• Please use real names.

    Greetings to all who have registered to OPF and those guests taking a look around. Please use real names. Registrations with fictitious names will not be processed. REAL NAMES ONLY will be processed

    Firstname Lastname

    Register

    We are a courteous and supportive community. No need to hide behind an alia. If you have a genuine need for privacy/secrecy then let me know!
  • Welcome to the new site. Here's a thread about the update where you can post your feedback, ask questions or spot those nasty bugs!

Spammers! @#@!!!?

fahim mohammed

Well-known member
I like Russia.

Besides, The most beautiful women are from Russia.

And the Tennis Players! Mano o mano!
Enough to make one take up excercising.

That's why men fall for them.

It was in the news..Seriously.

Let's not demonise any people or country. Just because they eat garlic and onions! or drink vodka. or wear a turban.

Yes we don't know who the ' angels ' are. But let's stop
thinking we know the ' demons '.

Stop reading Dan Brown..to start with. Might help.
 
Fahim, no racism intended, it's a fact. The most beautiful woman are from Russia, we all know that, the husband knows it too much for my taste... :)

It's not the people there that are more evil, there is a background of laxity with laws and a mere corrupted state. It could happen with China for example (well, it happens a lot with china as well) There is something connected with history of communism, I don't know.

All the people I know that have been contacted were by Russians, FACT. In those cases it's no question to be naive. It's an important, sensitive matter.

I know some Russians, and they are delightful people. It's a fact as well. :)
 

fahim mohammed

Well-known member
Here is my suggestion to keep out spanners.

Those who have posted the least photos. They are the spanners in the works.

Cull them.

What's left shall be the spammers.

Throw them out.

Good, clean, spam-free, opf-land secure site.
 

James Cook

New member
Spammers don't provide valid email addresses to reply to.

Can you set up an auto responder for the registration email? If so, make all registrations trigger a response, repeating the registration info and asking the applicant to reply for verification of their email address.

You'd then ignore all but those emails that are "Re:" or with a more elaborate configuration, the responder could change the subject and even the reply to address so that the valid registrations would be all you'd deal with.
 

Cem_Usakligil

Well-known member
Hi James,

Spammers don't provide valid email addresses to reply to.

Can you set up an auto responder for the registration email? If so, make all registrations trigger a response, repeating the registration info and asking the applicant to reply for verification of their email address.

You'd then ignore all but those emails that are "Re:" or with a more elaborate configuration, the responder could change the subject and even the reply to address so that the valid registrations would be all you'd deal with.
Thanks for the ideas. Unfortunately, this procedure is already in place. They have to react to the email that is sent to them in order to complete registering. After that, Asher or Nicolas has to approve the registration as the final step. Checking these for validity and subsequently banning is the majority of the effort.
 

fahim mohammed

Well-known member
Reluctantly Doug. Very reluctantly.

But the others..' off with their heads ' I say.

Preserve the sanctity of OPF!!. A better goal man hath not thought of.
Throw the Artsy thinkers along with them, methinks.

For Asher, Asher and Asher INC.

Regards sir.
 

Asher Kelman

OPF Owner/Editor-in-Chief
Fahim,

I used to think that most big problems need simply an axe, a spare part, a vice or a key. Now I favor balancing out issues. Saves a lot of resources. (Spam, neither the "pork-entrails-in-a can" emergency rations, nor the unwanted mail are O.K. for me).

What counts for us are not merely echoing popular values of consideration, but acts. In the latter category, you measure up!

Asher
 

fahim mohammed

Well-known member
Spam. Non-Kosher.

Spammers- Worse

Can the can makers too Asher. So long as you are doing it with the Spam- mers.

I just came back after watching the Fockers! The movie. Not the spammers.

What you been up to ?

Regards.
 

Asher Kelman

OPF Owner/Editor-in-Chief
But the others..' off with their heads ' I say.

Preserve the sanctity of OPF!!. A better goal man hath not thought of.
Throw the Artsy thinkers along with them, methinks.

For Asher, Asher and Asher INC.

Regards sir.

Fahim,

Great humor! You and I and could be generals surveying a vanquished but burned out, silent battlefield!

The spammers do not merely advertise their Viagra™ knockoffs, (and other drugs made who knows where), but also vacuum up email addresses. But it's worse than that. They reply to threads appearing to be genuine but actually are promoting their own travel firms, life rejuvenation or religious salvation opportunities. We've had multiple attempts to login to the administration section of OPF.

More unsettling, since we have a wide audience is simple gross vulgarity. One morning a tall organ structure 1400 pixels high, 200 pixels wide, appeared in the top thread of the day. We do actually like skyscrapers, but this was not one of those.

I don't believe we prevent access to OPF by any person intent on participating. We do not censor, but we don't allow humiliation of people or child porn. The latter we'd report.

It may seem to someone not dealing with floods of BOT registrations, that OPF is somehow elitist. Not so! Rather we'd like to refine the ways we make it easy for photographers to join and still keep the BOTS out.

I think we do a good job!

Asher
 
Thanks Fahim, we try. Only today, I have already banned 16 spammers. And there must be much more which has escaped my attention for Asher to eventually take care of. It is as if the floodgates are fullly open. :-(

Indeed. Before I left my home this morning I quickly looked and "killed" and immediately deleted a spammer, and I just logged on and deleted 2 more that were in the process of registering. As I'm writing this there are 4 more Guests trying to login, who knows when they will try it with some registration data and see if they can get in. But we stay vigilant!

Bots against Mods ..., I eat spammers for breakfast, lunch and dinner, Raw.

