Author Topic: Spambot attack - Update: Registration Re-Enabled  (Read 4848 times)

TonyV

  • Titan Staff
  • Elite Boss
  • ****
  • Posts: 2,175
    • Paragon Wiki
Spambot attack - Update: Registration Re-Enabled
« on: February 23, 2016, 09:20:48 PM »
Hey all, so as you might have noticed, over the past couple of days, we've been hit by a spambot that created hundreds of accounts, posted hundreds of spam forum messages, and created over 5000 spam wiki pages.  Thanks to hard work and diligent efforts of Blondeshell, Eabrace and Codewalker, we've nuked pretty much all of the messages, to our knowledge.  We're kind of fortunate in that since we use a custom registration process, we don't get hit often by spammers, and when we do, it's mostly one-off kinds of attacks since someone has to manually create an account through a non-standard interface in order to interact with our web sites.  That's protected us pretty well over the years, but this appears to be a case of someone actually writing a custom script to hit against our registration page, and then pointing a botnet at it to create the bogus content.

As a side note, they were undoubtedly mistakenly thinking that either this was a dead community or that we don't actively monitor what's going on with our sites, hoping that search engine crawlers would pick up the spam and process it to boost scam results.  Of course, most popular search engines these days don't work that way, but you know how it is; if it manages to boost one search result one spot on one obscure search engine that no one uses, they're willing to deface entire sites and tear down entire communities to do it.  Again, thanks to the diligence and hard work of people like Blondeshell, Eabrace, and Codewalker, they didn't get away with it.

However...

To keep them at bay, we have temporarily disabled new registrations.  We're going to work on implementing a new registration system, probably using a "CAPTCHA" system and tokens to prevent multiple submissions from a script.  From an end-user perspective, you probably won't notice much difference, except possibly having to choose pictures of cats or flowers or something when you register a new account.  But I did want to post a message to let everyone know what was going on in case you might have been wondering what we were doing about the situation.

If you notice any spam posts, please let us know and we'll take the necessary steps to delete it and lock the user accounts responsible.  If you're a legitimate user whose account was inadvertently locked in the past day or so, reach out to us at admins@cohtitan.com and we'll unlock it.  And rest assured, we'll continue taking whatever steps we have to in order to shut these bastards down.
« Last Edit: March 06, 2016, 02:50:59 AM by Sekoia »

Codewalker

  • Hero of the City
  • Titan Network Admin
  • Elite Boss
  • *****
  • Posts: 2,740
  • Moar Dots!
Re: Spambot attack
« Reply #1 on: February 23, 2016, 09:34:10 PM »
If you're a legitimate user whose account was inadvertently locked in the past day or so, reach out to us at admins@cohtitan.com and we'll unlock it.

I just want to add, if you did register an account between Feb. 21 and Feb. 23 and find yourself unable to log in, first try the password reset feature here. If you used a real email address to register (as you should have *cough*), you should be able to get your account working again that way.

Sekoia

  • Titan Network Admin
  • Elite Boss
  • *****
  • Posts: 1,848
Re: Spambot attack
« Reply #2 on: March 06, 2016, 02:35:46 AM »
Registration has been enabled again. A huge thank you to everybody for your patience, I know it took us (me) a rather long time to get this fixed and some of you have been waiting a while to register your account.
« Last Edit: March 06, 2016, 02:51:21 AM by Sekoia »