Looks like we’ve had a wave of porn bots hit recently. Screenshot is a sampling of what’s popping up on my threads feed when sorted by new.

A heads up to @ernest and to folks with magazines that might get hit by these guys. Looks like they’re submitting from a couple of different domains, so it’s difficult to block them from the user side, and some admin action might be necessary.

EDIT: ernest has removed the accounts and content, looks like all is well.

  • DarkThoughts
    link
    fedilink
    221 year ago

    DON’T CLICK ON THEM! They use multiple redirects which potentially leads them to load websites in the background that could infect your system.

    • ArotriosOP
      link
      fedilink
      161 year ago

      F for @DarkThoughts. We salute your sacrifice for the greater good. May your files be encrypted and your antivirus strong.

      • DarkThoughts
        link
        fedilink
        131 year ago

        Ublock already nuked the pop up, I had to use an online scanner to check what was even happening because it just closed the tab immediately. Also I’m on Linux, so I feel I am probably not the target audience.

  • ernest
    link
    fedilink
    91 year ago

    @Arotrios The magazines have been cleaned up and I’ve deleted the associated accounts. If this happens again, I’ll apply a temporary fix. And if the campaigns cease, I’ll work on a more comprehensive solution. Thanks for reaching out.

    • ArotriosOP
      link
      fedilink
      31 year ago

      @ernest - thanks! Glad I could help - you’ve built a great space here, and I know what a pain it is to deal with spambots.

  • @Carnelian
    link
    71 year ago

    Absolutely trashing c/all on lemmy as well

    • scytale
      link
      31 year ago

      Yep, it’s all over All even when sorting by Top or Hot.

    • ArotriosOP
      link
      fedilink
      2
      edit-2
      1 year ago

      You guys over at lemmy might be able to clear your feeds over there by unsubbing to or blocking kbin.social/m/random until the accounts get cleared out. It looks like that’s the only community they’re posting to here thus far.

      • @Carnelian
        link
        21 year ago

        I’ve blocked it for the time being, will keep an ear out for when the issue is resolved.

        I’m not quite sure what the purpose of m/random actually is under normal circumstances, though?

        • cacheson
          link
          fedilink
          111 year ago

          I think it’s mainly to facilitate the microblogging side of kbin. Microblog posts normally get sorted into magazines according to their hashtags. Any post that doesn’t have at least one matching magazine ends up in /m/random.

          • Teppic
            link
            fedilink
            61 year ago

            It is more like r/EverythingElse
            It ‘only’ catches posts which didn’t go to a magazine, it doesn’t aggregate the ones which did.

  • ArotriosOP
    link
    fedilink
    41 year ago

    Update 3:39 PST - another wave of 10 or so just came in - reported and blocked.

  • Jaysyn
    link
    fedilink
    41 year ago

    Click on the server name & block it for all time.

    • ArotriosOP
      link
      fedilink
      191 year ago

      I would, but it’s not just one server they’re submitting - they’re pushing multiple domains.

      That being said, I think I’ve reported and blocked all of them, and my feed is clear now - there were about 20 - 30 accounts in total. This indicates that someone manually set them up by going through Kbin’s login process - if they had built a bot that could hack the login, we’d probably see numbers in the hundreds.

        • ArotriosOP
          link
          fedilink
          21 year ago

          I found a bit more than that, but yeah, it was a manageable number on my end to clean the feed.

  • GeekFTW
    link
    fedilink
    41 year ago

    Yeah just unsubbed from /m/random a few moments ago, fuckin’ unreal lol.

  • hariette
    link
    fedilink
    31 year ago

    Ended up having to ban a bunch of accounts from my instance. They just kept coming for a bit.

  • ArotriosOP
    link
    fedilink
    21 year ago

    Update 11 hours from original post - 12:45am PST - still catching them. Got another 10. It looks like they’re firing off roughly every three hours.

  • Brkdncr
    link
    fedilink
    21 year ago

    Might need to throttle posts from anyone to a single domain that isn’t already allow listed.

    • roguetrick
      link
      fedilink
      21 year ago

      Asking to defend from us in a kbin thread is likely futile, I gotta say.

      • ArotriosOP
        link
        fedilink
        21 year ago

        Yeah - I was laughing about that too. Guess the guy likes downvote farming.

    • ArotriosOP
      link
      fedilink
      21 year ago

      You could, but then all you’d be left with is lemmings and mastodon toot.

    • EnglishMobster
      link
      fedilink
      2
      edit-2
      1 year ago

      You realize you are posting this to the KbinMeta magazine hosted on the main Kbin instance, right?

  • ArotriosOP
    link
    fedilink
    11 year ago

    And still coming in at a rate of about 10 every two hours… 6:30am PST, 17 hours from original post

    • ArotriosOP
      link
      fedilink
      11 year ago

      @ernest nixed them already. Note that according to reports, the porn wasn’t good and the sites full of malware and redirects.