Spam-Me-Not

29
Spam-Me-Not Greg Salt Purple Dogfish

description

We all love to be wanted but some advances can be a little uncomfortable. Spam, especially member profile spam, is a pervasive problem for any membership site. We'll take a short journey through the dark underbelly of the Internet and take a look at spammers; who they are, why they do it, the tools they use and some common operating methods. We'll finish with a look at some mitigation strategies for ExpressionEngine and how we can help each other as a community.

Transcript of Spam-Me-Not

Page 1: Spam-Me-Not

Spam-Me-NotGreg Salt

Purple Dogfish

Page 2: Spam-Me-Not

Profile Spam

The posting of links or plain text within a site member profile such that it is not displayed or visible when browsing or using the site normally

Page 3: Spam-Me-Not

Cross Platform

Page 4: Spam-Me-Not

Why?

• Some are traditional ‘SEO Experts’

• Many are spammers who want to scam other potential spammers

• Convince others that they’ve found a system that makes money

• Sell internet properties/ebooks etc

Page 5: Spam-Me-Not

Business Ideas!

Page 6: Spam-Me-Not

Spammer Lifeforms

Page 7: Spam-Me-Not

Primordial Soup• Unsophisticated

• Generally direct posts into forums and blog comments

• “Great post! www.buypills.com”

Page 8: Spam-Me-Not

Developing Tools• Link Generators

• Profile Creators/Bots

• Search Engine Scrapers

Page 9: Spam-Me-Not

Inventing the Wheel

Source: http://www.seo-back-links.com/link_wheel.htm

A number of independent web 2.0 sites, all with high Page Rank values, create a link to your site. And each of the "spokes" create a link to its neighbour - forming the wheel.

Page 11: Spam-Me-Not

Learning to Share• Preying on lesser

lifeforms

• Selling link packets, bots and sites

Page 12: Spam-Me-Not

Masters of Disguise• Register then wait a

few weeks before coming back to update profile

• Will probably never post in forums but will login from time to time

• Wrapping links around punctuation

Page 13: Spam-Me-Not

Masters of Disguise

Page 14: Spam-Me-Not

Who’s Responsible?

Page 15: Spam-Me-Not

Angela Edwards

Submit Comment

Automatic Profile Creators

uSMF – SMF Forums Profile Creator

uPun – PunBB Forums Profile Creator

uExpress – Expression Engine Forums Profile Creator

Vbulletin Profile Generator – Vbulletin Forums Profile Creator

Leave a Reply

Name (required)

Mail (will not be published) (required)

Website

angelae8654Automatic Profile Backlinks

angelae8654

Page 16: Spam-Me-Not

Paul Johnson

Page 17: Spam-Me-Not

ExpressionEngine Bots

Page 18: Spam-Me-Not
Page 19: Spam-Me-Not
Page 20: Spam-Me-Not
Page 21: Spam-Me-Not

backlinkengines.com

Page 22: Spam-Me-Not

Bot Weakness

• Not yet updated to deal with EE2 registration form (email verification)

• Can’t deal with anything non-standard

• Captchas do cause problems

• No built-in facility to use proxies

• Forced to use the same username/email/IP across all the sites

Page 23: Spam-Me-Not

What Can We Do?

Page 24: Spam-Me-Not

Site Setup

• Remove ability for guests to view profiles

• Don’t use default member registration form fields

• In forums remove active/newest members list

• Set up admin notifications for registrations and new posts

Page 25: Spam-Me-Not

Site Management

• Update Blacklist module regularly

• Use the EE member banning features - never delete

• Use community to flag/report spam

• Check your new members everyday

• Approve membership

• Use newbie member groups

Page 26: Spam-Me-Not

Community

• Report wheel links to other sites

• Report SEO spam to client company

Page 27: Spam-Me-Not

Fight Back!

The response...

Source: http://www.blackhatworld.com/blackhat-seo/black-hat-seo/186455-what-if-you-reported-google-spam.html#post1667639

Page 28: Spam-Me-Not

We weren’t bluffing

You can report link spam at:https://www.google.com/webmasters/tools/spamreport

Tick ‘Other’ and add ‘link spam’ in the comments box