Jump to content

Not so inoccent random PM's (from Emma ?) PLZ READ ITS A REAL ISSUE

Message added by vanished

We are aware of this problem and are actively working to eliminate it as best we can.

Do not make any more threads about this issue.  This is now the main topic and additional threads will just be merged into this one if found.

 

If you receive one of these PMs,

  • Do not click any links
  • Do not reply
  • Report it using the links/buttons available so we are made aware (example below)
  • Delete it

If you see one of these profiles:

  • Do not post on their page
  • Report any spam status updates on the page
  • If the account is more than 24 hours old and there is no spam on the page, it is almost certainly banned, even if you cannot see it.  Again, refer to recommendation 1 above

If you received a notification for a PM, but the PM does not exist, it was almost certainly due to one of these and can be safely ignored.

If you received what appeared to be spam email from LTT, please understand that we do not send spam, but if you have elected to receive email notifications of PMs, you will receive an email about PMs, including this PM which is spam.

Spoiler

image.thumb.png.a7da6dfe2c6e1cb53510c568fa2ccdc5.png

image.png.4bd16903dd5854e59b75011dc97fc4fa.png

 

10 hours ago, LogicalDrm said:

 

Well, not that unexpected. I would say we get the waves few times a year. This is extensive one, and mainly since it targets PM system. The Moderators have quick ways to deal with common spam. It removes account and all of their posts. However it doesn't remove PMs sent. So while NA/AUS/NZ based Moderators have already banned many of the bots, PMs sent can still be there. Making this look like a continuing issue (when it necessarily isn't).

It was an over exaggeration to get the point across.

Link to comment
Share on other sites

Link to post
Share on other sites

I`ve had these PM`s on about 6 different forums now, (mainly Flight sim Forums). 

Took me about 1/2 a second to recognise it for what it was, then click delete.

Not the end of the world, and she did have nice ermmm Eyes....?

Link to comment
Share on other sites

Link to post
Share on other sites

28 minutes ago, demotricus said:

I`ve had these PM`s on about 6 different forums now, (mainly Flight sim Forums). 

Took me about 1/2 a second to recognise it for what it was, then click delete.

Not the end of the world, and she did have nice ermmm Eyes....?

Good to know it's not just us, I guess.

Quote or tag me( @Crunchy Dragon) if you want me to see your reply

If a post solved your problem/answered your question, please consider marking it as "solved"

Community Standards // Join Floatplane!

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, wkdpaul said:

Damn .. looks like I missed the party!!!

I got "invited" by a Emas595. I wasn't interested. If I knew you wanted to go I would have offered you my invitation.

Link to comment
Share on other sites

Link to post
Share on other sites

I think the real question is how can you cosplay nude? isn't that like when you dress up? 

Link to comment
Share on other sites

Link to post
Share on other sites

Hi Bhosted,
Emmi756 has sent you a message!

Read full message


— Linus Tech Tips

 

What is this nonsense? Seems like she spammed all of us. 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Bhosted said:

Hi Bhosted,
Emmi756 has sent you a message!

Read full message


— Linus Tech Tips

 

What is this nonsense? Seems like she spammed all of us. 

topic merged

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

51 minutes ago, floofer said:

I think the real question is how can you cosplay nude? isn't that like when you dress up? 

Well you could cosplay as a nudist, or a nude character ;)

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, TempestCatto said:

Well you could cosplay as a nudist, or a nude character ;)

Nudist Beach time ?

Tho if ur nipples aren't glowing purple it's finna be a 0/10 cosplay ?

Intel HEDT and Server platform enthusiasts: Intel HEDT Xeon/i7 Megathread 

 

Main PC 

CPU: i9 7980XE @4.5GHz/1.22v/-2 AVX offset 

Cooler: EKWB Supremacy Block - custom loop w/360mm +280mm rads 

Motherboard: EVGA X299 Dark 

RAM:4x8GB HyperX Predator DDR4 @3200Mhz CL16 

GPU: Nvidia FE 2060 Super/Corsair HydroX 2070 FE block 

Storage:  1TB MP34 + 1TB 970 Evo + 500GB Atom30 + 250GB 960 Evo 

Optical Drives: LG WH14NS40 

PSU: EVGA 1600W T2 

Case & Fans: Corsair 750D Airflow - 3x Noctua iPPC NF-F12 + 4x Noctua iPPC NF-A14 PWM 

OS: Windows 11

 

Display: LG 27UK650-W (4K 60Hz IPS panel)

Mouse: EVGA X17

Keyboard: Corsair K55 RGB

 

Mobile/Work Devices: 2020 M1 MacBook Air (work computer) - iPhone 13 Pro Max - Apple Watch S3

 

Other Misc Devices: iPod Video (Gen 5.5E, 128GB SD card swap, running Rockbox), Nintendo Switch

Link to comment
Share on other sites

Link to post
Share on other sites

Was there not two or three obvious bots making accounts yesterday in the activity feed yesterday  ? I am pretty sure I seen that. There are a bunch of Emmas and some number from what I seen

Link to comment
Share on other sites

Link to post
Share on other sites

20 hours ago, Morgan MLGman said:

If you have any specific recommendations for improvements in mind, feel free to share.

