Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Fake Accounts and SPAM Posts

    Scheduled Pinned Locked Moved Forum Feedback
    87 Posts 15 Posters 7.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      elvisimprsntr
      last edited by elvisimprsntr

      One application I use for ODB-II diagnostics on my Ford vehicles (https://forscan.org) requires a forum invitation code, which you can only get when you pay for their application.

      Screenshot 2024-11-19 at 1.45.34 PM.png

      Now that you have to register to download the installer (CE or +), perhaps the forum invitation code can be part of the registration process.

      P.S. script kiddies are at it again already.

      1 Reply Last reply Reply Quote 0
      • P
        Patch @johnpoz
        last edited by

        @johnpoz said in Fake Accounts and SPAM Posts:

        yeah I can see the IPs - and lots of vpns on the ones I checked.. But not just 1 vpn, ie saw many of the major vpn players

        @johnpoz said in Fake Accounts and SPAM Posts:

        on many a forum posts from all over the place in the last few days..

        I mean a lot of different forums.. So clearly its not targeted at just pfsense forums.

        @Pippin said in Fake Accounts and SPAM Posts:

        OpenVPN forum has been hit also, close to 30000 posts the last few days.

        That suggests the source of the spam has significant resources and has build the capacity to attack over a considerable time.

        @Patch said in Fake Accounts and SPAM Posts:

        I don't understand where the profit is in doing this. The motivations I can think of are

        1. forum filter companies justifying their value
        2. denial of service attack by a product or country or political competitor.
        
        3. advertising for service spamming.
        
        4. the thrill of achieving a successful attack.
        
        5. A bot error
        
        6. An angry ex-customer
        

        Which suggest 2. is the most likely. Perhaps a response to Russia/Ukraine or Israel/Iran or American politics

        1 Reply Last reply Reply Quote 0
        • E
          elvisimprsntr
          last edited by elvisimprsntr

          Script kiddies are at it again. Can their mother please shout down the stairs to the basement to tell the trolls to knock it off?

          We are loosing the Whac-a-Mole game. Mark Rober seems to be good at inventing ways to defeat carnival arcade games.

          1 Reply Last reply Reply Quote 0
          • P
            Popolou @johnpoz
            last edited by

            @johnpoz Perhaps rotate the anti-spam question on new user registration. I wouldn't be surprised if they simply added that answer to any bot script. I'm presuming they aren't bypassing this somehow...

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @Popolou
              last edited by

              @Popolou I have no control over any of that, just a mod.. Need to do something different, the amount getting through is insane

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • M
                mer
                last edited by

                I don't know if it helps but today I learned that one can only report 10 spam profiles per day :)

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @mer
                  last edited by

                  @mer while reporting is good.. It can also turn into a form of spam for the mods and admins. If its a blatant spam post, ie its own topic etc.. and especially if there are bunch it more than likely doesn't warrant reporting.

                  What is good to report is those ones buried in another thread that don't standout as spam from a quick glance.. We are all aware of these spam floods coming in and you can't but help but know that they are spam.. Reports are prob best on those ones that they came back latter and added spam links in them and the like.. Even ones on old threads, etc. buried deep in the thread that nobody noticed when they were posted, etc.

                  Thanks!!

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  S stephenw10S 2 Replies Last reply Reply Quote 4
                  • S
                    slu @johnpoz
                    last edited by

                    @johnpoz said in Fake Accounts and SPAM Posts:

                    while reporting is good.. It can also turn into a form of spam for the mods and admins.

                    Good point, sorry. 😬

                    pfSense Gold subscription

                    1 Reply Last reply Reply Quote 1
                    • stephenw10S
                      stephenw10 Netgate Administrator @johnpoz
                      last edited by

                      @johnpoz said in Fake Accounts and SPAM Posts:

                      Reports are prob best on those ones that they came back latter and added spam links in them and the like.. Even ones on old threads, etc. buried deep in the thread that nobody noticed when they were posted, etc.

                      Yup that ^. Those are the hardest to pick up otherwise.

