Reporting spam

Off topic discussion zone.

Moderators: winston, another_commander, Cody

User avatar
DaddyHoggy
Intergalactic Spam Assassin
Intergalactic Spam Assassin
Posts: 8515
Joined: Tue Dec 05, 2006 9:43 pm
Location: Newbury, UK
Contact:

Post by DaddyHoggy »

Solas wrote:
I was using Google to search aegidian.org as results point to page,
and came accross a jsp that looked out of place, Google lists 240+
http//www.google.com/search?num=40&hl=en&q=js ... lr=lang_en

another thing ..
http//www.phpbb.com/index.php itself is down. ( vulnerability in an outdated PHPList )
http//community.mybboard.net/thread-44513.html advises on this.

hope this helps

Solas
Selezen wrote:
Apparently I was having a DaddyHoggy moment.
Oolite Life is now revealed here
User avatar
JensAyton
Grand Admiral Emeritus
Grand Admiral Emeritus
Posts: 6657
Joined: Sat Apr 02, 2005 2:43 pm
Location: Sweden
Contact:

Post by JensAyton »

DaddyHoggy wrote:
Solas wrote:
I was using Google to search aegidian.org as results point to page,
and came accross a jsp that looked out of place, Google lists 240+
http//www.google.com/search?num=40&hl=en&q=js ... lr=lang_en

another thing ..
http//www.phpbb.com/index.php itself is down. ( vulnerability in an outdated PHPList )
http//community.mybboard.net/thread-44513.html advises on this.

hope this helps

Solas
Well, that was interesting.

It appears that part of a distributed warez network had been hidden in our images/avatars/ directory. Until I have a good explanation for how that happened, uploading of avatars is disabled again. As far as I’m aware we don’t use PHPList for anything Oolite-related, but Giles may have it installed for some other part of aegidian.org, possibly something that’s no longer used. I’ve e-mailed him about it.

Out of interest, the following out-of-place files were in images/avatars/ (modification dates in parens):
  • index.htm (modified from original blank page; 2005-10-05 00:00)
  • time.php (2005-10-05 00:00)
  • date.php (2005-10-05 00:00)
  • 13923715934416f3d4e57ff.php (2005-10-05 00:00)
  • .htaccess (2005-10-05 00:00)
  • ferrometer91/ (2008-11-01 08:21)
  • ferrometer91/.htaccess (2008-11-01 08:21)
  • ferrometer91/guest.php (2008-12-16 12:14)
  • ferrometer91/messages.php (2008-12-16 12:13)
I’m assuming ferrometer91 and 13923715934416f3d4e57ff.php are random names; the latter looks like one of the random names of avatar images (for instance, 1584281108474245c375d5f.png). The .htaccess files set date.php and messages.php as the error pages for their respective directories, and these files created a virtual hierarchy of pages (the .jsp extension is a red herring). All the code was scrambled php and JavaScript; nothing complex, but I haven’t bothered decoding it.

I know a couple of our users manage phpBBs of their own; I suggest taking a look in your avatars directory. There should be no .htaccess file, no php files, no subdirectories other than gallery, and index.htm should be a blank page containing no JavaScript. (Note: these details may not be correct for phpBB 3.)
User avatar
0235
Deadly
Deadly
Posts: 175
Joined: Fri Sep 12, 2008 1:29 pm
Location: In a rock, being a hermit

Post by 0235 »

help.

this man attacked my computer

Image


look what it did!
Image
User avatar
Commander McLane
---- E L I T E ----
---- E L I T E ----
Posts: 9520
Joined: Thu Dec 14, 2006 9:08 am
Location: a Hacker Outpost in a moderately remote area
Contact:

Post by Commander McLane »

User avatar
Captain Hesperus
Grand High Clock-Tower Poobah
Grand High Clock-Tower Poobah
Posts: 2310
Joined: Tue Sep 19, 2006 1:10 pm
Location: Anywhere I can sell Trumbles.....

