Tuesday, May 27, 2008

Panoramio under Spam attack

Last weekend Panoramio suffered a Spam attack. Thousands of users were automatically created by a spammer and thousands of comments with malicious links were posted.

We reacted started deleting those fake users and comments using an internal automated script, but soon we realized that it was going to take too long for the database to delete all them, maybe several days. Therefore we did something that worked faster. We deleted all the text of those spam comments to eliminate the dangerous links. That worked immediately and that's why you will see now many spam comments without text. Gradually during the next days those fake users and the empty comments will be completely deleted. We also have temporarily disabled all e-mail alerts for new comments to reduce the impact of the spam in your mailbox.

Joaquin is working right now in adding a captcha (code inside an image) to the sign-up and to the "add a comment". A captcha is only readable by humans, so it should stop further automated massive attacks. However until the captcha is ready is possible you get some more spam.

Panoramio has been relavitely free of Spam for almost 3 years, but the more popular the site gets, the more probable is an attack. We are terribly sorry for this problem and we would like to apologize for all the trouble that it might have caused to you. I would like to thank all the people that reported the problem and helped to fix it, specially Panamon Creel who contacted snipUrl service and got them to disable the malicious links and block the IP of the spammer.

24 comments:

  1. Hi Eduardo,

    I just want to thank you and the whole team for all jobb you are doing.

    Kind regards from Sweden

    *Romy*

    ReplyDelete
  2. Please let me add to it that there most likely had been other users besides me who reported the misuse of service to snipURL so thanks should go to all users that actively worked in the background trying to "contain the Spam outbreak".

    ReplyDelete
  3. Please let me add to it that there most likely had been other users besides me who reported the misuse of service to snipURL so thanks should go to all users that actively worked in the background trying to “contain the Spam outbreak”.

    ReplyDelete
  4. Thanks for the speed and effectiveness in repairing this, Eduardo, Panamon & team !

    ReplyDelete
  5. I saw that. Thaks 4 Yours fast reaction.

    ReplyDelete
  6. Well done Panamon, good effort team.
    Also thanks to Ryan Cahoun and his list of spam accounts.
    Cheers,

    Tony

    ReplyDelete
  7. Why is captcha needed for comments?
    I mean, the captcha blocks signups, so a captcha on comments will only nag users

    ReplyDelete
  8. Thank you so much for clearing this! I was getting 19 emails in one day! I knew after the first spam that it was a spammer without opening up the email! Its great that everything is back under controll. Big thanks to the Panoramio Team and all who helped out!

    ReplyDelete
  9. You might also like to ask users to delete the spam comments from their lists; I did mine & it took me about 5 minutes. Good work on the cleanup, and we definitely need a captcha on the comments.

    ReplyDelete
  10. Thanks to the Panoramio team for the fast and furious completion of this incommodious problem.

    polytropos

    ReplyDelete
  11. Eduardo: just to let you know - we DO understand that things like this happen and it is not your fault. Please do not be sorry, we are with you on this one! I'm sure you wish the problem was gone even more than we do.

    Take it easy, it'll work itself out fine.

    ReplyDelete
  12. Thank you so much for the prompt repair. It was awful to discover this much loved site under attack. It was great to see everyone warning all their contacts. Well done to all

    ReplyDelete
  13. "captcha on comments will only nag users"

    Yes you're right, but so does spam. It's choosing between two evils I guess.

    ReplyDelete
  14. Hi, I see one more spam person: Antwineshad1961

    ReplyDelete
  15. I want to say thank you for the great job of your team. panoramio is a great enrichment.

    ReplyDelete
  16. Now the captcha in the sign-up process is working. We will see if we also add it for comments.

    ReplyDelete
  17. Thanks for the update Eduardo.
    At least we wont get any robo-users being created anymore.

    ReplyDelete
  18. Now all spam comments and users are deleted. If someone still see some spam, please, let me know.

    ReplyDelete
  19. Hallo Panoramio-Team,
    You've done a good job! Thank You very much indeed.

    ReplyDelete
  20. Thanks for the quick response after my email to you. I am still having trouble with Artolacorrina1965. sometimes it is there and sometimes not.

    ReplyDelete
  21. Hallo Alan,

    I had the same problem. I deleted the cache and pressed F5 to refresh.
    Possibly You will no longer have the trouble if You do the same.

    ReplyDelete
  22. very well fast done with those spam
    thank you to all Panoramio for your job

    ReplyDelete
  23. Hi there,

    I hate spam as well, but I dislike captcha also. I might want to consider the akismet spam plugin for wordpress. I have it installed as well and it works like a charm.

    ReplyDelete
  24. Thank you so much for the prompt repair. It was awful to discover this much loved site under attack. It was great to see everyone warning all their contacts.

    ReplyDelete