Increased spam here at the forum

A place to post alerts for confirmation, discussion, explanation.

Increased spam here at the forum

Postby Stephen » Wed Jun 14, 2006 1:40 am

Of late the forum is starting to get an increased amount of spam.

In the latest episode we had a person pertainging to act for animal rights in China, which no doubt the content of the story may itself be true, but that is 'social engineering/phising at the viewers expense in real fact.

I have gone though that users entire profile and data and gone on a search mission.

The message itself redirects to a site that appears legitimate and in fact it is NOT as in the backend code of the site they are using 'phishing/social enginnering' and some of the sites are using in-line frames to display the content and others are using a 'copy' of the original site and then auto-redirecting your browser to a new location and as such are decieving users about the content they are viewing.

In this particular case the owner of the site and other sites that are being run by the same user they are trying to by-pass Windows Security and to use a 'Windows Security Exploit' that is reffered in Microsoft Security Bulletin MS06-014

The sites through the network of asociated links that I traced through Google, Siteadvisor and WhoIS tools shows many traces of the 'ActiveX Object', 'Remote Data Services Data Control' 'msadco.dll' to automatically install because you do not have the latest security updates from Microsoft installed and as such this ActiveX object could be installed automatically into the users machine then giving the web site open access to your PC.

A few of the other posts that have started to appear are not just the latest 'blue pill' spam (don't want to mention that 'V' word due to Googles Adwords rubbish and have someone actually profit from this post by having an 'impression ad' displayed for that 'V' thing above')

The other type of 'spam' we are getting is of a different subject to what we are used to, a few of late have been for everyday pagerank/seo fools and as such appears harmless though just their 'Username' is tied to their internet domain name and are trying to increase there pagerank by having 'that' name in as many internet locations as possible, with or without a website link pointing back to there home page. (As the line between SEO and Google Pagerank is associated more and more these days with spam {Google is an advertising company and so are spammers, Google ARE NOT doing enough to address this problem} and I have serious issues with Google on all of this 'false economy' (again if it is not obvious) that only benefits spammers and Google, not the consumer or advertiser)

A solution for this is far from easy, though I am thinking that 'new users' should only be able to see a single area of the forum to then read a VERY EASY introduction to allow them to be able to post quickly and easily, though if the seo/pagerankers go though this the site that they link to will be reported to Google as a breach of Googles Terms and Conditions and will loose there account from Google and be removed from Google thus loosing the income stream they are trying to artificially create. (Whether Google accept this or not is another question, though it is in their best interests to do so)

I have started going absolute ruthless on these people getting into the forum, it is not just the links they are posting either. It includes there USERNAME, ICQ Numbers, Instant Messaging Addresses, Location, Occupation and Notes fields that they fill with 'keywords' applicable to them, sojust changing the website link is not enough anymore. We need to delete all of the profile information for the user and update the profile. I am then going in and deleting them completely from the system and how often they are actually returning to do this again we have no accurate statistics, only speculation. I think it is quite low, so I am deleting all accounts in this way.

If you see a 'new user' on the forum with only 1 post to their name (ie. The post you are reading) and it is just a link to a website please do not click the link and have these people (Google and the spammer) make money from your mouse click at best, at worst there is spyware/malware/virus waiting for you at the destination.

Why no 'source links in this post, I want to keep people away from where I have just been in having a security dodgeball game. Now that I have no Anti-Virus software running on Vista, I may just go do a security scan to check that I am still safe and clean myself. :wink:

One of the other issues surrounding all of this is the fact that if you have a Google Adwords/Adsense account you are basically not able to talk about this or you loose your account. Even part of Googles T&C state if you take legal action against Google for 'click fraud' you are for life banned from using the Google Adwords/Adsense as a revenue stream to help ofset your costs for running your website. So if you catch Google out on 'click fraud' you lose your revenue stream of income and are never allowed to use Google services in the future again for absolutly no fault of your own. Thus people who are getting 'dudded' by 'click fraud' are basically wearing the cost of 'click fraud' because they are still getting some money from the legitimates but if they complain they then have no income at all. How can an advertising company have a motto 'Do no evil'.

So, Google get your act together and I 'may' recommend your 'search' to users again, stop mis-directing users from your search results to URL's that you display as the destination address and take them to a differnt URL that is an advertisment for the company in question. And STOP spammers and yourselves profiting from SPAM. Google you MUST address this, and it is long overdue.

Here are the stats from the 'main-end-point' of the spam on 'Saving puppies in China' that tries to utilise the security exploit I mentioned above. So we are all being 'had' by these {I must watch my language} and if we feel guily about puppies in China and don't have our security up to date our machine gets infected. :( Sad for the puppies I say, but I will no longer be letting 'Dying Puppie' threads stay in the forum.

