How is someone sending PM's to my members?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Dexterity
    New Member
    • Jun 2003
    • 4

    #31
    PM spammer update

    The owner of zenofeller.com and I have been in email contact. He thought I was the spammer while I thought he was. But the truth is that neither of us have been sending out these PM spams, which by my estimate have hit at least 200 VB forums so far. Someone has been spamming links to his ebook, using my email and my wife's name and email to sign up for accounts. We don't know who's doing it yet.

    But apparently the problem is caused because the default VB installation allows PMing for unverified accounts. This means someone can register using someone else's email, never complete the email verification process, and PM spam the members. Naturally people will assume the spammer is either the person who owns the URL being spammed or the owner of the email account used to register. In this case neither of those were true.

    PM spamming for unverified accounts can be prevented by setting PMs to zero for COPPA, Unverified, and Awaiting Verification usergroups. But still a lot of forums are vulnerable to this.

    I strongly suggest the VB team disable PMing for unverified accounts by default. Otherwise it can create a real headache for people.

    If you know of anyone else being PM spammed, please refer them to this post.
    Steve Pavlina
    Personal Development for Smart People
    http://www.stevepavlina.com

    Comment

    • Ophelia
      Senior Member
      • Feb 2006
      • 218
      • 3.5.x

      #32
      Does anyone have a fix for this (vbulletin tech people?!). We have people who are not internet savy on our site and now they are paranoid that we are not secure. We can't get much more secure than to set permissions to 0. What can we do?

      Comment

      • Steve Machol
        Former Customer Support Manager
        • Jul 2000
        • 154488

        #33
        Not sure I follow this but PMs are turned off by default for unverified accounts. What is your exact question or problem?
        Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
        Change CKEditor Colors to Match Style (for 4.1.4 and above)

        Steve Machol Photography


        Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


        Comment

        • Jack Reacher
          New Member
          • Aug 2007
          • 6
          • 3.6.x

          #34
          Originally posted by monet_06
          We got hit with this today. It was the Buddhist message, but instead of einstein, it was a Jeanette.
          Same here today, Jeannette sent for about 30mins buddhist PM's for my users before I caught him. IP was 207.195.246.40.

          Only reason I caught the spammer was due to some PM notification emails bouncing back to me.

          Comment

          • essexell
            New Member
            • Jun 2006
            • 5
            • 3.5.x

            #35
            We've had the same problem. I've tested the Private Messaging, and it is definitely possible to send PM's from an unverified account. I assume that this is in vBulletin default settings - as we wouldnt' have changed the unverified accounts PM limit to 50.

            Comment

            • paperthreads
              New Member
              • Feb 2007
              • 24

              #36
              Jeannette hit our site too, sent over 1000 PM's in just under a few minutes. I went in and deleted them all from the database.

              here's the thing....I updated to the patch level 2 on SUNDAY the 13th. This Jeannette id registered on Monday the 14th, and then yesterday, hit almost 1/4 of our members. I found out by a member sending me a copy of the pm, immediately banned the id, and then went into the database and found the over 1000 pm's that they had sent and removed them. (I tried to do a quick remove of PM, but it said they had none........so I went in manually to the database to remove.)

              Oh, and default setting is that no one can send a message to more then 5 people at a time, and that coppa and users waiting email confirmation can't post at all, and that registered users must meet the next group level of 5 posts before they can send pm, but not one of this mattered. they were able to get in send to high numbers of people in a matter of a minute. So obviously, even if they did a manual registration and it's a human that got through all the other process (and believe me there are a lot, because I get complaints all the time how hard it is to get registered!)....once they got in, they were able to do something to allow them to do those PM's, and QUICK.
              Last edited by paperthreads; Thu 17 Jan '08, 8:44am.

              Comment

              • justlost
                New Member
                • Dec 2005
                • 6
                • 3.5.x

                #37
                I got hit by "Jeanette" too. They hit my board at 1:00 a.m. so they were able to PM all 770 members of my forum. I just now got that PM from another vbulletin board that I'm a member of.

