Author Topic: Bugs and things to fix  (Read 184230 times)

noako

  • Safe-Zone Citizen
  • **
  • Posts: 187
Re: Bugs and things to fix
« Reply #30 on: September 09, 2014, 05:59:25 PM »
Something very weird is happening with these spam bots.
I looked at their IPs and hostnames, and their IPs were all the same as mine, and their hostnames were all from the forum's host.  Not only that, but when I was cross checking everyone's accounts to make sure it was okay to ban them without affecting anyone, about 95% of you all had the same thing going on...  I've just deleted the bot accounts because I don't want to banlist an IP address that might belong to a real member.

This weirdness and the bots are definitely connected.  My hunch is that it either has something to do with my backing up the site yesterday, or Minna's posting a link on her site.  Most likely the backup thing.  If anyone can help, or has any general knowledge on this kind of thing, it'd be appreciated.

I have no idea how to help you in this. Sorry. Could we have some sort of spambot-filter, like email confirmation or writing numbers/letters like in some registeration sites?

ThisCat

  • Ranger
  • ****
  • Meow. Mew-eoow meaow, miaow. Mow.
  • Posts: 913
Re: Bugs and things to fix
« Reply #31 on: September 09, 2014, 06:02:25 PM »
I have no idea how to help you in this. Sorry. Could we have some sort of spambot-filter, like email confirmation or writing numbers/letters like in some registeration sites?

This would probably be a very good idea.
:norway:
 Mostly quiet.
:uk:

Eich

  • Thor
  • Ruler of a Derelict Airport
  • *
  • Retired Forum Admin
  • Posts: 1468
Re: Bugs and things to fix
« Reply #32 on: September 09, 2014, 06:07:31 PM »
I'm pretty sure I can set up a captcha, yeah.  I know I've at least seen one hanging around the site somewhere.
I'll check that out.
Feel free to PM.

JoB

  • Mage of the Great Restructuring
  • Admiral of a Sunken Ship
  • ******
  • Posts: 4117
Re: Bugs and things to fix
« Reply #33 on: September 09, 2014, 07:21:40 PM »
Something very weird is happening with these spam bots.
I looked at their IPs and hostnames, and their IPs were all the same as mine, and their hostnames were all from the forum's host.  Not only that, but when I was cross checking everyone's accounts to make sure it was okay to ban them without affecting anyone, about 95% of you all had the same thing going on...
According to Netcraft, there's a HTTP accelerator (a.k.a. reverse proxy) sitting in front of the actual server (Apache running on a Linux host?). That'ld mean that the Apache sees the requests coming from the IP of that proxy, with the IP of the actual client stashed into an X-Forwarded-For HTTP header - which SMF likely isn't equipped out of the box to expect, if it knows to deal with that in the first place.
native: :de: secondary: :us: :fr:
:artd: :book1+: :book2: :book3: :book4: etc.
PGP Key 0xBEF02A15, Fingerprint C12C 53DC BB92 2FE5 9725  C1AE 5E0F F1AF BEF0 2A15

Eich

  • Thor
  • Ruler of a Derelict Airport
  • *
  • Retired Forum Admin
  • Posts: 1468
Re: Bugs and things to fix
« Reply #34 on: September 09, 2014, 07:28:18 PM »
Well, all of your IPs and hostnames were different, a couple days ago.  That's why I think it's connected to some kind of stuff.  (I probably should've stated that in the first place)
Anyway, I'm not really sure what most of that meant (Apache=helicopters and natives to me), but I appreciate the input, and I guess I gotta learn this stuff at some point.  I'll ask for help on the SMF support site.
Feel free to PM.

JoB

  • Mage of the Great Restructuring
  • Admiral of a Sunken Ship
  • ******
  • Posts: 4117
Re: Bugs and things to fix
« Reply #35 on: September 09, 2014, 07:53:26 PM »
http://wiki.apache.org/httpd/FAQ#Why_the_name_.22Apache.22.3F ;)

If neither you (as part of some SMF add-on you installed?) nor X10HOSTING (nor whoever acts as a go-between between the two of you) installed that reverse proxy, back when the client IPs changed from diverse to "everyone looks the same", I'ld suspect some kind of hostile intrusion ...
native: :de: secondary: :us: :fr:
:artd: :book1+: :book2: :book3: :book4: etc.
PGP Key 0xBEF02A15, Fingerprint C12C 53DC BB92 2FE5 9725  C1AE 5E0F F1AF BEF0 2A15

Eich

  • Thor
  • Ruler of a Derelict Airport
  • *
  • Retired Forum Admin
  • Posts: 1468
Re: Bugs and things to fix
« Reply #36 on: September 09, 2014, 08:20:41 PM »
http://wiki.apache.org/httpd/FAQ#Why_the_name_.22Apache.22.3F ;)

If neither you (as part of some SMF add-on you installed?) nor X10HOSTING (nor whoever acts as a go-between between the two of you) installed that reverse proxy, back when the client IPs changed from diverse to "everyone looks the same", I'ld suspect some kind of hostile intrusion ...
That's what I'm worried about.  I can't very well ban an IP or hostname used by a troll or bot when it's the same IP and hostname for everybody else.
Feel free to PM.