<img src="http://img159.imageshack.us/img159/1599/spam9jd.png">

I will delve into a fact finding mission to give some backup to what I am flat accusing Google of being the reason why we have so much exta spam these days on another day. But needless to say until Google clean up their act you will continue to see spam anywhere and everywhere on the internet becuase Google makes money from it.

Hmmm... Not the best worded or structered post, I apologise for that as it was a paragraph by paragraph typed as I progressed thorugh my discovery and its 12:30am now so enough of this for now....

As a sidenote I have reported this site to many software companies and will speak with some other 'authorites' tommorrow about this site and having it taken offline ASAP.
Cheers, Stephen
---------
Always lurking, and you can always email me or find me on Twitter
I no longer I have a Facebook account, I deleted it 31st May 2010, I have enough issues with Google and privacy and Facebook just gets worse by the day.
User avatar
Stephen
Site Admin
 
Posts: 2727
Joined: Wed Aug 03, 2005 4:56 pm
Location: Melbourne

Postby newman » Wed Jun 14, 2006 2:21 am

Stephen, I sent an email to Charles on this topic. It went a bit like this:

As I see it, the weakness in the site is the way in which logins are handled. I have very little knowledge of how web coding works. But, I see the dozens of posts of people putting up irrelevant and / or blatant advertising. My sister and I are moderators of a group over in Yahoo! I don't know how it's done, but every time someone registers, an email request is sent to either of us asking us to approve the new login. We can say yay or nay. The person's login, whilst waiting for approval, denies to them the right to post until we OK it.

I don't know how it's done, the coding is done inside Yahoo! All I know is that it works. We have had zero content spam. So, why can't something like this be set up at BE? The weakness is that one can register, confirm via email, and spam away. You and the mods are always chasing it. I saw Stephen delete one tonight on signing an on-line petition to protest treatment of domestic animals in China. Why not be proactive?
newman
Friend of BleedingEdge
 
Posts: 1262
Joined: Mon Aug 22, 2005 1:43 am

Postby Stephen » Wed Jun 14, 2006 2:46 am

The volume has most definatly been increasing over the past month. it must be our 'Google Pagerank' being so good because of the content we post here on the forum and all the spammers want a piece of it. :D

But with this guilt trip on 'puppies' and what I found at the end-point I did not expect to see what I saw to say the least and we need to find a way to curb this.... As speaking for myself you may have noticed I am far from impressed compared to last time we discussed this subject Newman. :wink:

100 million pages views this month to a site exploiting Windows.... That is HUGE
Cheers, Stephen
---------
Always lurking, and you can always email me or find me on Twitter
I no longer I have a Facebook account, I deleted it 31st May 2010, I have enough issues with Google and privacy and Facebook just gets worse by the day.
User avatar
Stephen
Site Admin
 
Posts: 2727
Joined: Wed Aug 03, 2005 4:56 pm
Location: Melbourne

Postby Paul » Wed Jun 14, 2006 8:08 am

I have been "fixing" the poster's links, mail, ICQ and key words for a long time.

cheers, Paul
Paul
Site Admin
 
Posts: 2081
Joined: Wed Aug 04, 2004 2:45 pm

Postby extulit » Wed Jun 14, 2006 12:10 pm

Just as a matter of passing interest, was there any reason for the so-called animal rights post remaining on the Forum for so long? Since the Forum has had a number of monitors these nuisance posts have usually been deleted very quickly.
extulit
Friend of BleedingEdge
 
Posts: 619
Joined: Sat May 28, 2005 12:56 pm

Postby wilbert » Wed Jun 14, 2006 12:51 pm

I am currently working with Charles on a new platform for this site. As it’s in the very early stages, I didn’t wish to out myself until BE 2.0 was somewhat closer to BE 1.5. It’s currently sitting at about 1.0.2

This is not an invite for this thread to be hijacked by a wish list, lets keep on topic with Stephen’s SPAM/Security concerns. If you’d like to start a wish list then start another thread.

In deciding on which platform to recommend to cw, SPAM and exploit links have been an issue I am keeping in mind. CAPTCHA images and email activation for both the forum and Blog are on the list, no system is perfect but something is better than nothing.

Back to the topic…

It is disgusting that GADs are slowly been hijacked by people advertising V and security software that isn’t.

If the human on the street is going to have any impact on the advertising arm of Google, then he/she needs to argue their point along commercial lines, ‘I won’t respond to your clients brief text based messages unless you fix up this, this and this’.*

The human on the street is the commodity, if the commodity is annoyed then the company (GADs) will lose clients (advertisers). Like it or not, we are the commodity.

I don’t object to people placing links in their forum signature – provided they’re real people linking to real websites – it always help one get to know their fellow travelers.

