4 ms·
Spammers started to hit GitHub?
- buttscicles 14y agoI noticed some spammers a couple of weeks ago, they occasionally create repositories too. I'm not sure if there is a way to report them, there is nothing no the GH contact form.
- Heliosmaster 14y agoI'm quite confident a story on top of HN is a good way to reach them :D
- sudhirj 14y agoI suppose it is... it's not like it's some security hole that everyone is going to exploit. I'm sure they're already working on spam filtering and reporting.
- kindahero 14y agoNo.. they have "contact" page and they are very quick and responsive. https://github.com/contact https://github.com/contact
- vidar 14y agoThis must have been a problem for some time, considering how popular GitHub is. There is no way around spam when running a popular service where the users can create their own content.
- daGrevis 14y agoWhat about old-good CAPTCHA? There are many ways, but all are annoying for normal users.
- DizzyDoo 14y agoEven the best captcha methods can be circumvented by farming them out to poorer countries for only pennies.
- 67726e 14y agoHell, you could farm it out to minimum wage workers here in the US. I've seen it done, although I think it would only really work on a large scale if you have a constant stream of captchas.
- ceejayoz 14y agoThere's an even cheaper way - host a porn gallery, and require a captcha to access it. Present the captcha you're trying to solve to the horny user.
- deleted 14y ago[deleted]
- bencevans 14y agoCaptchas just advertise that a service has a spam problem.
- thejosh 14y agoYou can purchase 1000 captcha solves for $1.39 last time I checked. CAPTCHA only security is fantastic for spammers.
- ozi 14y agoYup; $1.39 per 1000 on Deathbycaptcha.com It's cheaper if you buy ~1,000,000+ in bulk. Or you can buy OCR software that plugs in to your bots; e.g. captchasniper.com Captcha'd targets are usually higher-quality and more valuable as there is some economic cost of posting to it.
- donbronson 14y agousing CAPTCHAs assumes the majority of people are spammers rather than real users. it's an alienating user experience and one that i hope goes away.
- beagle3 14y agoProper etiquette would be to let the github people know for a few days before you alert the whole world. Have you notified them before posting this?
- enneff 14y agoWhy? It's not like they're disclosing something sensitive, like a security vulnerability.
- reitzensteinm 14y agoThis isn't a security flaw, it's just mundane crap that every web app goes through. They'll delete this today and tweak their filtering, and tomorrow the spammer will try again (or in twenty minutes, who am I kidding?). I'm not sure why you say prior notification is proper etiquette in this circumstance. It's equivalent to pointing out a grammar mistake in a blog post. Not particularly interesting, but not malicious.
- bencevans 14y agoI don't see any reason too I'm afraid. If it was a security vunerbillity I would have, as I have done before ... https://help.github.com/articles/responsible-disclosure-of-security-vulnerabilities https://help.github.com/articles/responsible-disclosure-of-s... (Ben Evans - @bencevans)
- beagle3 14y agoThanks for all the downvotes, guys! I'm not talking about "responsible disclosure" and I'm not sure why people assumed I do. If I see that a person has their fly open, I'd go and discretely alert them of that. Similarly, if someone has a note saying "I am stupid" taped to their back (which I think is a good analogy to what the spam on github is), I would do the same. I wouldn't go shouting "hey, github has an 'I am stupid' sign taped on their back" in town square, which is what posting it on HN amounts to.
- Gigablah 14y agoReported the blogspot link as a spam blog. Not sure about Google's response time on these things.
- jpdoctor 14y agoLooks like git needs the equivalent of a downvote: Something like % git nuke https://github.com/quartzjer https://github.com/quartzjer
- hk__2 14y ago404 error.
- mochizuki 14y agoGoogle Cache http://webcache.googleusercontent.com/search?q=cache%3Ahttps%3A%2F%2Fgithub.com%2Fquartzjer%2FTeleHash%2Fissues%2F5 http://webcache.googleusercontent.com/search?q=cache%3Ahttps...
- pooriaazimi 14y agoEvery time I mention this on HN, at least 15 people upvote it - which means they didn't know about it. So I feel obliged to repeat it again and again (as I usually use this method a few times every week and it's tremendously useful for me): If you want to get Google's cached version of a webpage, just type cache:[url] e.g.: cache:https://github.com/quartzjer/TeleHash/issues/5 in the search bar and press return.