Nimphy

  • Ruler of a Derelict Airport
  • *****
  • The Almighty Phoenix, future Ruler of the World
  • Posts: 1792
Re: Bugs and things to fix
« Reply #37 on: September 10, 2014, 03:24:24 AM »
That's what I'm worried about.  I can't very well ban an IP or hostname used by a troll or bot when it's the same IP and hostname for everybody else.

Can you suspend it, though? You could try for a day or so of suspension, and see if it affects the rest of us. Otherwise a captcha seems a pretty logical and easy solution to me.
Fluent: :italy:, :albania:, :usa:

Okay: :spain:

Learning: :germany: :norway: :japan:

Bloody messed-up spoils of a language: :france:

Survivor: :chap0: :chap1: :chap2: :chap3: :chap4: :chap5: :chap6: :chap7: :chap8:

Eich

  • Thor
  • Ruler of a Derelict Airport
  • *
  • Retired Forum Admin
  • Posts: 1468
Re: Bugs and things to fix
« Reply #38 on: September 10, 2014, 10:02:32 PM »
Can you suspend it, though? You could try for a day or so of suspension, and see if it affects the rest of us. Otherwise a captcha seems a pretty logical and easy solution to me.
It's my IP now, too.  That's the big problem.  I don't want to risk nullifying the site entirely by locking myself out.
I'll ask SMF about setting up a capcha to register.  I'm also getting responses to my question about our email problem and the IP problem, so I'm looking into those.
Feel free to PM.

Eich

  • Thor
  • Ruler of a Derelict Airport
  • *
  • Retired Forum Admin
  • Posts: 1468
Re: Bugs and things to fix
« Reply #39 on: September 10, 2014, 10:43:44 PM »
Okay... I've set up some simple verification questions.  They're not hard and, according to the folks over at SMF, they're practically fool proof (I would've set up a capthca but, apparently, people have made bots that decipher those more successfully than people).  People have said their forums have been spambot free for several years.  Only actual people can get past these, supposedly, so we'll see how these fare in the next few days.  Hopefully this'll be good enough to filter out the bots and stop this crap.
Feel free to PM.

JoB

  • Mage of the Great Restructuring
  • Admiral of a Sunken Ship
  • ******
  • Posts: 4117
Re: Bugs and things to fix
« Reply #40 on: September 11, 2014, 05:31:15 AM »
I just posted, and the forum reports "my" IP as being 198.91.81.5, which is the server's IP and definitely not the one my connections go out onto the Internet with (says the local net admin). There must be something like the mentioned reverse proxy shielding the SMF software from the incoming requests.
native: :de: secondary: :us: :fr:
:artd: :book1+: :book2: :book3: :book4: etc.
PGP Key 0xBEF02A15, Fingerprint C12C 53DC BB92 2FE5 9725  C1AE 5E0F F1AF BEF0 2A15

Sunflower

  • Saraswati
  • Admiral of a Sunken Ship
  • *
  • Preferred pronouns: She/her
  • Posts: 4158
Re: Bugs and things to fix
« Reply #41 on: September 11, 2014, 12:12:14 PM »
I just posted, and the forum reports "my" IP as being 198.91.81.5, which is the server's IP and definitely not the one my connections go out onto the Internet with (says the local net admin). There must be something like the mentioned reverse proxy shielding the SMF software from the incoming requests.

I checked out all my posts.  About half of them give the same IP as you:  198.91.81.5.  The rest state my home IP, starting 76.14. 
Hoping this data point helps...
« Last Edit: September 11, 2014, 05:02:16 PM by Sunflower »
"The music of what happens," said great Fionn, "that is the finest music in the world."
:chap3:  :chap4:  :chap5:  :book2:  :chap12:  :chap13:  :chap14:   :chap15:  :chap16:

Speak some:  :france:  :mexico:  :vaticancity:  Ein bisschen: :germany:

Richard Weir

  • Scout
  • ***
  • Posts: 336
Re: Bugs and things to fix
« Reply #42 on: September 11, 2014, 03:05:55 PM »
Another datapoint for you: Between September 8th and September 9th my posts change from showing my proper IPA to showing the erroneous IPA.
My one-and-only: :uk:

JoB

  • Mage of the Great Restructuring
  • Admiral of a Sunken Ship
  • ******
  • Posts: 4117
Re: Bugs and things to fix
« Reply #43 on: September 11, 2014, 03:59:28 PM »
Good idea to check the actual time of the change ... I have the proper IP with topic=31.msg1179 (08-09-2014, 16:37:32) and the wrong one on topic=31.msg1234 (09-09-2014, 05:03:10).
native: :de: secondary: :us: :fr:
:artd: :book1+: :book2: :book3: :book4: etc.
PGP Key 0xBEF02A15, Fingerprint C12C 53DC BB92 2FE5 9725  C1AE 5E0F F1AF BEF0 2A15

Eich

  • Thor
  • Ruler of a Derelict Airport
  • *
  • Retired Forum Admin
  • Posts: 1468
Re: Bugs and things to fix
« Reply #44 on: September 14, 2014, 12:15:23 AM »
Sooo... Uhh-  The IP thing cleared up while I was asleep last night, apparently...
I'm not going to risk banning anyone by IP or hostname, just in case it was something more malicious than a glitch, so I'll be restricting myself to banning by email and usernames for a while, until I know for sure what was going on.
Feel free to PM.