---

* I don’t usually speak like this, I’m trying to avoid GADs spiders from confusing the message for something outside their terms and conditions.
wilbert
Site Admin
 
Posts: 106
Joined: Sun Mar 13, 2005 6:18 pm

Postby cookalb » Wed Jun 14, 2006 3:35 pm

This post was an interesting read. I'm over 70 and always wary about sites I visit. I must confess that I always considered BE a safe site to visit along with the links posted. I'll exercise more caution from now on on using the links although I have all IE patches installed. Rest assured I wont be posting links of any sort.
cookalb
Forum Regular
 
Posts: 19
Joined: Fri Dec 17, 2004 7:53 am

Postby cw » Wed Jun 14, 2006 4:17 pm

It's best not to view any Web site as completely safe. Bleeding Edge is pretty safe, but in the forum, where people can post external links, it's wise to exercise caution. You can judge the reliability of a poster simply by checking their record.
cw
Site Admin
 
Posts: 297
Joined: Fri May 21, 2004 4:46 pm

Postby Stephen » Wed Jun 14, 2006 4:53 pm

Cookalb,

When this first surfaced here on the forum, I checked it out and had a bit of a look around and didn't think there was anything wrong with the site or link provided, just 'Chinese animal rights' are not something that relates to 'Bleeding Edge Technologies' we deal with here very often.

I like yourself try to practice safe internet practices and now and then even the most knowledgable of users will get caught out by such evilness.
Cheers, Stephen
---------
Always lurking, and you can always email me or find me on Twitter
I no longer I have a Facebook account, I deleted it 31st May 2010, I have enough issues with Google and privacy and Facebook just gets worse by the day.
User avatar
Stephen
Site Admin
 
Posts: 2727
Joined: Wed Aug 03, 2005 4:56 pm
Location: Melbourne

Postby Paul » Thu Jun 15, 2006 10:42 am

extulit, the links were removed reasonably quickly, the thread was left as an example to others to be careful.

cheers, Paul
Paul
Site Admin
 
Posts: 2081
Joined: Wed Aug 04, 2004 2:45 pm

Postby extulit » Thu Jun 15, 2006 11:29 am

extulit, the links were removed reasonably quickly, the thread was left as an example to others to be careful.
cheers, Paul


Thanx Paul.
extulit
Friend of BleedingEdge
 
Posts: 619
Joined: Sat May 28, 2005 12:56 pm

Postby cookalb » Thu Jun 15, 2006 3:26 pm

Thanks for words of wisdom Stephen
cookalb
Forum Regular
 
Posts: 19
Joined: Fri Dec 17, 2004 7:53 am

Postby Paul » Fri Jun 16, 2006 4:00 pm

Detecting Click Fraud is now free.
Detection Tools Story

cheers, Paul
Paul
Site Admin
 
Posts: 2081
Joined: Wed Aug 04, 2004 2:45 pm

Postby Stephen » Tue Jun 27, 2006 10:29 pm

I got bumped this today and there are more sites to be added to the list of this same scam using different messages and different styles though all using the same vulnerability attack.

Many suspect posts on the forum here need to be looked at very closely and if you are unsure simply do not click the link. Check out the users profile and the data contained in the profile if you do not know who the user is.


<blockquote>Hi Stephen,

Firstly, my apology for the late reply. Thank you very much for this report - we've added these to our monitoring system. We also saw another incident with a very similar "Prevent animal cruelty" hook last week which used multiple redirections.

www,stop-the-slaughter.net ->
yappeee,web,aplus,net ->
www,biggameslive,info/cgi-bin/ie0606.cgi

Not sure if you've come across it before, but the code at www,biggameslive,info is known as the Web Attacker Control Panel, and as you note, is a multi-exploit engine that analyses your operating system, browser version and service pack level before delivering an exploit you're most likely to be vulnerable to.

The good news is that biggameslive.info appears to have been disabled now. We released some AusCERT alerts along these lines about a very similar scam using the Web Attacker Control Panel with a "National Bank bankrupt?!" hook:

http://www.auscert.org.au/6398 (initial scam)
http://www.auscert.org.au/6411 (forum spamming)
http://www.auscert.org.au/6418 (new URLs)

Hope this is of interest. Thanks for sending this along - keep them coming!

Best regards,

AusCERT
The University of Queensland
http://www.auscert.org.au</blockquote>
Cheers, Stephen
---------
Always lurking, and you can always email me or find me on Twitter
I no longer I have a Facebook account, I deleted it 31st May 2010, I have enough issues with Google and privacy and Facebook just gets worse by the day.
User avatar
Stephen
Site Admin
 
Posts: 2727
Joined: Wed Aug 03, 2005 4:56 pm
Location: Melbourne


Return to Software Security Alerts

Who is online

Users browsing this forum: No registered users and 0 guests