# Spam attacks on this forum

**URL:** https://discourse.processing.org/t/spam-attacks-on-this-forum/20646
**Category:** Community
**Created:** [May 8, 2020, 7:40pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646 "2020-05-08T19:40:12Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)
#### Post date: [May 8, 2020, 7:40pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/1 "2020-05-08T19:40:13Z")

</div>

Currently we are starting to get a new kind of attack from spambots (or spam posting humans).

The spammer creates a new account, then copy-pastes a programming question from Reddit r/Processing.

They then return many hours or days later and edit ad links or malware links into their original posts.

Our spam filters aren’t catching this – and of course we aren’t either, responding to these (legitimate) reddit questions with full answers. I’m opening this community thread to let people know, and also take suggestions.

---

<div class="post-metadata">

### Author: ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)
#### Post date: [May 8, 2020, 7:40pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/2 "2020-05-08T19:40:54Z")

</div>

I’m now also moving some comments and discussions from spam examples into this thread. They link back to spambot examples (until they are removed).

---

<div class="post-metadata">

### Author: ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)
#### Post date: [May 8, 2020, 7:18pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/3 "2020-05-08T19:18:12Z")

</div>

> [@LennoxConner](#):
>
> I write a lot of letters and e-mails

spambot post (this spambot already flagged by another post), looks like from reddit

[https://www.google.com/search?q=reddit+"i+write+a+lot+of+letters+and+e-mails"](https://www.google.com/search?q=reddit+%22i+write+a+lot+of+letters+and+e-mails%22)

---

<div class="post-metadata">

### Author: ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)
#### Post date: [May 8, 2020, 6:53pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/4 "2020-05-08T18:53:41Z")

</div>

Another reddit copying spambot

> **[r/csshelp - Colored Textbox over image help](https://www.reddit.com/r/csshelp/comments/g67q8q/colored_textbox_over_image_help/)**
>
> 1 vote and 8 comments so far on Reddit

---

<div class="post-metadata">

### Author: ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)
#### Post date: [May 8, 2020, 6:48pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/5 "2020-05-08T18:48:25Z")

</div>

Another spambot copying from Reddit:

> **[r/processing - Is it possible to call built in camera only after clicking a...](https://www.reddit.com/r/processing/comments/g7n2o9/is_it_possible_to_call_built_in_camera_only_after/)**
>
> 2 votes and 0 comments so far on Reddit

---

<div class="post-metadata">

### Author: ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)
#### Post date: [May 8, 2020, 5:35pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/6 "2020-05-08T17:35:47Z")

</div>

> [@Confused. What can I do after learning Processing ? What could be the benefits of that?](https://discourse.processing.org/t/confused-what-can-i-do-after-learning-processing-what-could-be-the-benefits-of-that/20435/1):
>
> I used Processing and I must say it didn’t make that, started using Y and I am very happy and never looked back

Well, it looks like @anon43149899 is another spambot, like @LennoxConner – mirroring legitimate reddit questions for us to answer:

[https://www.reddit.com/r/processing/comments/e96y3w/confused\_what\_can\_i\_do\_after\_learning\_processing/](https://www.reddit.com/r/processing/comments/e96y3w/confused_what_can_i_do_after_learning_processing/)

…and then injecting random malware spam later:

```auto
Understanding these concepts is key - they translate eas
https: //getappvalley.com/ [https: //vlc.onl](https: //vlc.onl/) ily to any other programming language you may use later.

```

I’m temporarily leaving these up so we can look at them / talk about it. If I delete the user it will also delete all their posts, removing all the answers.

---

<div class="post-metadata">

### Author: ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)
#### Post date: [May 8, 2020, 5:28pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/7 "2020-05-08T17:28:27Z")

</div>

Well, this is a real bummer. Looks like the @LennoxConner account copies reddit posts from the Processing reddit channel,

> **[r/processing - How would something like this be achieved?](https://www.reddit.com/r/processing/comments/g8iz8o/how_would_something_like_this_be_achieved/)**
>
> 4 votes and 4 comments so far on Reddit

…then waits a while before injecting them with random spam.