- uxp 14y ago*in Chrome's search bar. I know, it's a petty technicality. Safari says it can't open the specified address, and Firefox doesn't understand the URL. I'm even more certain IE will explode if I was to try, but I can't at the moment. From what I remember, IE can't even parse a raw IP address without explicitly putting http:// http:// in front of it.
- pooriaazimi 14y agoYou're right. But you can do a `cache:http://...` http://...` in google.com's search bar, which is how I do it. And unless I'm mistaken, Chrome's built-in search bar is called OmniBar, so my wording was (incidentally) correct! ;-)
- ck2 14y agoThe amount of time and energy and cpu cycles wasted on spammers is truly a crime against humanity. I still do not understand how it makes them money, I think it's just an endless chain of people falsely thinking others are successful with it so they try to do it too and the cycle continues.
- xSwag 14y ago>I still do not understand how it makes them money When I saw this post the page had 404d. However, the page was still active in the Google cache[1] It is not just Github being targeted, a lot of other large websites with user generated content are also being spammed with this content[2][3] The spammers are linking the content to blogspot blogs so that they can: 1. hide the referrer from their affiliate program (to prevent getting banned for spamming) 2. to utilize the temp increase in search engine rankings 3. save money on domains for one-off usage Since the "live stream" is just a one-off game that will only be popular/trending for 1-3 days in which period the spammers will use a lot of macro scripts/bots to spam these websites. Believe it or not, even a "nofollow" link can give you an advantage in search rankings. They spam them to death in the "popular period" and then bank money from the affiliate program[4] [1]http://webcache.googleusercontent.com/search?q=cache%3Ahttps%3A%2F%2Fgithub.com%2Fquartzjer%2FTeleHash%2Fissues%2F5 http://webcache.googleusercontent.com/search?q=cache%3Ahttps... [2]http://shine.yahoo.com/author-blog-posts/watch-38-enjoy-florida-st-vs-maryland-live-081500525.html http://shine.yahoo.com/author-blog-posts/watch-38-enjoy-flor... [3]http://webcache.googleusercontent.com/search?q=cache%3Awww.funnyordie.com%2Flists%2F58f182726b%2Fwatch-ncaa-florida-state-vs-maryland-live-stream-college-football-week-12-online-satellite-tv%3Frel%3Dby_user http://webcache.googleusercontent.com/search?q=cache%3Awww.f... [4]http://www.officialtvstream.com.es/passport/signup.php?price_group=-478&product_id=80&hide_paysys=ccbill http://www.officialtvstream.com.es/passport/signup.php?price...
- sillysaurus 14y agoThey spam them to death in the "popular period" and then bank money from the affiliate program If you had to speculate: How much money? (I know, it all depends, etc. But I was just hoping to get a rough idea of the order of magnitude here.)
- AshleysBrain 14y agoAll large sites get hammered by automatic/semi-automatic spam, and occasionally some leaks through. Is this surprising?
- Zak 14y agoAll sites get hammered by automatic spam. If it gets indexed by google, or if anybody links to it, the spam bots will find it eventually. It is not practical to operate any kind of website that allows users to post things without some form of spam protection. For small sites, email verification or text classification will do the job by itself. Traditional captchas are fairly ineffective, but written questions like "what color rhymes with true?" seem to work pretty well for smaller sites. Bigger sites dealing with a larger volume of traffic almost always require regular human intervention, curated IP block lists, stealth banning and the like.
- jeremymcanally 14y agoWe're aware of the problem. Just like any service like ours, we see a fair amount of spam repos, issues/comments, and, of course, Gists. We already expend a good bit of energy on handling it as it is, but we're always working on new ways to handle it. :)
- driverdan 14y agoIt'd be nice if gists had a link to report them as spam. Also, links in gists should be nofollow.
- dutchbrit 14y agoI don't understand spammers that target tech sites - especially the ones that add nofollows, techies know spam and don't click the shit. Waste of time, effort and money for the spamlords to be honest
- thedufer 14y agoAs others have said, nofollows do give you help in search results, although not as much as otherwise. They're looking to rise in search results more than for legitimate clicks.
- waffle_ss 14y agoThis is nothing new. If you watch the [new gist feed][1], for instance, you'll see plenty of it roll by. [1]: https://gist.github.com/gists https://gist.github.com/gists
- driverdan 14y agoWhat's especially interesting is that gists are allowed by github's robot.txt and none of the links are nofollow. That means every gist spammers create with links are helping their ranking.