Post by Captain Hesperus »

https://bb.oolite.space/viewtopic.php?p=70187#70187

<ka-chik> BOOOOOOOOOOOOOOOOOOOOOOMMM!!!!

Captain Hesperus
The truth, revealed!!
Image
User avatar
Commander McLane
---- E L I T E ----
---- E L I T E ----
Posts: 9520
Joined: Thu Dec 14, 2006 9:08 am
Location: a Hacker Outpost in a moderately remote area
Contact:

Post by Commander McLane »

Captain Hesperus wrote:
https://bb.oolite.space/viewtopic.php?p=70187#70187

<ka-chik> BOOOOOOOOOOOOOOOOOOOOOOMMM!!!!
You wouldn't want to start another civil war inside the clock-tower now, would you? :wink:
User avatar
Captain Hesperus
Grand High Clock-Tower Poobah
Grand High Clock-Tower Poobah
Posts: 2310
Joined: Tue Sep 19, 2006 1:10 pm
Location: Anywhere I can sell Trumbles.....

Post by Captain Hesperus »

:D
I'm a cat, thus easily bored....

Captain Hesperus
The truth, revealed!!
Image
User avatar
Disembodied
Jedi Spam Assassin
Jedi Spam Assassin
Posts: 6885
Joined: Thu Jul 12, 2007 10:54 pm
Location: Carter's Snort

Post by Disembodied »

*

This one looks dodgy to me ... website links to a "money-making robot".
User avatar
Disembodied
Jedi Spam Assassin
Jedi Spam Assassin
Posts: 6885
Joined: Thu Jul 12, 2007 10:54 pm
Location: Carter's Snort

Post by Disembodied »

*

And another – website linking to online loans ...
another_commander
Quite Grand Sub-Admiral
Quite Grand Sub-Admiral
Posts: 6685
Joined: Wed Feb 28, 2007 7:54 am

Post by another_commander »

*

This one is definitely spamming and has posted the same message all over the Internet. I just deleted it from Outworld, so would one of our esteemed Spam Assassins do the honors and terminate the bot?
User avatar
Disembodied
Jedi Spam Assassin
Jedi Spam Assassin
Posts: 6885
Joined: Thu Jul 12, 2007 10:54 pm
Location: Carter's Snort

Post by Disembodied »

*

And another one for the chop ...
User avatar
Disembodied
Jedi Spam Assassin
Jedi Spam Assassin
Posts: 6885
Joined: Thu Jul 12, 2007 10:54 pm
Location: Carter's Snort

Post by Disembodied »

*

And yet another ...
User avatar
Disembodied
Jedi Spam Assassin
Jedi Spam Assassin
Posts: 6885
Joined: Thu Jul 12, 2007 10:54 pm
Location: Carter's Snort

Post by Disembodied »

*

Blechh ... and still another
User avatar
DaddyHoggy
Intergalactic Spam Assassin
Intergalactic Spam Assassin
Posts: 8515
Joined: Tue Dec 05, 2006 9:43 pm
Location: Newbury, UK
Contact:

Post by DaddyHoggy »

Is anybody actually killing these off? All the ones identified so far are still present and correct

[unpacks Silent Death and watches the door as new members shuffles in]
Selezen wrote:
Apparently I was having a DaddyHoggy moment.
Oolite Life is now revealed here
another_commander
Quite Grand Sub-Admiral
Quite Grand Sub-Admiral
Posts: 6685
Joined: Wed Feb 28, 2007 7:54 am

Post by another_commander »

DaddyHoggy wrote:
Is anybody actually killing these off? All the ones identified so far are still present and correct
I was under the impression that members tagged as Spam Assassins had the power to do this. Unfortunately moderators cannot interfere with user status, otherwise these spam instances would have been already sanitized. If the SAs cannot do anything, then I guess it's up to one of the forum admins.
Post Reply