Author Topic: Bugs and things to fix  (Read 149808 times)

wavewright62

  • Valkyrie
  • Admiral of a Sunken Ship
  • *
    • Tumblr
  • Preferred pronouns: she/her
  • Posts: 4989
Re: Bugs and things to fix
« Reply #585 on: December 21, 2018, 08:01:55 PM »
Dilandu reports that he's suddenly banned from the forum, I'm guessing it's the antispam things that are a bit too effective again. Can anyone help him?
Poor Dilandu, I can see him attempting to log in from all sorts of devices.  This is among the hundreds of continuing attempts by the Russian spambots to enter. (This is not hyperbole.  There were well over 800 hits since the evening of 10 Dec, at which point I stopped scrolling back.)  I identified several basic IP addresses, but they must switch them around, because a different crop have started attempts this week.
Always a newbie at something
Native speaker: :us:
Acquired: :nz:
Grew up speaking but now very rusty: :ee:


Ruler of Queenstown Airport (Thanks Purple Wyrm, I will wear my wings with pride)
Admiral of the Sunken Rainbow Warrior

JoB

  • Mage of the Great Restructuring
  • Admiral of a Sunken Ship
  • ******
  • Posts: 4100
Re: Bugs and things to fix
« Reply #586 on: January 21, 2019, 02:15:04 AM »
[Oh, look. It's the guy who keeps parading bad news around again. :P ]

Over in the comments (on page 42), Kis asked whether someone could unban him (again).
native: :de: secondary: :us: :fr:
:artd: :book1+: :book2: :book3: :book4: etc.
PGP Key 0xBEF02A15, Fingerprint C12C 53DC BB92 2FE5 9725  C1AE 5E0F F1AF BEF0 2A15

wavewright62

  • Valkyrie
  • Admiral of a Sunken Ship
  • *
    • Tumblr
  • Preferred pronouns: she/her
  • Posts: 4989
Re: Bugs and things to fix
« Reply #587 on: January 21, 2019, 02:53:33 AM »
I'm seeing what I can do for him.
Always a newbie at something
Native speaker: :us:
Acquired: :nz:
Grew up speaking but now very rusty: :ee:


Ruler of Queenstown Airport (Thanks Purple Wyrm, I will wear my wings with pride)
Admiral of the Sunken Rainbow Warrior

viola

  • Hel
  • Conqueror of an Abandoned City
  • *
  • I AM VENOM GROOT
  • Preferred pronouns: no preference
  • Posts: 5131
Re: Bugs and things to fix
« Reply #588 on: January 21, 2019, 10:26:30 AM »
I removed one of the IP addresses that is similar to Kis's. Their email, hostname, and user names are not listed on the ban list, so I'm pretty certain it's not one of those.
everyday: :gb: :fr: (:ca:) | can do: :is: | somewhat: :dk: :se: :no: :de: | lil bit: :lb: :np: | currently learning: :sgn:

Surviving since: :chap7:

Forum Rules | Important Information | Help

hushpiper

  • Slayer of Silence
  • Scout
  • *
    • Tumblr
  • steam engenius, you see
  • Posts: 327
Re: Bugs and things to fix
« Reply #589 on: October 12, 2019, 12:05:54 AM »
Quick heads-up: I've removed the BotScout mod from our forum, as it was doing its job of keeping spam registrations away too well--by shutting down registrations entirely. I'm looking at options to potentially keep it around, but for the moment, just keep a close eye out for spammers.  ;)

Ragnarok

  • Admiral of a Sunken Ship
  • ******
    • Tumblr
    • DeviantArt
  • I write things, and I'm okay at that.
  • Preferred pronouns: he/him
  • Posts: 3410
Re: Bugs and things to fix
« Reply #590 on: October 12, 2019, 09:59:53 AM »
Quick heads-up: I've removed the BotScout mod from our forum, as it was doing its job of keeping spam registrations away too well--by shutting down registrations entirely. I'm looking at options to potentially keep it around, but for the moment, just keep a close eye out for spammers.  ;)

Found one!

