Planet Descent

Community => Mess Hall => Topic started by: -<WillyP>- on May 10, 2009, 07:11:40 AM

Title: Spammers attacking forums.
Post by: -<WillyP>- on May 10, 2009, 07:11:40 AM
We all know spam in the form of e-mail, and irrelevent posting. However, spam has recently reached a new level of intrusiveness. About a week ago, I went to my own website, Prepare For Descent! (http://prepare4descent.net) and discovered DescentiaPedia wasn't working. Everything else worked fine, including the Guides Forum. I took a look at the file referenced in the error message, and discovered some foreign code written in at the beginning of the file. So I deleted it, and tried again, this time it errored out on a different file. Sure enough, same code at the beginning of the file. I looked at more files, every php (the code the wiki and forum run on) file had the same script injected into it. So, after making backups of everything, I set about to wipe everything clean, and reload clean files.

The purpose of the script, I later discovered, would been to have uploaded advertising software to the server, and thereby feed spam at my expense. Fortunately the wiki script broke with the added code, or I might not have known. How could this happen? It was so easy I don't dare speak of it aloud...  ;) But let's just say, as a result, you cannot upload images or other files at the Guides Forum until you have a post count of ten or more.
Title: Re: Spammers attacking forums.
Post by: The Chief on May 11, 2009, 04:03:15 PM
There is also now a requirement here of 5 posts prior to uploading.