OpenXcom Forum

OpenXcom => Open Feedback => Topic started by: Nikita_Sadkov on November 12, 2019, 08:03:46 pm

Title: Forum is Under Attack by Russian Dating Scam Bots
Post by: Nikita_Sadkov on November 12, 2019, 08:03:46 pm
Don't click the link! These scam site frequently have embedded viruses!

(https://i.imgur.com/ojI4IxS.png)
Title: Re: Forum is Under Attack by Russian Dating Scam Bots
Post by: SupSuper on November 13, 2019, 07:06:49 am
Thanks for letting us know. In the future, report spam directly to an admin or moderator so we can deal with it faster.
Title: Re: Forum is Under Attack by Russian Dating Scam Bots
Post by: Nikita_Sadkov on December 02, 2019, 05:17:25 pm
Thanks for letting us know. In the future, report spam directly to an admin or moderator so we can deal with it faster.
Ok. But it continues, this time with some tank spam, instead of adult sites. Maybe you can require users to have some forum posts, before allowing them to send PMs? It is doubtful any real person would start mass sending PMs immediately after registering.

(https://i.imgur.com/v1jVgza.png)
Title: Re: Forum is Under Attack by Russian Dating Scam Bots
Post by: The Martian on December 02, 2019, 06:20:16 pm
But it continues, this time with some tank spam, instead of adult sites.

Thank you for the warning Nikita_Sadkov, I will avoid clicking any strange links sent via PM.

I noticed that strange (https://openxcom.org/forum/index.php?action=dlattach;topic=7568.0;attach=45534) image icon when I was glancing at the "Who's Online" section of the forum earlier, thought it was a bit curious that it said "Yahoo Instant Messenger - Test, just a test" beside the green light so I snapped a screenshot.

(https://openxcom.org/forum/index.php?action=dlattach;topic=7568.0;attach=45535)

None of the other users that I've seen have there forum "Personal Text" message visible on that screen. I'm not sure if it means anything useful but I figured I'd mention it in case it helps pin down a solution.
Title: Re: Forum is Under Attack by Russian Dating Scam Bots
Post by: SupSuper on December 03, 2019, 04:05:22 am
Ok. But it continues, this time with some tank spam, instead of adult sites. Maybe you can require users to have some forum posts, before allowing them to send PMs? It is doubtful any real person would start mass sending PMs immediately after registering.
We can't snoop on everyone's PMs. :P You gotta tell us when it happens. I've disabled new member PMs just in case.
Title: Re: Forum is Under Attack by Russian Dating Scam Bots
Post by: Anon011 on December 04, 2019, 09:40:24 pm
Russian Dating Scam Bots
Please... any proofs that this spam is of "Russian" origin?
Title: Re: Forum is Under Attack by Russian Dating Scam Bots
Post by: Warboy1982 on December 05, 2019, 09:27:49 am
Please... any proofs that this spam is of "Russian" origin?
username: "Tusik Vitusikk"
hardly conclusive, but enough to warrant the assumption.
Title: Re: Forum is Under Attack by Russian Dating Scam Bots
Post by: Nikita_Sadkov on December 07, 2019, 04:30:51 pm
Please... any proofs that this spam is of "Russian" origin?
The fake dating site had Russian girls. It could have been created by anyone, but I personally knew people in Russia who created such sites to defraud foreigners. Nigerians also do that, but they usually identities of western girls and guys (stealing idenity is easy, since people tell everything about themselves on social networks). That and carding are some of the reasons PayPal doesn't work in Nigeria and had been unavailable in Russia for a long time. I've lived in a hostel for some time with a fugitive from Nigeria, hiding in Eastern Europe. He did carding stealing US citizens identities, cashing out money in Ukraine. Reported him to local Interpol - they don't care.

So yeah, be careful - avoid suspicious sites, because browsers have 0day vulnerabilities, which allow stealing your passwords and card numbers.
Title: Re: Forum is Under Attack by Russian Dating Scam Bots
Post by: Yankes on December 07, 2019, 05:55:22 pm
And use no-ads and no-script that reduce drastically surface that 0day can exploit.