Seriously though, good luck.
Survived: Chapters: :chap8::chap9::chap10::chap11::chap12::chap13::chap14::chap15::chap16::chap17::chap18::chap19::chap20::chap21: :A2chap01: :A2chap02::A2chap03::A2chap04::A2chap05:
Books: :book3: :book4:

I wrote a thing. It has consumed my life.

Reigning champion of time spent on this forum.

wavewright62

  • Valkyrie
  • Admiral of a Sunken Ship
  • *
    • Tumblr
  • Preferred pronouns: she/her
  • Posts: 4989
Re: Bugs and things to fix
« Reply #591 on: October 12, 2019, 08:19:25 PM »
I've put in bans on entire swathes of Ukrainian IP addresses, which has been working to repel dozens of hits daily, 10K+ over the past year.  This newest spammer had at least one of their IP addresses in the Ukraine (the other was for an individual from Vietnam), and an email address from Palau.
I try to scope new registrations for dodgy entities, ones where the IP addresses and hosts don't match each other, as well as email addresses from known spam sites.  I especially look for the new class where they put up a website that mashes together completely random phrases from medical journal websites, as a vehicle for generating spam email entities.  The Palau address was one of those.
I don't get to check every day, so I'm sorry I missed that one.
Thanks hushpiper for your help!
Always a newbie at something
Native speaker: :us:
Acquired: :nz:
Grew up speaking but now very rusty: :ee:


Ruler of Queenstown Airport (Thanks Purple Wyrm, I will wear my wings with pride)
Admiral of the Sunken Rainbow Warrior

hushpiper

  • Slayer of Silence
  • Scout
  • *
    • Tumblr
  • steam engenius, you see
  • Posts: 327
Re: Bugs and things to fix
« Reply #592 on: October 12, 2019, 10:03:40 PM »
Well you know, there's more than one way to skin the spam cat--how about we try introducing some more friction into the signup process? I've turned on the option to require email verification for new signups. That should stop a huge portion of them, especially the ones whose email addresses don't exist in the first place.

It also probably wouldn't be hard to just block Ukraine's IP space wholesale, but that would cause issues for any Ukrainian members or prospective members, so I don't know how good an idea it is.

ETA: Email verification has downsides as well--like the possibility that the verification message might go to spam, although that doesn't seem to be an issue in gmail so far--but it's a common mitigation. Having people contact us by other means if they run into issues seems to be a decent workaround so far?
« Last Edit: October 12, 2019, 10:07:58 PM by hushpiper »

wavewright62

  • Valkyrie
  • Admiral of a Sunken Ship
  • *
    • Tumblr
  • Preferred pronouns: she/her
  • Posts: 4989
Re: Bugs and things to fix
« Reply #593 on: October 13, 2019, 08:01:33 PM »
The gobbledy-gook websites do exist, I suspect mostly as a domain for hosting bot email addresses.  The addresses would be legitimate, since they belong to a registered domain. Setting up a website often allows X number of free email addresses as part of the deal. 
I see one user awaiting email verification now, and I am curious to see the outcome.
The ban on Ukrainian IP is not universal - it is total for one particular mobile bandwidth provider, true, and partial for another provider.  So far, I have not heard of any bounced users being from the Ukraine, though, even from among our Russian Forumites.
The newest ban on a gobbledy-gook website has possibly yielded three thwarts within 24 hours, from what I can tell.  All of those were trying, as their first touch on the website, to access a thread left by the bot that got through, that has since been banned.  Apparently the bot registered another user *while I was instituting the ban* and it never got to post, poor baby.
Always a newbie at something
Native speaker: :us:
Acquired: :nz:
Grew up speaking but now very rusty: :ee:


Ruler of Queenstown Airport (Thanks Purple Wyrm, I will wear my wings with pride)
Admiral of the Sunken Rainbow Warrior

Unlos

  • Ruler of a Derelict Airport
  • *****
    • Tumblr
  • Posts: 1490
Re: Bugs and things to fix
« Reply #594 on: November 17, 2019, 03:32:03 PM »
Do we have a possibility to set up control questions in the signup process? Super easy ones, but where you need to click the correct answer?

