Spam Attack on December 15th, 2010

• Dec 15, 2010 - 16:20

The MuseScore.org forum suffered from a spam attack less than 12 hours ago. 600 spam comments were posted by a spam bot operated from Rusland with the IP address 89.163.39.37. The result was a flood of forum subscription emails being sent to users containing the spam. Sorry for everyone for the disturbance that may have caused.

Something has to be done against this and so two measurements are being put in place:

  • Posts and comments from new users are now not send out anymore in subscription emails (a bug slipped in and eliminated a previous fix)
  • There is a posting limit for new users which should prevent automated flooding of the forum with spam

Hopefully these anti spam measurements will be enough to control it for the time being. Thanks for your understanding and patience.


Comments

In reply to by Thomas

Hi guys,

A fix is in place to prevent flooding. I can't get into a lot of details, but I could reproduce the problem which preventing the anti flooding script to work. I'm pretty confident that this fix will hold it for a while.

Thx for your understanding and happy holidays.

I'm happy to say that not one single spam message was sent out via mail subscriptions in the past 2 weeks. So the anti spam measurements seem to be holding up. The number of spam posted in the forums has also dropped a lot. Great!

Thank you all for sticking with me.

In reply to by xavierjazz

..but occasionally (approx. twice a week) I receive from the forums a number of e-mail notifications for updates to my posts with no update inside.

I mean: in the e-mail there is my original post, all the paraphernalia of boilerplate links and notes present in all notifications and nothing else, no new post or answer or reply of any kind.

Anybody else noticed this?

Thanks for the effort in trying to keeping the forum clean! (Do these spammers have nothing more interesting to do than forcing other peoples to waist time on their crap?)

M.

In reply to by Miwarre

Miwarre, Are you referring to forum posts or bug reports?

With bug reports, when the status changes from fixed to closed it sends an email that does not explain what happened and when you visit the web page the comment the changed the issue from fixed to closed is often hidden. I believe the emails would be better if they showed status changes (or title changes, etc.) or were not sent at all.

In reply to by David Bolton

David: posts or issues? I think both; I cannot be 100% sure but I am rather confident.

Notification about issue status: I do not have an example to quote at hand, but I am pretty sure the notification sent when an issue changes of status DOES contain a line with the status change: rather INconspicuous but it is there (and now I know to look for it).

So, I still suspect, like David, that those no-contents notifications could be spurious notifications sent after spam removal.

Thanks,

M.

Do you still have an unanswered question? Please log in first to post your question.