I have noticed over the last month that SSC has been getting flooded with user registrations but none of these accounts have posted or even logged in after initial registration. After digging into a few accounts I have noticed they are making these accounts to create linkbacks to other sites. I will look into creating a question for registration thats related to science fiction to slow this down, because the captcha is obviously not working 🙂
Example of this was this morning I check my email and 35 new accounts created.... but no new posts. I would like to think SSC is super popular and getting 35 new accounts a day from legit gamers but I know this isn't happening 🙂 darn spammers are relentless.
So if you are a new user that has visited recently and you are real and you have yet to post you may have your account removed. Just a heads up! Simplest way to not have your account deleted is make a legit post.
We get plenty of those on the Oolite forum, which I clear out on a daily basis.
As for the captcha, these days it ain't so effective. A sci-fi question is better.
Oolite Naval Attaché
Damn spammers are everywhere these days but yes a sci-fi question should put a stop to them or really slow them down a bit. Perhaps think of something that would need to be looked up? Don't make it too hard of course but spammers wont bother if they have to put any effort into signing up for a site.
Yeah been looking into it last night and I can't seem to find a simple question mod for login for wordpress. I started to use 'deny' statements in the security file to block IPs I found a site that publishes daily blocked IP lists and I have setup a cron job to download this daily (hopefully) and this will help a little I think - if you suddenly get blocked by accident let me know 🙂 your IP might be in a known IP range of spammers.... I would add you specifically to my white list.
But these account creation bots are crazy I get 30-50 a day..... so I will still continue to look into this issue and I been just deleting all accounts unless they change their acct password, those users that do change I think are legit people. Ugh, so frustrating at times 😉
Yeah, well I've changed my email for the site just to be safe. Hopefully that will help. Makes me wonder tho if anyone out there has a plan to deal with all these spam bots cluttering up the net in general.
Looks like what I did has slowed this attack down, I didn't get any registrations from the domains I have been seeing lately 👍
You probably didn't need to change your email Geraldine, because they don't have access to the accounts or any site critical data. But I was just trying to slow down the mass registrations that were happening for some reason, noticed this happening about 4wks ago.
I have to admit its a bit smart to do it that way.... one your not spamming so your account doesn't get banned and you post links in your account profile which gets indexed by google so technically its a backlink to your site. I would have probably overlooked this if I wasn't paying attention to the usernames and wondering.... why would someone want a username that complex, it will be a pain to type everytime.... so I looked up the profile and saw the links and then examines a lot of the other accounts and they had it too... so I just started deleted them if they were common domains that I have been observing.