Administrative suspension

Status
Not open for further replies.

vivcool

New Member
Messages
13
Reaction score
0
Points
1
Hi,

I was suspended two days ago, after appealing I was unsuspended yesterday morning apparently. I checked my email today to see that I am suspended again, and this time it says you appeal has been sent.

Is there something wrong with the system, or is this permanent?

Thanks,
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
The original dispute was marked as In Progress; your account was sending out over 10,000 spam registration emails due to an unmitigated spambot attack on your Joomla install. In the original reply to the appeal, you were advised that this needed to stop within 24 hours, or the suspension would be reapplied; the spam continued after 24 hours with no visible reduction in volume, so the account was re-suspended once again.

Normally this secondary suspension is permanent, as we cannot continue to allow the spam and resource-usage of the account to remain at the level they were (the bots were causing high CPU usage due to their attacks). That said, I've opted to go back in and move your public_html to public_html_spambotattack, and created a new one in its place.

The suspension is being lifted shortly, however you need to ensure your account does not come under a spambot attack in the future - we cannot have a single account sending out this much spam. Lock down the Joomla install so the bots can't register, otherwise this would likely occur again in the future.
 

vivcool

New Member
Messages
13
Reaction score
0
Points
1
The original dispute was marked as In Progress; your account was sending out over 10,000 spam registration emails due to an unmitigated spambot attack on your Joomla install. In the original reply to the appeal, you were advised that this needed to stop within 24 hours, or the suspension would be reapplied; the spam continued after 24 hours with no visible reduction in volume, so the account was re-suspended once again.

Normally this secondary suspension is permanent, as we cannot continue to allow the spam and resource-usage of the account to remain at the level they were (the bots were causing high CPU usage due to their attacks). That said, I've opted to go back in and move your public_html to public_html_spambotattack, and created a new one in its place.

The suspension is being lifted shortly, however you need to ensure your account does not come under a spambot attack in the future - we cannot have a single account sending out this much spam. Lock down the Joomla install so the bots can't register, otherwise this would likely occur again in the future.

Hi,

I'm not really an expert when it comes to preventing spam accounts. But I've learnt one way to stop it, for that I need to access my sharetronix account. I have auto-directed the joomla to sharetronix which is when this happened I think.

How can I access my share tronix website/account, I need to login from frontend.

By the way; I didn't get any messages that about me being 'advised that this needed to stop within 24 hours, or the suspension would be reapplied'. I only got 4 emails from x10; suspended, unspended, suspended and unsuspended again. And I was suspended before I could login to check any replies.

Thanks,
 
Last edited:

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
The previous install is located in public_html_spambotattack; I don't recommend putting these files live due to the level of spammng that has occurred, but if you really need to, copy its contents into public_html - the database for the installs are still intact.
 

vivcool

New Member
Messages
13
Reaction score
0
Points
1
The previous install is located in public_html_spambotattack; I don't recommend putting these files live due to the level of spammng that has occurred, but if you really need to, copy its contents into public_html - the database for the installs are still intact.

I have moved it to public_html, when I access my website it says account has been suspended. I need it unspended so I can change the setting. Is there thing I can do?

Thanks,
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
That's my bad actually, I forgot there's a file I need to erase before moving the compromised folders around.

I'll have it fixed in about 60 seconds.


Edit: Aaaaand done. When I moved the folders around it meant it didn't properly remove the suspended redirect; I've fixed that and the account is loading normally once again.
 
Last edited:

vivcool

New Member
Messages
13
Reaction score
0
Points
1
That's my bad actually, I forgot there's a file I need to erase before moving the compromised folders around.

I'll have it fixed in about 60 seconds.


Edit: Aaaaand done. When I moved the folders around it meant it didn't properly remove the suspended redirect; I've fixed that and the account is loading normally once again.

No problem,

I have changed the setting to 'email confirmation' therefore spam bots should not be able to register anymore and put messages on the sites. Is there anything else I need to prevent/change?

One thing it won't stop is the spam bots having a look at my website. My joomla website is redirected to my sharetronix.

Thanks for your help,
 
Last edited:

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
One thing to try and see if you can add would be captcha's, otherwise there's a good chance it'll start sending out a ton of spam emails for the spambots passing registrations. As far as bots viewing, that's fine - once the bots realize they can't post, they'll stop visiting.
 

vivcool

New Member
Messages
13
Reaction score
0
Points
1
One thing to try and see if you can add would be captcha's, otherwise there's a good chance it'll start sending out a ton of spam emails for the spambots passing registrations. As far as bots viewing, that's fine - once the bots realize they can't post, they'll stop visiting.

I can try, but I won't guarantee as I don't really know how to integrate captcha on other platforms.

May I ask when this problem occurred? I'm pretty sure the number of registration decreased over a month or two ago when I made people/spam bots confirm their email first.
 

descalzo

Grim Squeaker
Community Support
Messages
9,373
Reaction score
326
Points
83
What CMS are you using?

And "confirm their email" ? Like they try to register and you send them an email?
 

vivcool

New Member
Messages
13
Reaction score
0
Points
1
What CMS are you using?

And "confirm their email" ? Like they try to register and you send them an email?

Hi,

Share tronix

Yeah, they register and then have to confirm registration via email. This has worked before. Spam bots register when I disable that option.
 

descalzo

Grim Squeaker
Community Support
Messages
9,373
Reaction score
326
Points
83
So if my bot tries to register at your site 10000 times a day, you send it 10000 emails?
 

descalzo

Grim Squeaker
Community Support
Messages
9,373
Reaction score
326
Points
83
It's all auto email, so yeah I guess so.

So, do you see the source of the problem?

I would check with Share tronix and see if they have some kind of anti-spam/captcha plugin.
 

vivcool

New Member
Messages
13
Reaction score
0
Points
1
So, do you see the source of the problem?

I would check with Share tronix and see if they have some kind of anti-spam/captcha plugin.

I think a captcha would be the best solution before registration. I'll look into it, hopefully I don't get a permanent suspension whilst looking for one.
 
Status
Not open for further replies.
Top