Showing posts with label Fighting spam. Show all posts
Showing posts with label Fighting spam. Show all posts

Saturday, 24 October 2009

Link bombing spam ring discovered

For not to many weeks ago I wrote about how spammers are killing me and my project fuzzzy.com.
After posting the blog post I deliberately shut down the site to see what happened, hoping the spammers would leave for good. After two weeks down time I put the site online again but without the SMTP server connection so that new users would not get the e-mail confirmation during the signing up process.

Guess what. Suspicious users still registered with the same rate even if they could not log in. This continued for 3 weeks. After three weeks, I turned the SMTP server back on and in an hour or two the spam started trickling in again.

So here's the things I have tried and did not work:
  • E-mail confirmation.
  • Captcha.
  • Wrote rigorously that the site is for web enthusiasts only.
  • Wrote that spam would be deleted without notice.
  • Added a human only answerable question to the sign up form. ('Are you human?')
  • Change the URL's of the pages most used by spammers to post spam.
Another thing I tried was to add a question where the answer is commonly known to the target group. The question I added was; 'Who invented the web?'. This actually had some effect. Spam went down by about 50% after adding this question to the sign up page. It seems that most spammers don't know the answer to this question and moves on to other sites to do their spamming.

One thing I have learned is to be very careful not to deploy pages that let users enter html so users can create url's in free text. Once this gets out amongst the spam ring you will get a hard time fighting them off even if you remove the ability to add hyperlinks.

Looking at the IP addresses of about 100 the spammers these are the typical ISP's:
  • Mango Teleservices, Bangladesh
  • Philippine Long Distance Telephone, Manila, Philippines
  • Digitel Mobile Philippines Inc., Philippines
  • National Internet Backbone, India
  • FibreNet Communications Ltd.Dhaka Bangladesh
  • Smart Broadband Incorporated, Sorsogon Philippines
  • TATA Communications formerly VSNL is Leading ISP, Ahmadabad, India
  • Smart Broadband Incorporated, Quezon City, Philippines
  • Bharti Broadband, Delhi, India
  • VietNam Post and Telecom Corporation, Vinh, Vietnam
  • Telefonica del Peru, Peru
  • Grameenphone is the largest telecommunication Orga, Dhaka, Bangladesh
  • NIB (National Internet Backbone), Sivakasi, India
  • FASTER CZ spol. s r.o., Brno, Czech Republic
  • Makedonski Telekom, Skopje, Macedonia
  • SC AVA TELECOM INTERNATIONAL SRL, Bucharest, Romania
  • Vietel Corporation, Hue, Vietnam
  • Telekom Malaysia Berhad, Kuala Lumpur, Malaysia
  • PTCL Triple Play Project, Islamabad, Pakistan
  • RELIANCE COMMUNICATIONS, Madras, India
  • SIA Lattelekom, Priekule, Latvia
  • Sify Limited, Calcutta, India
  • SATNET, Quito, Ecuador
  • SC AVA TELECOM INTERNATIONAL SRL, Bucharest, Romania
The list shows that most of the spammers come from poor countries or countries with high unemployment rates.

Looking further at the activities carried out and the spam they add my hunch is that there is a link bombing spam ring. Since most automated robots don't get past captcha's and other blockers, organized spam cartels will outsource spamming to poor people in developing countries.

One might think that these spammers are the scum of the earth.. wait scum of the web. But if we look at things from a higher perspective we will probably find that the digital-divide, the socio-technical and global networked economics of the world and the immature stage in the evolution of the web is what really has caused this cancerous spam situation.

So fighting the spammers is like slapping around poor thieves caught in their act.
Bashing up the thief will only make him sink deeper into the black hole his already in. Getting rid of one spammer only leaves room for another spammer. Instead we should focus on prevention and helping people out of their miserable situation. How do we do that? Fair trade is a good solution. Another good solution is to work on innovative R&D projects that will evolve the web.





Sunday, 20 September 2009

Spammers are killing me

I have over the last years developed an experimental socio-semantic bookmarking service as a part hobby and part academic research project. The site can be said to be under early Beta testing. I have a lot of plans for the site but as it is being developed on my spare time the progress is not as fast as I could have hoped for. Also, as I write the project is kind of on the shelf while I explore another exiting hobby project in the area of social location based services.

Here come the spammers
In the middle of July 2009 I suddenly saw a rise in the number of new members signing up on my bookmarking service fuzzzy.com. Surely it's some robots spamming fuzzzy I thought. But after looking into the actions performed I soon figured out the spam where human generated. Based on the type of actions and data/metadata entered I could tell these where not generated solely by automated agents. It very much looked like coordinated spamming from a spam ring. There were no pattern in the IP addresses used. Captchas and human-readable-only questions on the sign up page did not stop them. Looking in the log-files at the seconds between actions, links added in the form of bookmarks and free html text links where added and modified in a typical human workflow. Some spammers also added tags and comments.

Why are they doing this
Obviously Google pagerank is the root of all evil link bombing spam. Often called link bombing, google bombing, spamdexing, referer spam, spammers add links to sites in order to promote a site and make it rank higher on Google and other search engines using page rank and similar ranking algorithms.

Spammers killing me slowly
For the last weeks I have got about 30 spam links every day and the process of removing the spam is killing me. Instead of using my scarce time on development and learning new stuff I am tied down for 10 minutes each day just verifying links and deleting spam. 10 minutes a day is not that much but its the feeling of fighting against a mob of EVIL EVIL EVIL real world spammers that really makes me just feel sad and frustrated. On just about every page on fuzzzy there is now text saying the site is a community site for people interested in web science and web development. Still, people keep bombing the site with spam links.

So what should I do
As the site is still in sort of early closed beta I don't have a bunch of users that can report, moderate and delete spam.
The few options I see are:
  • Close the site until I decide to focus 100% on the site and a real community is built around the site.
  • Keep deleting spam every day.
  • Develop a spam blacklisting service my self.
  • Report the spam to some third party black list.
  • Develop functionality that favours user with high reputation. Links posted by new users are just not shown until the link or the user is voted up or something like that.
If you have any ideas for how to fight the spam please let me know.
The last option or similar approaches seems to be the way to go but it does seem futile to fight the spam mob. If I can free my site of the spammers they will only move on as parasites to new victims. This only shows how primitive the current state of the web really is.