[SAC] SPAM Alert!

Hi,

what happens right now is what we get if we are not careful in accepting
request. If one spammer gets through, they send their bots or click farms.

I took care of the spammer mentioned in the forwarded mail, by blocking
him and deleting his "contributions".

So, please be careful in accepting requests, better contact the user
directly and ask him/her about his/her intentions.

Regards,
Christian

PS: Thanks for setting this shared mail adress for account request
handling up!

-------- Weitergeleitete Nachricht --------
Betreff: SPAM Alert!
Datum: Tue, 23 May 2017 18:58:07 +0530
Von: saman fatma <nilesh.saman@gmail.com>
An: mail@cwillmes.de, info@osgeo.org

Hi
OSGeo Webmaster

Request for Block This Person and delete all his content He is spamming
on_ __https://wiki.osgeo.org/&gt;\_\.
posting duplicate file and content too Kindly check his profile and take
action against him.

Details are mention below

user name:Smithedward5768 <https://wiki.osgeo.org/wiki/User:Smithedward5768&gt;

https://wiki.osgeo.org/wiki/ARIZONA_QB$$_1_800_860_9230_$$_Quickbooks_support_phone_number_%3D_Quickbooks_Customer_service_number

https://wiki.osgeo.org/wiki/ALASKA_QB$$_1_800_860_9230_$$_Quickbooks_support_phone_number_%3D_Quickbooks_Customer_service_number

https://wiki.osgeo.org/wiki/ALABAMA_QB$$_1_800_860_9230_$$_Quickbooks_support_phone_number_%3D_Quickbooks_Customer_service_number

Thanks&Regards
Saman Fatma

On Tue, May 23, 2017 at 04:23:33PM +0200, Christian Willmes wrote:

So, please be careful in accepting requests, better contact the user
directly and ask him/her about his/her intentions.

Could it be possible to include the confirmed email of the requestor
in the notification mail to this list, so that we can maybe do
this step publically (like we do for mantra-requests) ?

Even better, don't produce an email *at all* if the candidate
email was not confirmed...

--strk;

it is possible to “decide” a request as spam. In this case the request is deleted and no email will be send.

Christian

On 2017-05-23 2:47 PM, Sandro Santilli wrote:

On Tue, May 23, 2017 at 04:23:33PM +0200, Christian Willmes wrote:

So, please be careful in accepting requests, better contact the user
directly and ask him/her about his/her intentions.

Could it be possible to include the confirmed email of the requestor
in the notification mail to this list, so that we can maybe do
this step publically (like we do for mantra-requests) ?

Even better, don't produce an email *at all* if the candidate
email was not confirmed...

hi Sandro,

You may have noticed that I have been modifying that same notification email to the admins, so it doesn't contain escaped text and also contains a working link to the ConfirmAccounts page (yay!). Please note that this ConfirmAccount extension only sends out this notification when that (spammer) has confirmed his/her email account. So, I am not sure how the spammer/bot avoids this now.

I have looked into the ConfirmAccount settings, and I don't see a magical variable to add so that I could include that 'confirmed' email address, in the email to admins. I'll keep looking.

I hope this answers your questions, or, tries to? -jeff

On Tue, May 23, 2017 at 03:59:49PM -0300, Jeff McKenna wrote:

On 2017-05-23 2:47 PM, Sandro Santilli wrote:
> On Tue, May 23, 2017 at 04:23:33PM +0200, Christian Willmes wrote:
>
> > So, please be careful in accepting requests, better contact the user
> > directly and ask him/her about his/her intentions.
>
> Could it be possible to include the confirmed email of the requestor
> in the notification mail to this list, so that we can maybe do
> this step publically (like we do for mantra-requests) ?
>
> Even better, don't produce an email *at all* if the candidate
> email was not confirmed...

You may have noticed that I have been modifying that same notification email
to the admins, so it doesn't contain escaped text and also contains a
working link to the ConfirmAccounts page (yay!). Please note that this
ConfirmAccount extension only sends out this notification when that
(spammer) has confirmed his/her email account. So, I am not sure how the
spammer/bot avoids this now.

Ah, great. So that part is already done, cool :slight_smile:

I have looked into the ConfirmAccount settings, and I don't see a magical
variable to add so that I could include that 'confirmed' email address, in
the email to admins. I'll keep looking.

I hope this answers your questions, or, tries to?

It does answer it, yes. Thanks for keep looking as I think it could
help to move the conversation from web to email as Christian was
suggesting.

--strk;