Cheers,
Bart
 

fahim mohammed

Well-known member
Russia got the gold medal in the world youth hockey championship. But got pulled off the plane for ' unruly ' behaviour. Maybe Delta doesn't like vodka drinkers either.

I like to see a team that played well win. I loved their cheer leaders. Yea!

should I say proust. or is that some foreign language.
 
I just had 6 and i am online for mere 20 mins.
This is getting out of hand. We can't win the numbers game when the opponents are computers.

Agree, I've done 21 so far, time for a lockdown (or 24 hour acceptance period before allowing to view other user profiles) for new registrations it seems.

Cheers,
Bart
 

Asher Kelman

OPF Owner/Editor-in-Chief
Another 40 spammers later. but I am using Cem's fast and brutal way. I did rescue two real photographers on the way! It's very way to nuke them too with these weapons of mass destruction.

I'm going to review the registration process and make it more thought requiring. Have to first deliver pictures for tomorrow and get my CS5 installed. Bad back. Too much lugging of gear. Ultrasound is magic. Will catch up here over the weekend.

Asher
 
Another 40 spammers later. but I am using Cem's fast and brutal way. I did rescue two real photographers on the way! It's very way to nuke them too with these weapons of mass destruction.

I had one this morning with what looked like a real name, but the other fields showed the tell tale signs of a fake entry, like duplicate field entries and fake words or incomprehensable grammar. IP addresses that lead nowhere may give false clues, but there might be other reasons for traceroutes or pings or whois not finding them. It's the collective of clues and patterns that makes me decide if it is a fake or not, I don't think I caused any collateral damage because most are easy to spot for a human, it just takes too much time to be in time.

I'm going to review the registration process and make it more thought requiring. Have to first deliver pictures for tomorrow and get my CS5 installed. Bad back. Too much lugging of gear. Ultrasound is magic. Will catch up here over the weekend.

Take care, and watch your health. Perhaps a temporary lockdown on registrations is in order.

Cheers,
Bart
 

Asher Kelman

OPF Owner/Editor-in-Chief
Thanks to you and Cem for the help today!

Take care, and watch your health. Perhaps a temporary lockdown on registrations is in order.

Cheers,
Bart


We don't want to punish the real photographers trying to join. In fact we must make it easier. If folk can get in faster by posting pics and having a gallery or a sensible introduction, then we will get them in while their enthusiasm is high!

If we lock down, then after 24 hours it just starts again. We'll get through this. The BOT has not got one successful registration in about 200 attempts! I wonder if they give up!

Please do not ever send them a message that they have been banned or deleted. Make sure that you check No to that option in the registration notification dialog box below the list of registrations!!

Thanks so much,

asher
 
Please do not ever send them a message that they have been banned or deleted. Make sure that you check No to that option in the registration notification dialog box below the list of registrations!!

I have no access to that list or option, I can just see the "Who is on-line" and decide to allow their registration attempt to continue, or go to the Mods area and take Banning action there.

Just banned another 5, I'm up to 31 this morning, and counting.

Cheers,
Bart

P.S. 41 and counting
 
What has happened so suddenly to account for this ? Any ideas ?

Why now ?

Hi Fahim,

From my perspective, hard to say, I don't have access to all the board's logs.

Maybe we're just popular, and thus a potential source for email addresses and other valued info?

Just nuked registration attempt no. 56 since this morning.

Cheers,
Bart
 

Cem_Usakligil

Well-known member
Important security notice!

Dear All,

Important security notice: Please take note that any activated member, including the spammers, can see your profile details, "visitors messages" (if you have ever used them) and your contacts/friends, etc. A spammer who has activated his registration using a valid email address has subsequently access to these details of your profile even before his membership request has been finally approved by Asher. By which time, Asher or a mod can ban the spammer, but it may have been too late.

Bart and I have tested this scenario today and I could successfully register and activate myself as a dummy spammer, after which all your visitors messages and member details (except for your email addresses) became visible to me and I could harvest them if I wanted to. We shall take this up with Asher and try to fix things asap. In the meantime, in order to protect yourselves you can take the following actions:

1) Go to your User CP (see the attached picture for details)
2) Click on the "Profile Privacy" link on the left hand menu.
3) Change the privacy options as shown in the attached picture.

opf_07012011_1.png

Mind you, it is anyway a good idea to limit the visibility of your visitor messages to your friends even without a threat from the spammers. Some people use the visitor messaging as a replacement to PMs, but we then can all read what's going on. Not a good practice if you ask me. Please use PMs instead.

Hope this helps, if not, please ask!


opf_07012011_1.png
 

Cem_Usakligil

Well-known member
Update

Hi All,

....Important security notice: Please take note that any activated member, including the spammers, can see your profile details, "visitors messages" (if you have ever used them) and your contacts/friends, etc. A spammer who has activated his registration using a valid email address has subsequently access to these details of your profile even before his membership request has been finally approved by Asher. By which time, Asher or a mod can ban the spammer, but it may have been too late.

Bart and I have tested this scenario today and I could successfully register and activate myself as a dummy spammer, after which all your visitors messages and member details (except for your email addresses) became visible to me and I could harvest them if I wanted to. We shall take this up with Asher and try to fix things asap.
As promised, we have now taken care of this security loophole; thanks to Nicolas. The previously suggested change to your profile privacy is no longer a strict requirement, although it is always a good idea to be aware of what info you are sharing with the registered members and unshare it if you don't want to.

Cheers,
 

fahim mohammed

Well-known member
just logged in to check.

all the heavy weights are logged on.

i am out of here.

get 'em tigers.

doug/john/asher...shall respond in the morning.

good night. good hunting.
 
Top