Poker MX Red with PBT Key Caps - PFCN6000


"Consumers use touch screens.  Producers use keyboards."

Offline BucklingSpring

  • Thread Starter
  • Posts: 1613
How does spambot posting on GH?
« Reply #16 on: Mon, 04 April 2011, 16:54:28 »
I like the puzzle thing.

I think I will register over and over just to solve it once more. :baby:
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)