New SPAM attack style

BossDog

KnifeDogs.com & USAknifemaker.com Owner
Staff member
We are getting 2 or 3 notes a week now on failed password attempts and the member here didn't attempt the sign on's.

What this means is there is new SPAM bot software harvesting user names on forums and then attempting to hack the account by guessing up to 5 passwords getting the account blocked for 15 minutes.

We are taking steps to block any specific IP address where any attacks are originating. Naturally, the attacks are coming from overseas SPAMmers looking to sell something. These are not malicious attacks. They want to post a message with a link hoping you buy something from them.

It is a public forum and anyone can read the user names so we expect this to continue until we whittle down the IPs. The problem with block IP's is often these are spoofed (by technically competent spammers) or they simply rotate to a new IP (trivial) as others become blocked.

If it is happening here, it is happening on every forum so it's not unique to us.

What happens if they guess your password? They will post a few SPAM messages, we will delete them. We have software in place that sniffs out questionable 'spammy' posts and moderates them. I or one of the helper moderators here manually delete the rest. We normally ban/block a spammer but if someone guesses a password, hacks your account and you get banned, we can reset that easy enough.

To help reduce the chances of your password being guessed:
(if you have worked for a company with a gestapo IT department, you already know the password drill.)

  • Use a combination of capital and lower case letters. The password function is case sensitive.
  • Use characters like $%^&*(, etc in your password.
  • Use a number or two or three.
  • Make is something you can remember so you don't have to write it down.
  • You do NOT have to routinely change your password as some companies recommend. That isn't going to help with this.

If you have a simple word password that could be guessed you should update it
by going to Settings (top right), then looking to your left menu for Edit Email & Password and toughen up the password. I suggest you do this on every forum you are registered on.
 
We are getting 2 or 3 notes a week now on failed password attempts and the member here didn't attempt the sign on's.

This happened to me this morning and the forum sent me this message;

Dear Snapper,

Someone has tried to log into your account on KnifeDogs.com Forums with an incorrect password at least 5 times. This person has been prevented from attempting to login to your account for the next 15 minutes.

The person trying to log into your account had the following IP address: 183.221.60.157

All the best,
KnifeDogs.com Forums
 
This happened to me this morning and the forum sent me this message;

Dear Snapper,

Someone has tried to log into your account on KnifeDogs.com Forums with an incorrect password at least 5 times. This person has been prevented from attempting to login to your account for the next 15 minutes.

The person trying to log into your account had the following IP address: 183.221.60.157

All the best,
KnifeDogs.com Forums

Hey Snapper. Thanks for the heads up.
Good to hear from you again. Are you going to Blade this year?
 
an update:
This type of spammer hacking is blooming up all over the place. There are several websites that track this kind of thing. Most of the IP's are originating in China and we have started blocking them as we find them out. It's trivial to change an origin IP so the blocking will be only marginally effective but we still feel better doing something.

Don't use your userid as your password.
Use a mix of words and numbers and maybe a character or two.
Don't use simple words as your password. That is what they are counting on so they can log in and post spam messages under your account.

you can change/toughen up your password by going to Settings(upper right) and then edit password(left menu).

carry on dogs.
t
 
Hey Snapper. Thanks for the heads up.
Good to hear from you again. Are you going to Blade this year?

Tracy,
No Blade Show this year for me. I'd love to be there but can't swing it again this year. I'll get back to the Blade one of these years.
 
I recieved a Private message from New Member Smiley entitled Hi!......It turned out to be an ad for......................easymoney.bg.tf
 
I don't post much here, just not enough time in the day for all the great knife forums.
As I am an administrator on another knife forum I thought you might like to know that I got a spam PM from someone named Mike Dailey
I didn't see a link on the PM to report it, so I thought I would let Tracey know by posting in this thread.

Good luck stopping the spammers, I know it is a never ending battle!

Dale
 
Yeah I sent Boss a report about ole smiley myself. Makes me wish I knew how to send a virus I would respond to SMILEY!:what!::biggrin:

You know it is such a shame most of us struggle just to keep our PC's up and running and there are those out there who have such a know how that they can create SPAM and hack into our systems and they waste their knowledge and talents creating, a big ole pile of stuff waiting to fall on someone!:yawn:
 
If you are having issues with your account getting compromised, you may want to try this FREE password manager - LastPass.com

I just ponied up the $$$ for the paid version, a whole $12/year, because I have been using LastPass for 6+ years and it's great for managing the many password accounts I have. With the paid version, you can also use it on your smartphone and/or tablet to manage your login processes. It's a great way to bookmark and easily access your protected websites & forums.

No need to remember the passwords, just use the LastPass browser plugin to access the accounts. LastPass will create STRONG passwords for your accounts based on the password requirements of the accounts.

This will drastically reduce the possibility of your account getting compromised, and also makes it easier to change a password regularly.

I have no affiliation with LastPass, I am just a real happy user who has been a Technical Consultant for 25+ years and I like to share what works well for me.

Hope that helps ya out, and Thanks BossDog for the great forum!
 
We use an enterprise version at work and it's a good one. I have also used Dashlane and prefer that one but I couldn't get it set up for how we use it at work like I wanted it.
 
Back
Top