One Man's Fight Against Forum Spam
JWSmythe writes "Free Internet Press has an interview with 'Random Digilante,' an anonymous hacker who has been taking over forum spammers' email accounts, and notifying forum operators to delete those accounts. It looks like his reasoning is sound, and his methods are safe, where he won't hurt any real users."
No matter your reason, it's illegal to access other peoples email accounts without their permission. Even more so when you disable the accounts.
If you do what you want based on what you feel is right, we might just not have any laws at all. There is a reason why the laws are created by the society as whole and not a single person or a group with single interest.
Forum spammer sues vigilante, gets both arrested. Vigilante does more time.
Forum spam is best solved with good forum software. A good karma system is probably the best solution. I've never seen spam on slashdot (unless I dig through the low rated posts).
Overperforming busy bodies? How does he get them?
He is like an internet superhero!
Using the 'powers' to stop the bad guys!
I created an account and was banned almost immediately.
They have extremely vigilant forum monitors who will bring the banhammer down for the slightest offense.
My offense? I insinuated that gays might be able to serve in the military just as well as straights.
Yon don't take over someone else's email account, just it's automated.
It's also a stupid way to solve the problem.
The Kruger Dunning explains most post on
As long as it's him working manually and the spam bots working automatically he won't even make a dent in the flow of forum spam.
You are a great writer. I found this article very informative. Would you like to be buying genuine spam today?
best solved with a bullet through their head.
As someone who deals with forum spam on a daily basis, I'm rather surprised at how intelligent the spambots are becoming.
Of course there's always the blatant, obvious spam (99% of which are video encoding tools for iPad, iPhone, etc). But I've recognized two other types of very covert spambots.
First one will take fragments of sentences from previous posts in the topic and regurgitate them. At first glance it seems on topic, but closer inspection reveals the post doesn't make sense and is just portions of others' posts.
The second type uses a database of sentences harvested from other websites, and attempts to post a sentence that matches keywords in that topic. Usually I can spot those because they aren't exactly on topic to the thread. I've also seen these modify various throw-away words, like adjectives and articles, so the sentence isn't an exact copy of the original source.
Now the key thing with both of these kinds of spambots is that they do not include any links initially. A couple weeks after posting they come back and change their signature, which results in spam links appearing under all of their previous posts.
I've also noticed that the vast majority of spambots use yahoo.com email addresses, so yahoo's captcha must be weaker than gmail / hotmail.
Now on the topic of this story, I don't quite understand. The forums I moderate have a few spambot accounts created daily (using recaptcha and custom implemented captcha). So it's not like there's just a couple spambot accounts causing all the trouble. Over the course of a month it around a hundred different accounts. So I don't see how this hacker is helping anything going after accounts one at a time manually.
Better known as 318230.
My forum software gets spammed. My solution is to ask real users to email me to activate the account. I get 200 sign-ups a day and all are spammers so i just filter them from my inbox. What does this guy do? Sends me an email warning that the account is spam bringing his unsolicited spam message into my inbox. I think I've had about 5 messages from him and probably have had about 30,000 spam sign-ups.
Posting this anonymously because Random Digilante got my account deleted.
Dear Decision maker , We know you are interested in
receiving amazing intelligence . This is a one time
mailing there is no need to request removal if you
won't want any more . This mail is being sent in compliance
with Senate bill 1625 ; Title 4 ; Section 302 . THIS
IS NOT MULTI-LEVEL MARKETING ! Why work for somebody
else when you can become rich as few as 33 days . Have
you ever noticed people love convenience and more people
than ever are surfing the web ! Well, now is your chance
to capitalize on this ! WE will help YOU decrease perceived
waiting time by 190% and increase customer response
by 150% . You can begin at absolutely no cost to you
. But don't believe us . Ms Ames of Florida tried us
and says "My only problem now is where to park all
my cars" ! We are licensed to operate in all states
! We implore you - act now ! Sign up a friend and you
get half off . God Bless !
Here's a specific example of what I'm talking about. Here is a post made to my forums in July 2010:
You can choose ‘Micro-ATX’ size motherboard for your HP. That limits the possible range of motherboards deals you will find. My advise is to buy a case that fits full ‘ATX’ form factor motherboards and go from there, many choices. It is depending on money and what you want if your building a good rig for gaming multimedia etc and don't buy a case with power supply. Please choose a separate power supply.
Now here is a post from another website made in 2009:
Your HP case (the cheapest part of the pc!) takes a ‘Micro-ATX’ size motherboard.
That limits the possible range of motherboards\deals you will find. (look for a motherboard\processor package)
Now you are already buying ‘a whole new computer’ except the case, why stop there? (unless you want the small form factor)
My advise (thats why your here!) is to buy a case that fits full ‘ATX’ form factor motherboards and go from there, much more choice.