viola

  • Hel
  • Conqueror of an Abandoned City
  • *
  • I AM VENOM GROOT
  • Preferred pronouns: no preference
  • Posts: 5131
Re: Bugs and things to fix
« Reply #595 on: November 18, 2019, 11:10:38 AM »
The lovely Wyrd (Hush's other half) has joined the admin team and is working behind the scenes to outfit the forum with protection from spam bots. It will take a bit of time but we should have better security without making things difficult for users.
everyday: :gb: :fr: (:ca:) | can do: :is: | somewhat: :dk: :se: :no: :de: | lil bit: :lb: :np: | currently learning: :sgn:

Surviving since: :chap7:

Forum Rules | Important Information | Help

WyrdGrin

  • Æsir/Jumala
  • Newbie
  • *
  • Background tinkerer.
  • Posts: 14
Re: Bugs and things to fix
« Reply #596 on: November 27, 2019, 02:56:43 AM »
Do we have a possibility to set up control questions in the signup process? Super easy ones, but where you need to click the correct answer?
The lovely Wyrd (Hush's other half) has joined the admin team and is working behind the scenes to outfit the forum with protection from spam bots. It will take a bit of time but we should have better security without making things difficult for users.

Right now it's gathering site statistics and reviewing what the forum software is capable of and to make sure it can keep doing what it's doing.

For logging in for the future the initial goal that would affect users would be:

Email only login: using just your private email that you signed up with instead of your public facing user. Less softhacking attempts or spoofiing.

Captcha validation: There's a few heuristics with this but the idea is to use what's on the shelf for the software so it's futureproof.

Everything else should be in the background handling most of the heavy lifting.

With that being said due to holidays, time, pumpkin bread, and just life in general I'll work on this when I can. :)

Happy holidays!






wavewright62

  • Valkyrie
  • Admiral of a Sunken Ship
  • *
    • Tumblr
  • Preferred pronouns: she/her
  • Posts: 4989
Re: Bugs and things to fix
« Reply #597 on: January 21, 2020, 04:38:11 PM »
I am seeing stats for unusually high traffic:
Example:
37 Guests, 4 Users (0 Buddies)

Users active in past 15 minutes:
wavewright62, (3 others whose names are redacted)

Most Online Today: 848. Most Online Ever: 848 (Today at 15:30:09)


Now, I would love to think these new usage records that have been reset repeatedly since early December are due to resurgent interest in the Forum and SSSS in general, but the disjoint between the record online figures and the number of registrations/posts leads me to believe that there is something else going on.  I should note that I have not seen any hits from banned IPs in a time range any of the times I checked.
Can someone with more visibility into the traffic patterns please take a quick look to see what might be going on? 
Always a newbie at something
Native speaker: :us:
Acquired: :nz:
Grew up speaking but now very rusty: :ee:


Ruler of Queenstown Airport (Thanks Purple Wyrm, I will wear my wings with pride)
Admiral of the Sunken Rainbow Warrior

viola

  • Hel
  • Conqueror of an Abandoned City
  • *
  • I AM VENOM GROOT
  • Preferred pronouns: no preference
  • Posts: 5131
Re: Bugs and things to fix
« Reply #598 on: January 22, 2020, 01:56:37 PM »
I wouldn't be too worried about it. It could be spiders (search bots), which show up when there are links to or from the forum with search sites. They're pretty harmless. I'll keep an eye on it though.
everyday: :gb: :fr: (:ca:) | can do: :is: | somewhat: :dk: :se: :no: :de: | lil bit: :lb: :np: | currently learning: :sgn:

Surviving since: :chap7:

Forum Rules | Important Information | Help

wavewright62

  • Valkyrie
  • Admiral of a Sunken Ship
  • *
    • Tumblr
  • Preferred pronouns: she/her
  • Posts: 4989
Re: Bugs and things to fix
« Reply #599 on: January 22, 2020, 03:14:39 PM »
Thankeeee
Always a newbie at something
Native speaker: :us:
Acquired: :nz:
Grew up speaking but now very rusty: :ee:


Ruler of Queenstown Airport (Thanks Purple Wyrm, I will wear my wings with pride)
Admiral of the Sunken Rainbow Warrior