 

  • Limit multi-user PMs to only accounts who have an specific amount of existing forum engagement (e.g. 20+ posts, keep actual number private and changing)
  • Limit links in PMs to only accounts who have a specific amount of existing forum engagement (e.g. 5+ posts, keep actual number private and changing)
  • Require account setup (e.g. profile picture upload, signature) before access to certain features (e.g. PMs)
  • Automatic flagging and logging of accounts that get errors too often (helps stop people testing bots)
  • Captchas for PMs containing profanity (would help with toxicity too)
  • Disable PM email notifications by default

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, rcmaehl said:
  • Limit multi-user PMs to only accounts who have an specific amount of existing forum engagement (e.g. 20+ posts)

I had this same idea, it is not viable sadly.  The change required would prevent all existing users from sending PMs until they posted an additional X times.  There is a potential workaround, but we are weary of using that given the risk.  Additionally, this would likely just push the spam into topics and status updates where public visibility is higher.  It would be good that it's less directed at users, but you can see the downside as well hopefully.

Quote
  • Limit links in PMs to only accounts who have a specific amount of existing forum engagement (e.g. 5+ posts)

I'm not sure this is even possible, but if it was, it would fall victim to the above limitation anyway.

Quote
  • Require account setup (e.g. profile picture upload, signature) before access to certain features (e.g. PMs)

I'm not sure we really want to do this given the amount of collateral damage it could cause, as well as the relatively low barrier to entry for spam accounts.

Quote
  • Automatic flagging and logging of accounts that get errors too often (helps stop people testing bots)

Not sure about this one, will mention it to the group

Quote
  • Captchas for PMs containing profanity (would help with toxicity too)

An additional captcha has been added to the sign-up process for probable spam sources

Quote
  • Disable PM email notifications by default

This should be easily doable, but would not help anyone with them already enabled.

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

18 minutes ago, TheVillageIdiot said:

Was there not two or three obvious bots making accounts yesterday in the activity feed yesterday  ? I am pretty sure I seen that. There are a bunch of Emmas and some number from what I seen

No, it's more than a few bots, a LOT more.

 

Our count of spam PMs is in the thousands! Quite a few people worked their ass off to fix that (thx guys!)

 

But not me though, I was offline fighting my own IRL war ; my daughter didn't want to do her homework !!! :P

 

Edited by wkdpaul

If you need help with your forum account, please use the Forum Support form !

Link to comment
Share on other sites

Link to post
Share on other sites

They seeded the crap out of this site .... I am certain there was there three names with some random numbers just making account after account. So do not comfortable cause there is more. :)  Should be easy to figure out tho ? New account list.

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, Ryan_Vickers said:

-snip-

One additional thing. Various websites use exit pages/scripts. Links to external traffic headed can be filtered and specific domains blacklisted. onbeforeunload or something along those lines

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, rcmaehl said:

One additional thing. Various websites use exit pages/scripts. Links to external traffic headed to external websites can be filtered and specific domains blacklisted. onbeforeunload or something along those lines

Without going into too much detail, we are actively filtering spam based on content and have added things to the list to deal with this new issue.  I am not sure I follow... is this what you're describing or something else? 

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, TheVillageIdiot said:

:)  Should be easy to figure out tho ? New account list.

Way ahead of you, we have a list of accounts.

 

Not sure how they got around the signup captcha, but it happened quickly and it was hundreds of accounts.

 

As @Ryan_Vickers mentioned, if there are any accounts left, it's because they don't follow the *name+number* scheme and were not reported.

 

That shit hurt the forum spam reputation since lots of people have email notification enabled, so the forum sent thousands of spam-looking emails (the emails contained the PM content, which was spam) ... So yeah :(

Edited by wkdpaul

If you need help with your forum account, please use the Forum Support form !

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, wkdpaul said:

Not sure how they got around the signup captcha, but it happened quickly and it was hundreds of accounts.

Basically, these groups have hoards of human slaves they can submit capchas to for verification.  They just sit around all day doing them for pennies, letting the attackers focus on other aspects of what they're doing (not that they ever seem to put much effort or thought into that either though).

 

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

33 minutes ago, Ryan_Vickers said:

Without going into too much detail, we are actively filtering spam based on content and have added things to the list to deal with this new issue.  I am not sure I follow... is this what you're describing or something else? 

This is more of a retroactive(?) approach for linked content that has bypassed spam filters.

Sites used to display messages like these for external links with onClick, onBeforeUnload, or other implementations:
 

Image result for external link warning

 

During this time you can compare the external link to a blacklist in whatever implementation you've created and display an appropriate message. e.g. Navigation to <domain> has been blocked due to known malicious content. OR <domain> appears suspicious, are you sure you wish to continue? While this can easily be bypassed using URL shorteners and really any website with open redirects, it's an extra layer of security while cleanup is being done. It's a bit of work, but spam filters can't catch everything, so additional mitigation options after the spam has been created are always useful. 

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, rcmaehl said:

This is more of a retroactive(?) approach for linked content that has bypassed spam filters.

Sites used to display messages like these for external links with onClick, onBeforeUnload, or other implementations:
 

Image result for external link warning

 

During this time you can compare the external link to a blacklist in whatever implementation you've created and display an appropriate message. e.g. Navigation to <domain> has been blocked due to known malicious content. OR <domain> appears suspicious, are you sure you wish to continue. While this can easily be bypassed using URL shorteners and really any website with open redirects, it's an extra layer of security while cleanup is being done. It's a bit of work, but spam filters can't catch everything, so additional mitigation options after the spam has been created are always useful. 

Ah I see now, yes I've seen those before on other sites.  I'll mention this to the team as well, since it's probably not the worst thing to have anyway, although I'm not sure how much it'll help in this case.

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×