It did it twice, and since they were (copies of) legitimate user questions, we answered them.

[https://discourse.processing.org/t/what-coding-language-do-i-need-to-learn-to-accomplish-this-specific-task-word-processing/20073](https://discourse.processing.org/t/what-coding-language-do-i-need-to-learn-to-accomplish-this-specific-task-word-processing/20073)

Then it vandalized them with spam later.

---

<div class="post-metadata">

### Author: ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)
#### Post date: [May 8, 2020, 6:44pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/8 "2020-05-08T18:44:15Z")

</div>

@GoToLoop – are you still an active r/processing reddit user, and have you seen things like this before?

I am trying to think about a quick way to screen for these things. @Kevin sometimes signals when a person has cross-posted from StackOverflow without cross-linking – I’m assuming that is periodic manual checking – but this is automated and involves malware, not bad manners.

---

<div class="post-metadata">

### Author: ![GoToLoop](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/gotoloop/32/86_2.png) [@GoToLoop](https://discourse.processing.org/u/GoToLoop)
#### Post date: [May 8, 2020, 6:51pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/9 "2020-05-08T18:51:36Z")

</div>

> [@jeremydouglass](#):
>
> Are you still an active r/processing reddit user, and have you seen things like this before?

Yup, I check on [Reddit - Dive into anything](http://Reddit.com/r/processing) daily, but seldom reply to anything there.

When I spot an obvious cross-post, I usually post a link to each other.

---

<div class="post-metadata">

### Author: ![SomeOne](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/someone/32/8639_2.png) [@SomeOne](https://discourse.processing.org/u/SomeOne)
#### Post date: [May 9, 2020, 7:00am UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/10 "2020-05-09T07:00:43Z")

</div>

Would it be possible to prevent external links in posts until you get a certain badge? Then it might require too much effort for spammers to persist.

---

<div class="post-metadata">

### Author: ![Kevin](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/kevin/32/2297_2.png) [@Kevin](https://discourse.processing.org/u/Kevin)
#### Post date: [May 9, 2020, 4:17pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/11 "2020-05-09T16:17:36Z")

</div>

> [@jeremydouglass](#):
>
> @Kevin sometimes signals when a person has cross-posted from StackOverflow without cross-linking – I’m assuming that is periodic manual checking

Yeah, this is just me manually noticing the same post in multiple places.

I know admins can ban a user’s IP address, would that help at all here?

---

<div class="post-metadata">

### Author: ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)
#### Post date: [May 9, 2020, 5:43pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/12 "2020-05-09T17:43:13Z")

</div>

I’ve gone ahead and marked all posts as spam to help train, then banned and banned the IPs on the accounts – but we just got some more new accounts with reddit-copy first posts. Right now the ability of new users to first-post without moderation (usually) and to post a link (to a p5 sketch, or github, or an arduino peripheral etc.) really helps people. I really hope we don’t have to shut that down. We’ll keep an eye on it.

Many of the spam links were odd – like .onl or .ooo, not .com – so they _should_ be easy to train on.

---

<div class="post-metadata">

### Author: ![Chrisir](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/chrisir/32/45_2.png) [@Chrisir](https://discourse.processing.org/u/Chrisir)
#### Post date: [May 12, 2020, 10:56am UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/13 "2020-05-12T10:56:03Z")

</div>

a crawler could collect **all** links in the forum (in a hashMap).

- all links up to today are marked as okay
- a new link is checked against the old links
- if it’s new, it shows them in an extra list

---

<div class="post-metadata">

### Author: ![Bobby54](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/bobby54/32/9302_2.png) [@Bobby54](https://discourse.processing.org/u/Bobby54)
#### Post date: [May 12, 2020, 3:27pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/14 "2020-05-12T15:27:42Z")

</div>

Does the spam appear in all categories or just in Processing?

---

<div class="post-metadata">

### Author: ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)
#### Post date: [May 12, 2020, 3:49pm UTC](https://discourse.processing.org/t/spam-attacks-on-this-forum/20646/15 "2020-05-12T15:49:26Z")

</div>

Multiple categories so far – processing code, project guidance, libraries. although some might be being moved into those categories by mods.