                      1 Reply Last reply Reply Quote 0
                      • Bob.DigB
                        Bob.Dig LAYER 8
                        last edited by Bob.Dig

                        For weeks now I see messages like your IP has been banned, but if I reload the page, it still works. I changed from using a privacy-VPN to my ISP but I even get more messages like this. Now I have to ask, what should I do about it. It is a mild annoyance, reloading fixes it. But what else could I do. Should I enable third-party-scripts? Or is it just how it is, after all those spam-posts.
                        I get it, stopping those must have priority. But I m also curious, why not using a privacy-VPN makes even more (light) problems for me.

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Hmm, are you using a fixed IP?

                          There are a bunch of things in the blacklists but I don't think we added any after the spam flood. Most of what is there are used by VPN providers because, unfortunately, that's what spammers use.

                          But I wouldn't have expected your usual ISP to be listed.

                          Bob.DigB 1 Reply Last reply Reply Quote 0
                          • Bob.DigB
                            Bob.Dig LAYER 8 @stephenw10
                            last edited by

                            @stephenw10 My impression is and I have not talked about that with anyone else yet, that whatever I do, I get those messages. And reloading helps every time so it might not be an actual blacklist but something else with my Browser, what triggers this...

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              Hmm, do you have load-balanced WANs perhaps?

                              Bob.DigB 1 Reply Last reply Reply Quote 0
                              • Bob.DigB
                                Bob.Dig LAYER 8 @stephenw10
                                last edited by Bob.Dig

                                @stephenw10 No. My Browser is optimized for privacy though.
                                Still having that problem...

                                Before and still I often get "Looks like your connection to Netgate Forum was lost, please wait while we try to reconnect.", but not that my IP is blacklisted ([[error:blacklisted-ip]]), which it is not. But it seems like I am the only one with that interesting problem.

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  I used to see the connection lost message but haven't for some time, like maybe 6 months.

                                  You don't have dual WANs?

                                  Bob.DigB 1 Reply Last reply Reply Quote 0
                                  • Bob.DigB
                                    Bob.Dig LAYER 8 @stephenw10
                                    last edited by Bob.Dig

                                    @stephenw10 said in Fake Accounts and SPAM Posts:

                                    You don't have dual WANs?

                                    No, I am not JKnott, god bless him.

                                    I have a lot of VPN Client-Connections (and Gateways) but I am not using them for this forum right now.

                                    Edit: My connection goes through a SOCKS5-Proxy under my control. I don't know if this can be seen by the forum or anyone though. I hope not. 😉

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Hmm, no the forum couldn't 'see' that. It also implies your traffic always comes from that IP. Unless the proxy is load-balancing somehow?

                                      Bob.DigB 1 Reply Last reply Reply Quote 0
                                      • Bob.DigB
                                        Bob.Dig LAYER 8 @stephenw10
                                        last edited by

                                        @stephenw10 said in Fake Accounts and SPAM Posts:

                                        Hmm, no the forum couldn't 'see' that. It also implies your traffic always comes from that IP. Unless the proxy is load-balancing somehow?

                                        Hi Stephen, I still have that problem every day and I have no clue what to do about it. May I ask for a whitelisting? I can give a "static" IP if it helps.

                                        johnpozJ 1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by stephenw10

                                          Hmm, as far as I know the forum has no way to whitelist IPs. There is only a blacklist. And your IP cannot be one it because if it was you wouldn't be able to connect at all. 😕

                                          Something else must be happening. Do you have dual stack v6/v4 perhaps?

                                          There are 5 IPs logged for recent connections on your account. But it looks like from x.x.x.182 in the last 25 days.

                                          1 Reply Last reply Reply Quote 0
                                          • johnpozJ
                                            johnpoz LAYER 8 Global Moderator @Bob.Dig
                                            last edited by

                                            @Bob-Dig no need for static - what is your IPv6 address, can you give the prefix, or pm it to me and can check the blacklist - maybe you are hitting it via IPv6 and then switching to IPv4 that is allowed?

                                            There was a period where was seeing those you lost connection myself - but as Steve mentioned haven't seen that in quite sometime.

                                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                                            If you get confused: Listen to the Music Play
                                            Please don't Chat/PM me for help, unless mod related
                                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                            Bob.DigB 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.