Fast method of deleting spam accounts

General Discussion
  • So I decided to start deleting spam accounts. With more than 150, doing so from the Latest Users tab of the Users page was kinda slow. So I decided to use the Search tab and type in some common keywords that spammers like to register with. From there, it proved to be a lot faster to delete the accounts that came up in the search results.

    What are the common keywords? Check out the screenshots below.

    NodeBBuser1.png

    Aside from generic, cialis is very common too. online or online pharmacy is also pretty common.
    NodeBBuser2.png

    Something about Canadians and enhancement drugs. 😉
    NodeBBuser.png

    levitra and buy tend to be common too, at least on my site.

  • @planner said:

    So I decided to start deleting spam accounts. With more than 150, doing so from the Latest Users tab of the Users page was kinda slow. So I decided to use the Search tab and type in some common keywords that spammers like to registers with. From there, it proved to be a lot faster to delete the accounts that came up in the search results.

    Jeeze, already? Need to get the ball rolling on the honeypot project then. :squirrel:

  • I find it hilarious that "Canadian" is a common keyword for spammers.

  • @trevor I've been doing this every 12 hours on my forum, but they register faster than I can delete. 😛

  • @anooxy

    Since I started yesterday, I've deleted more than 200 spam accounts.

    Less than 20% of the verification emails the system is sending are being delivered. That says a lot.

    This screenshot is just from today; and I still have a few hours to go.
    NodeBBuser3.png

  • Thanks @planner -- would like to accelerate overhauling of the user registration system, so you won't have to deal with this any longer. NodeBB originally went with the "anybody can register and post without verifying" model because it's a very low barrier to entry (second to having no registration at all, 4chan style).

    We can probably move away from that model now I think

  • I'm using Mandrill as a 3rd-party email provider and another means that I'm using to purge the system of spam accounts is to look at confirmation emails that were not delivered. Obviously, if an email is not delivered, it's very likely that it's a spam registration, even if the username does not contain any of the keywords listed in the OP.

  • @julian

    What would help plenty is to have a filter in place that will look for admin-configurable keywords/phrases in user registration names. Any that match an entry in the list of keywords/phrases will be refused registration. If such a system is in place on my site now, bot registration will be down by more than 90%.

    My list of keywords/phrases?

    • levitra

    • viagra

    • cialis

    • canadian

    • generic

    • online shopping

    • buy levitra/viagra/cialis

  • @Schamper 哈哈

  • For some reason spam registrations have dropped drastically. I noticed it 3 days before I upgraded to 0.4.1. Now all those cialis, viagra, and levitra usernames no longer populate my list of users.


Suggested Topics


  • 0 Votes
    4 Posts
    7k Views

    When re-run ./nodebb setup, it did ask for the admin user/password (before it was an existing db present) so it's working now, thank you! In case someone would miss that or forget the admin pwd, what's the solution (via redis)? I saw a post somewhere but can't find it any more.

  • 0 Votes
    3 Posts
    1k Views

    @PitaJ said in how to connect to fb account?:

    https://github.com/julianlam/nodebb-plugin-sso-facebook

    Sorry, I am talking about integrating to my fb page. So that all post shared from my forum goes to my page.

  • 0 Votes
    1 Posts
    830 Views

    I just installed it but i dont see captcha for version 6.0?

  • 0 Votes
    1 Posts
    754 Views

    I have nodebb setup with mongodb. Whenever I login as admin and go to the plugins page. I see this message in the log. I am not able to install any plugins. Clicking on "Install" doesn't do anything. Please help.

  • The spam is real.

    General Discussion
    56
    3 Votes
    56 Posts
    23k Views

    A couple of points for you guys to consider. First time poster here, But I manage some large forums that rank for lots of high value keywords.

    Our line of defence on vBulletin is as follows:

    Registration - Passed to StopForumSpam (this allows us to gauge the threat of the email address used and the IP address used). New users are not allowed to post links - configurable post count. Posts are passed to Akismet to gauge their spam levels.

    Even with this, we still get hit every now and then with manual spam from SEO agencies in various parts of the world - some parts of the world are worse than others. For those we use broad CIDR bans at the firewall levels.