Spammers have found a way around the filters!

Get answers to your Shareaza related problems.
Forum rules
Home | Wiki | Rules

Spammers have found a way around the filters!

Postby grey-hame » 19 Dec 2009 01:00

This is Not Good. I just got a result for a search for "word1 word2 word3" with the name

Crack for - word3 word2 word1.zip

with a file size of 111K. The thing is, zips should be blocked by the "bogus files" filter in this instance and this one is showing up anyway ("bogus files" seems to be the one that filters file types that don't fit the query).

It gets worse: I tried several regexp security rules to block it and none worked:

^Crack for - .*\.zip
^Crack for - .*\.zip$
^(Crack for - ).*\.zip$
^(Crack for - )

So, it looks like a (almost certainly malware-distributing) spammer has discovered a way to make Shareaza not filter a query hit they send.

This foretells a monstrous flood of unblockable spam results in the near future, as soon as whatever technique they've discovered becomes widespread knowledge among p2p spammers.

Which in turn means you'd better release 2.5.2.0 with the filtering bug fixed ASAP. (The bug in question being whatever is causing this particular search result to not be subjected to filtering. I am now using 2.5.1.0.)
grey-hame
 
Posts: 189
Joined: 08 Aug 2009 19:47

Re: Spammers have found a way around the filters!

Postby cyko_01 » 19 Dec 2009 03:53

User avatar
cyko_01
 
Posts: 938
Joined: 13 Jun 2009 15:51

Re: Spammers have found a way around the filters!

Postby ocexyz » 19 Dec 2009 10:02

User avatar
ocexyz
 
Posts: 624
Joined: 15 Jun 2009 13:09

Re: Spammers have found a way around the filters!

Postby mojo85 » 20 Dec 2009 07:31

Confirm what? It works for you or doesn't?
mojo85
 
Posts: 115
Joined: 27 Sep 2009 05:35

Re: Spammers have found a way around the filters!

Postby ocexyz » 20 Dec 2009 11:18

User avatar
ocexyz
 
Posts: 624
Joined: 15 Jun 2009 13:09

Re: Spammers have found a way around the filters!

Postby grey-hame » 20 Dec 2009 18:00

Consider that with my usual filters, I normally see none of the .zip extension spam that gets returned for every gnutella query one makes, yet this one somehow snuck through. *Something* is wrong.
grey-hame
 
Posts: 189
Joined: 08 Aug 2009 19:47

Re: Spammers have found a way around the filters!

Postby grey-hame » 21 Dec 2009 21:36

Found another one. "foo bar baz(192k 44100 stereo).snd" in response to one of my queries, doesn't get clobbered by a security rule using .*(\(192k 44100 stereo\)\.snd)$ even though it obviously should.
grey-hame
 
Posts: 189
Joined: 08 Aug 2009 19:47


Return to Help and Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron