Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Fake Accounts and SPAM Posts

    Scheduled Pinned Locked Moved Forum Feedback
    87 Posts 15 Posters 7.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      elvisimprsntr
      last edited by elvisimprsntr

      Well seems some script kiddies have found another way to automatically create random fake accounts and post SPAM, making the forums unusable.

      Seems like there needs to be additional barriers to creating fake accounts.

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @elvisimprsntr
        last edited by

        @elvisimprsntr

        additional barriers

        That's problematic, as the bots are getting more 'intelligent' as some of the human (may I call them bottom tiers ?) subscribers.
        The forum was usable (for me) as the spammer(s) posted only here : Home > pfSense® Software > General pfSense Questions

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        fireodoF 1 Reply Last reply Reply Quote 0
        • fireodoF
          fireodo @Gertjan
          last edited by

          @Gertjan said in Fake Accounts and SPAM Posts:

          as the spammer(s) posted only here : Home > pfSense Software > General pfSense Questions

          Not only there also in https://forum.netgate.com/category/76/tnsr-feedback and in other parts of the forum too ...

          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
          pfsense 2.7.2 CE
          Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

          P 1 Reply Last reply Reply Quote 1
          • P
            Popolou @fireodo
            last edited by

            Seeing a lot of this lately elsewhere too. Over here, they seemed to be posting every few seconds since last night. Need to beef up the security.

            1 Reply Last reply Reply Quote 0
            • J
              jwt Netgate
              last edited by jwt

              Was up at 3am local dealing with this.

              We’re on it

              P 1 Reply Last reply Reply Quote 12
              • M
                mvikman
                last edited by

                Looks like the bot spamming is still continuing, at slower pace now though

                pfSense Plus 24.11-RELEASE (amd64)
                Dell Optiplex 7040 SFF
                Core i5-6500, 8GB RAM, 2x 240GB SSD (ZFS Mirror)
                HPE 561T (X540-AT2), 2-port 10Gb RJ45
                HPE 562SFP+ (X710-DA2), 2-port 10Gb SFP+

                fireodoF 1 Reply Last reply Reply Quote 0
                • fireodoF
                  fireodo @mvikman
                  last edited by

                  @mvikman said in Fake Accounts and SPAM Posts:

                  Looks like the bot spamming is still continuing, at slower pace now though

                  That was a huge amount of SPAM&Damage so I guess the cleanup work continues ...

                  Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                  SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                  pfsense 2.7.2 CE
                  Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                  P 1 Reply Last reply Reply Quote 0
                  • P
                    Popolou @fireodo
                    last edited by

                    @fireodo Perhaps just lockdown any new signups and the bot will get the message.

                    1 Reply Last reply Reply Quote 1
                    • P
                      Patch @jwt
                      last edited by Patch

                      I don't understand where the profit is in doing this. The motivations I can think of are

                      1. forum filter companies justifying their value

                      2. denial of service attack by a product or country or political competitor.

                      3. advertising for service spamming.

                      4. the thrill of achieving a successful attack.

                      5. A bot error

                      6. An angry ex-customer

                      For discrete attacks 3. could deliver a useful return. Not for the recent one here. Seams unlikely in this case as the intrusion would be negative for every forum user

                      fireodoF GertjanG 2 Replies Last reply Reply Quote 0
                      • fireodoF
                        fireodo @Patch
                        last edited by

                        @Patch said in Fake Accounts and SPAM Posts:

                        I don't understand where the profit is in doing this.

                        Neither do I ...

                        Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                        SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                        pfsense 2.7.2 CE
                        Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                        1 Reply Last reply Reply Quote 0
                        • E
                          elvisimprsntr
                          last edited by elvisimprsntr

                          Well the script kiddies are at it again this morning.

                          1 Reply Last reply Reply Quote 0
                          • GertjanG
                            Gertjan @Patch
                            last edited by Gertjan

                            @Patch

                            All of that, or something else.
                            Someone wants it to happen, that's for sure.

                            For myself, I think, as we live in a world where it has become 'easy' to be known worldwide, they are out for the likes, the attention, the view hits. All this can help to sell advertisements on the sites - sell products, or get a product known. "Feeding the buzz beast".

                            It could be as simple as as "see If they can do it".

                            Spam forum posts today? Tagging with paint the concrete walls yesterday. Tomorrow, the 44K Starlink satellites will laser project our entire sky ?

                            edit : the spam scripts has been updated : now they are posting in every forum section.

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            A 1 Reply Last reply Reply Quote 0
                            • E
                              elvisimprsntr
                              last edited by elvisimprsntr

                              Are all the [redacted] fake accounts and SPAM posts coming from a particular CIDR blocks or TOR exit nodes?

                              GertjanG 1 Reply Last reply Reply Quote 0
                              • GertjanG
                                Gertjan @elvisimprsntr
                                last edited by

                                @elvisimprsntr said in Fake Accounts and SPAM Posts:

                                from a particular CIDR blocks or TOR exit nodes?

                                I put my chances on "change particular for big variety".
                                I can see the poster's IP's but if it was a /24 or /16 (IPv4) or /56 or even /32 (IPv6 both ) then a one click acrion would block them all.
                                The thing is : it isn't as easy as it looks.

                                All torrent exit nodes, or VPN (Shark, Nord, Express and friends) exit nodes are already mostly known and IP listed. So easy to one-click ban them all, but this would also block all the other forum visitors that need to use a VPN (is this actually a thing ? ) to visit this forum.

                                As usual, the visiting diversity of IPs used look more like a soft DDOS attack : hundreds of posts on the forum coming from as much different IPs.

                                Btw : I hope to be wrong, of course ^^
                                @johnpoz ; You can see the IPs : any thoughts ?

                                No "help me" PM's please. Use the forum, the community will thank you.
                                Edit : and where are the logs ??

                                johnpozJ 1 Reply Last reply Reply Quote 0
                                • M
                                  Marc05
                                  last edited by

                                  It seems more like targeted attack than random bots, but who knows...

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator @Gertjan
                                    last edited by johnpoz

                                    @Gertjan yeah I can see the IPs - and lots of vpns on the ones I checked.. But not just 1 vpn, ie saw many of the major vpn players then my daily quota of checking ran out at the site I use. But also lots of IPs just from known spammer countries.. If me I would just block all those countries.. I mean I have asked a few times to run a analysis on known users from those countries - do we have even one valid user from them? All of the IPs were coming from either VPN, or vps providers from what I could tell.. Saw a few DO netblocks, which I blocked. Nothing good would ever come from DO..

                                    But it does seem insane the amount of it coming in when it happens.. Either the spam filter was doing a way better job than I thought or yeah seemed like a targeted attack.. last night I clear up 46 different posts.. Normally we would see 1 or 2 posts from an account.. I saw 13 from one, 9 from another.. And while I was cleaning up those 4 more new accounts, etc. Previous round of flooding I saw one account with 18 posts in just a few minutes.

                                    Something that was working, is for whatever reason not currently - maybe they found a way thru the spam filter? All of the posts have the exact same sort of format. And were all posting phone numbers of how you could do something, contact a real person, call some company for a problem.. Clearly trying to get their SEO up what it looked like to me.

                                    Maybe the spam filter doesn't see phone numbers as possible spam and only links to websites?

                                    Many of the posts had broken variables posted vs a value, like a script that fails - sure everyone has seen those in spam email they get, etc. But they were not your typical sort of spam where someone seems to answer a question in the thread with a link to where you could find more info on the subject matter, etc. Nobody in their right mind would see that post on the forum and think oh great I will call that number next time I have a problem with X company ;) They have to be a targeted way to get some seo up on these phone numbers when googling for where to call, etc.

                                    In one way the seeing the amount of spam seems to indicate that the forums are popular, etc. And we make a good target for such shenanigans.. Maybe if not so popular we wouldn't get so much spam..

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                    GertjanG PippinP P 3 Replies Last reply Reply Quote 0
                                    • A
                                      Antibiotic @Gertjan
                                      last edited by

                                      @Gertjan said in Fake Accounts and SPAM Posts:

                                      For myself, I think, as we live in a world where it has become 'easy' to be known worldwide

                                      I'm from Moon.

                                      pfSense plus 24.11 on Topton mini PC
                                      CPU: Intel N100
                                      NIC: Intel i-226v 4 pcs
                                      RAM : 16 GB DDR5
                                      Disk: 128 GB NVMe
                                      Brgds, Archi

                                      1 Reply Last reply Reply Quote 0
                                      • GertjanG
                                        Gertjan @johnpoz
                                        last edited by

                                        @johnpoz said in Fake Accounts and SPAM Posts:

                                        Normally we would see 1 or 2 posts from an account.. I saw 13 from one, 9 from another.. And while I was cleaning up those 4 more new accounts, etc. Previous round of flooding I saw one account with 18 posts in just a few minutes.

                                        Is initial rate (== post) limiting possible ?
                                        Like : new users can post 2 new forum posts in 24 hours, and this limit will go away after X days, or 5 upvotes, whatever comes first.

                                        I mean : some (new) pfSense user decides to sign up and ask a - just one - question ? A legit person doesn't open 18 different post all over the place - and if he had 18 different questions, he would post them all in in the General Section, even of the majority of the questions are (for example) DNS related .... ;)

                                        This one : if a user edits his post, then it surely must be a human !

                                        What about : if the new forum user produces a valid ID (from these) :

                                        Netgate 4100
                                        Serial: 2014321874
                                        Netgate Device ID: e57dfcd41dc5ad5afb223
                                        

                                        then the "post rate limiting" is skipped right away as the new member is using a real pfSense.
                                        I presume these are "IDs" are avaible somewhere within the same Netgate walls ^^

                                        Anyway, just thinking out loud here.

                                        @johnpoz said in Fake Accounts and SPAM Posts:

                                        In one way the seeing the amount of spam seems to indicate that the forums are popular, etc. And we make a good target for such shenanigans.. Maybe if not so popular we wouldn't get so much spam..

                                        About that : before, AFIAK, forum stats existed.
                                        But I get it, showing that the forum has tens of thousands of forum members, and hundreds of thousands (a million soon) forum post ... that doesn't go unnoticed so I agree : don't show these stats (anymore).

                                        No "help me" PM's please. Use the forum, the community will thank you.
                                        Edit : and where are the logs ??

                                        johnpozJ 1 Reply Last reply Reply Quote 0
                                        • johnpozJ
                                          johnpoz LAYER 8 Global Moderator @Gertjan
                                          last edited by

                                          @Gertjan I just did google for one of the phone numbers in just a new spam that popped in.. And you see that number on many a forum posts from all over the place in the last few days..

                                          I mean a lot of different forums.. So clearly its not targeted at just pfsense forums.

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                          1 Reply Last reply Reply Quote 0
                                          • PippinP
                                            Pippin @johnpoz
                                            last edited by

                                            @johnpoz said in Fake Accounts and SPAM Posts:

                                            maybe they found a way thru the spam filter?

                                            Think so, OpenVPN forum has been hit also, close to 30000 posts the last few days.

                                            I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
                                            Halton Arp

                                            johnpozJ 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.