                It looks like there is an exploit in the software somewhere.

                I'm running 3.6.7 PL1.

                Comment

                • karabalsagun
                  New Member
                  • Dec 2006
                  • 12
                  • 3.6.x

                  #38
                  I got hit by "Jeannette" too. Sent thousands of PMs using IP 128.241.105.37


                  I'm running 3.6.8 PL2

                  Comment

                  • peterska2
                    Senior Member
                    • Oct 2003
                    • 8869
                    • 3.7.x

                    #39
                    Check your permissions on the Users Awaiting Email Confirmation usergroup and set the max stored PMs to 0 to prevent them from sending PMs.

                    Comment

                    • justlost
                      New Member
                      • Dec 2005
                      • 6
                      • 3.5.x

                      #40
                      Originally posted by Kerry-Anne
                      Check your permissions on the Users Awaiting Email Confirmation usergroup and set the max stored PMs to 0 to prevent them from sending PMs.
                      Thank you! Mine was set to 50 but is now zero.

                      Comment

                      • flynnibus
                        Senior Member
                        • Aug 2005
                        • 177

                        #41
                        Originally posted by Wayne Luke
                        Just because it is spam doesn't mean it is being done by a bot or automatically. There is no way to prevent humans from registering at your site except to take it down. That probably isn't an acceptable solution.
                        No - but its clear when you have such a repeatable pattern and high speed that the stuff is being done by software. If the registration is done automatically or not is only one piece of this.

                        Originally posted by Steve Machol
                        Not sure I follow this but PMs are turned off by default for unverified accounts. What is your exact question or problem?
                        No they are not - at least - its not effective.

                        The defaults are

                        Maximum Stored Messages:If you set this to 0 users from this usergroup will not be able to use private messaging.

                        That is set to 50

                        Maximum Recipients to Send PMs at a timeo not set this too high for performance reasons (set to 0 to disable)

                        This setting is set to 0

                        Yet - a user is still able to send PMs. Its my understanding from the description that the second setting should disable sending PMs - but it does not - at least in 3.6.8

                        Originally posted by Kerry-Anne
                        Check your permissions on the Users Awaiting Email Confirmation usergroup and set the max stored PMs to 0 to prevent them from sending PMs.
                        Yes, but that also would prevent users from receiving them would it not? Shouldn't the second setting prevent sending?

                        ... and yes, we saw the Jenette varient of this spammer today.

                        Comment

                        • Freezerator
                          Senior Member
                          • May 2002
                          • 574
                          • 3.6.x

                          #42
                          I got him to, i already had max stored pm's to 0 on the users awaiting e-mail confirmation?
                          Dutch vBullletin users social group!

                          Comment

                          • TruckZMod
                            New Member
                            • May 2002
                            • 14

                            #43
                            Jeannette got me too...

                            It would be interesting to see what's been exploited. I believe this one was tapping into the Calendar, peeking into events well into 2011 on the site.

                            Comment

                            • Silver_2000
                              Senior Member
                              • Mar 2002
                              • 555
                              • 4.2.X

                              #44
                              I also got hit

                              I still think its a script - seems that large forums are reporting that 400 messages are being sent - same in our case 4x0 messages


                              If a member was manually sending PMs they would be awfully busy and consistent to send spam to 400 members of all these various forums...
                              if the permissions are working the max at a time they could send is 5

                              Maybe Im wrong but I doubt that its likley that these tens of thousands of personalized Pms are being manually typed by someone..
                              Last edited by Silver_2000; Mon 11 Feb '08, 3:01pm.
                              http://www.TALONClub.com/forum
                              http://www.prowltalk.com
                              http://www.nloc.net
                              http://www.nhtoc.com

                              Comment

                              • oz_moses
                                Member
                                • Oct 2004
                                • 44
                                • 4.0.0

                                #45
                                got me too.

                                Is there a way to allow a maximum of 5 messages to be sent for any user with under 5 posts? This way new users can still contact me if they have difficulty with the site, however spammers will be stopped at 5..
                                sigpic

                                Comment

                                widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                                Working...