Depending on money and what you want if your building a good rig for gaming\multimedia etc DON’T buy a case with power supply, they are usually sh*t (cheap\unreliable). Choose a case, choose a separate power supply (after research!)
Better known as 318230.
Michael David Kristopeit is a spammer.
edrugtrader (442064)
madddddddddd (1710534)
Michael Kristopeit (1751814)
Michael D Kristopeit (1887500)
M. D. Kristopeit (1890086)
M. Kristopeit (1890764)
Kristopeit, Michael (1892492)
Kristopeit, M. D. (1892582)
Mike Kristopeit (1900306)
Mike D. Kristopeit (1900568)
Kristopeit, Mike D. (1900570)
MichaelDavKristopeit (1905312)
Mike Dav. Kristopeit (1905334)
MichaelDa.Kristopeit (1905336)
Mike Da. Kristopeit (1905338)
Kristopeit, Mike Da. (1905342)
Kristopeit, Mike (1905452)
Kristopeit, Mike Dav (1905462)
Kristopeit,MichaelDa (1905518)
It would be nice to live in a world where whistleblowers and positive vigilantes were rewarded for their actions. But, in the vast majority of cases, these people end up in more trouble than the scumbags they're exposing and fighting. This guy will probably end up with more legal trouble for fighting spam than the spammers themselves will ever face for their network-clogging, frequently illegal, openly harassing activities.
SJW: Someone who has run out of real oppression, and has to fake it.
Warrantless wiretaps are illegal in many jurisdictions too. This doesn't seem to be a problem.
Likewise, bugging someone's home, ESPECIALLY a child, with video cameras is illegal, but a school having done so still seems to be At Large.
You should go hunt them down, or something.
Correct, I don't. He does. And what experience and knowledge applicable to you bring so that your pronouncement about it being a stupid way to solve the problem can be taken with no supporting evidence?
Or was your entire post bullshit?
Unfortunately, your Mother's clever saying presumes that the second act is a wrong. Since this discussion is about if it is in fact wrong or not, your presumption is unfounded. Bear in mind that doing something illegal is not necessarily wrong. In fact, my good friend Henry David Thoreau wrote an excellent essay arguing that, in many cases, violating the law is in fact the only "Right" thing you can do.
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
HAHAHAHAHA
So you reply from a second account to show that you aren't the spammer?
Yup, you have us all convinced.
Make a filter that detects his notifications and deletes the account automatically.
He is trying to help and he is fighting.
What are you doing about it? You're not helping anyone except of course protecting your advertising on your site.
Slashdot needs Geekcode | Can anyone recommend any good SCIFI? My tastes: Foundation, Startide Rising, CITY, Ringworld,
flamebait? really?
Obvious troll is obvious.
Can anyone tell me why 99% of
Your comment is well-thought-out here, but I have to say your recommended approach is flawed when dealing with a vast quantity of comment spam. It certainly will work on high-traffic sites like slashdot. The problem is with lower-traffic sites with a lot of scattered content. In high-traffic forums, your approach will generally work.
Sites with articles and photo albums, will need to additionally disable comments on older content because it won't be seen by visitors, but the indexing bots will pick up the thousands of links. Another problem is with signature spam, and that can hit forums hard. A spam bot can post a bunch of innocuous forum posts for months, then after the threads have sunk out of sight, the spam bot changes the signature to include a bunch of spam links, and no notification is given to the admin or other users that new content (posts) have been added to the forums, but the spam links are all over the place in the signature of the spam bot's posts. Users can mark the specific posts as spam, but they will be scattered through thousands of old threads. The users will need to be able to mark the user as spam to notify the admin to delete all posts by the spam bot.
Seth
$5 / month hosted VPS on linux = awesome!
As I said, its not a completely trivial problem. (BTW, sorry for the first sentence in my post which was garbled. I meant to say something like: "You really believe that slashdot wouldn't have spam, if people were able to freely post spam on slashdot and have it reach more than a few eyeballs?")
First off, I think signatures that can be changed later are seriously problematic. (I hate sigs, personally) If people find that feature so important, it would have to be handled separately. (e.g. users with a reputation could mark a sig as being spam, and the sigs on all posts by that user would be immediately disabled)
Low traffic sites or old threads aren't that big a problem either. If anyone is viewing it, the spam will be found and killed immediately. Even users with no reputation could mark something as spam, but those would be reviewed by another member before action would be taken. If the system is global (like Disqus or the like), the whole process can be smoother because truly "new" posters are pretty rare....if they don't have history of posting benign posts (even on other sites), the posts can be flagged as "needing review" before large numbers of people view them.
