On Thu, 8 Feb 2018 10:47:37 +0100 Marcel Hollerbach <m...@bu5hm4n.de> said:

> Hi,
> 
> On 02/08/2018 10:35 AM, Carsten Haitzler (The Rasterman) wrote:
> > On Thu, 08 Feb 2018 02:41:18 +0000 Mike Blumenkrantz
> > <michael.blumenkra...@gmail.com> said:
> > 
> >> This is the second mail I'm sending about this topic. The volume and
> >> frequency of the spam tickets is increasing. Something needs to be done,
> >> either by moving to a different project hosting service which
> >> prevents/filters spam or by permanently ip banning anyone creating tickets
> >> at a rapid pace.
> > 
> > moving project hosting is a crazy option. we loose all our tickets, patches,
> > wiki etc. if we don't then invest 100's of hours of moving things around and
> > restarting on something else. then there is the fun of "alternative hosting"
> > eventually "going away or degrading". been there before. i think you're
> > over-reacting to 10 spam tickets from 1 user today.
> > 
> > i looked at your recent activities and it looks like it was all "jdnka" and
> > they seem to all originate from 183.166.174.13 according to phab's logs.
> > 
> > geoip says this one comes from huangshan city, china. banning a single ip, i
> > doubt will have much effect unless there is a pattern of every spam account
> > coming from this same ip or a restricted range of them. so far i know of
> > just 2 spam accounts:
> > 
> > bvhgfh5 (the previous one you mentioned - cant get logs for ip now - too
> > old) jdnjka (this one)
> > 
> > are there others? i only know of 2 instances of spam (i would consider
> > these 2 instances even if 10 of spam tickets were created per account). can
> > you point me to others? 2 does not make a pattern yet. i do notice they both
> > use the same email domain for email address for the user. unfortunately phab
> > only has the ability it whitelist email domains, not blacklist them. i've
> > added blacklisting to phab's auth email stuff right now on e.org, so we'll
> > nbe carrying this patch for a while... i hope it works. it's simple
> > enough...i blacklisted the domain used here anyway now.
> > 
> > you don't need to manually go close every ticket. just find one ticket and
> > the problem user and tell me. it's possible to wipe the mess easily enough
> > on the cmdline. i put together a small script that can qeury the sql db and
> > nuke the user AND tasks they authored:
> > 
> >    sudo ./phab-nuke-spam-user.sh jdnjka
> > 
> > for example. don't waste your time closing etc. every ticket for now i
> > haven't nuked the above yet in the interests of gathering more data... do
> > you have any more data to share?
> > 
> 
> Its like 1 user per week, that creates ~10 tickets, i usally report them 
> to beber, who is deleting the users. A few other usernames:

ok. i only have heard of these 2 above. the below is news to me.

> xcjdd5v
> lskd89

lskd89 seems to be deleted, but xcjdd5v also uses the same email address
domain... so the blacklist i put in should stop this.

> I cannot get more names since they are deleted, and the tickets are 
> deleted, but its since december like this. I usally post them on phab in 
> the spam group :)

well i'd have liked to know more of these so i can find patterns... it's
knowing the patterns that allows for finding some way to block them. removing
the user and their mess is an easy enough script like above. please let me know
when this happens and who it is etc. etc. so i can find a pattern. at least the
email domain is common. they may switch to a new email provider, but this
likely will eventually exhaust their supply of "easy to register" email
providers and make them give up. we have a blacklist now and it can expand as
long as i know who the culprits are.

i've nuked all the 3 above that still exist (easy to do). let me know about
more.

> Greetings,
>     bu5hm4n
> 
> > 
> > 
> >> ------------------------------------------------------------------------------
> >> Check out the vibrant tech community on one of the world's most
> >> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
> >> _______________________________________________
> >> enlightenment-devel mailing list
> >> enlightenment-devel@lists.sourceforge.net
> >> https://lists.sourceforge.net/lists/listinfo/enlightenment-devel
> >>
> > 
> > 
> 
> ------------------------------------------------------------------------------
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
> _______________________________________________
> enlightenment-devel mailing list
> enlightenment-devel@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/enlightenment-devel
> 


-- 
------------- Codito, ergo sum - "I code, therefore I am" --------------
Carsten Haitzler - ras...@rasterman.com


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel

Reply via email to