I could go on and on, but the gist is, the system needs to spread the work of marking spam among many, make it very easy and quick, and make sure that spam messages are viewed by very few before they are killed. Slashdot's system is designed for a high traffic site, but there is nothing that says a system can't work on low traffic sites as well. Spam messages may stick around longer on very low traffic sites, but if no one sees them, that's not such a problem.
the difference between a "spammer" and a "real user" is a matter of opinion.
the opinion of the users here on slashdot, which I can deduce from the moderation of your posts and the posts made in response to your posts, is that you are the spammer.
by your own standards I will judge you.
that's because I AM YOU engaging yourself in discussion. by your own words I will condemn you. by your own standards I will judge you. you just condemned yourself.
the difference between a "spammer" and a "real user" is a matter of opinion. the opinion of the moderators is that you are a spammer. by your own words, you are a spammer. by your own words I will condemn you. by your own standards I will judge you. I AM YOU engaging yourself in discussion. if I am nothing, it is only because YOU are nothing.
This is probably obvious, since no one is talking about it, but how is he taking over the email addresses? Surely the bots aren't registrering on his honeypot forums with the same password as is used for the e-mail they use to register.
you post anonymously because you are DRIVEN BY FEAR.
you are NOTHING.
And that action should go through the boxes in the correct order without skipping any. Jumping right to the 'ammo' box isn't the right way to do things in a lawful society.
Soap, ballot, jury, ammo: Ballot and jury fail unless the parties have substantial assets in the same jurisdiction. So I don't see anything wrong with skipping to ammo against judgment-proof spammers.
You're batshit insane, you know that right?
No attempt to discredit you is necessary; there's no credit to begin with. You're simply a raving lunatic, repeating the same phrases with the same insane punctuation and capitalization style, assuming somehow that if you do it often enough someone is bound to be swayed.
Who am I?
I am YOU
So you are NOTHING
Scream that I'm right again. You're doing it RIGHT NOW.
you're a lying coward.
pathetic.
You screamed that I'm right as you were told.
Do it again.
You will always obey.
I wouldn't be surprised if you meet the diagnostic criteria for Schizophrenia, or at the very least general delusional disorder. My recommendation is to see a psychologist, or at the very least to engage in discussions with your family members. Seek help, don't be ashamed.
That's certainly true. You've responded this far to anonymous cowards trying to bait you, and have created a bajillion accounts to do so with.
You appear to be wasting an inexplicable amount of time on Slashdot, as evidenced by your posting habits, so this is so.
Your bloody-minded persistence and repeated name calling in this thread come to mind.
Seems to fit. You're not some sort of spam freedom-fighter, no matter how strongly you think so and how little sense that makes.
Oh boy, don't get me started on irritability and hostility.
YOU ARE ALL IDIOTS.
No one likes a spammer, much less people who spend a lot of time on Slashdot. This fits.
I can't make a judgment here as I have no experience with you outside of this thread. It seems likely, however.
Abnormal relative to the rest of society, yes. Again, I can't judge your character completely however.
Schizophrenia
Mmm is this just me, or is the blog article dated "Monday, February 8, 2010" ?
Jicehix
you suggest i see a psychologist, suggesting you are not a psychologist... then you proceed to suggest a diagnosis you are not qualitified to make, of multiple personalities when i SOLELY present myself as who i am: MICHAEL DAVID KRISTOPEIT.
and just like someone who is lying and does not want to be labeled as such, you post cowardly and anonymously.
you are NOTHING
ur mum's face have been around at least for a little while.
I like the intentions of this person, but his/her words are starting to sound like a vigilante.
These are some of the stupidest people I have ever heard of.
...these scum add to every forum they do this to.
Good intentions are great, but don't get consumed by your project. That will lead you down a very bad path.
Funnyhacks - Wierd, unusual, and fun hacks
But isn't his method going to stop working once the spammers start creating more complex and unique passwords for their email accounts?
He didn't suggest you had multiple personalities, you retard. That's not what schizophrenia is.
talk about wasting time. how about this, i diagnose you as an idiotic asshole. symptoms include being an idiotic asshole or having an idiotic asshole mother.
he didn't suggest anything... because HE doesn't exist. a COWARD made the claims against me THAT CAN NOT BE PROVEN TRUE. A PERSON has rejected those claims WITH PROVABLE FACTS.
i DO exist. i am michael david kristopeit.
you are NOTHING
That last line isn't quite correct. The people it affects are "real users" they're just assholes. Again, imaginary: no, jackass: yes.
Google's Super Secret Search Algorithm: SELECT @search_results FROM internet WHERE @search_results = 'good'
This is all well and good, but it sounds like he's gone to an awful lot of work to solve a problem that could have been more easily remedied just by installing reCAPTCHA. I run a large forum, and the use of reCAPTCHA (plus a few other minor tricks, like changing the name of the registration script) has eliminated 100% of automated spam. I now only have to deal with the fairly small trickle of manually-registered accounts, which is quite a bit more manageable.
People who say "sheeple" have about as much sophistication as an AOL user, and in fact are probably actually AOL users.
Talk about proving the man's point.
Oh, I'm sorry. Did you actually think you were refuting him?
any diagnosis or conclusions you offer are irrelevant.
you are NOTHING