Welcome, Guest. Please login or register.
May 17, 2012, 02:58:00 pm
Home Help Search Login Register
News: SMF Forum plugin now available: Code Samples

BotScout  |  General Category  |  BotScout Discussion (Moderator: MysteryFCM)  |  Topic: Possible root for misuse of botscout « previous next »
Pages: [1] Print
Author Topic: Possible root for misuse of botscout  (Read 1023 times)
Matt
Newbie
*
Posts: 7


View Profile
« on: April 14, 2011, 03:00:06 am »

I was wondering if anyone has considered that botscout could be misused to maliciously apply 'spammer' status to an ip or ip range.

As botscout applies a spammer status to any ip that is tested with a known spammer email, it would be easy for someone to modify the code to autosubmit & set any ips they wanted to spammer status.

Has this been looked into? has the option of not flagging ip's so quickly been considered?
Logged
Mike
Administrator
Sr. Member
*****
Posts: 280



View Profile
« Reply #1 on: April 14, 2011, 06:32:03 am »

As with almost any service it's possible for it to be used maliciously. We have some safeguards in place but there isn't any way to vet every email address or ip. It's one reason why user submissions aren't added automatically to the database, but are instead held pending statistical verification. It's not a perfect system but so far it's worked pretty well.

We generally remove email addresses and ips on request, so if someone does get listed by accident or through malicious actions they can be taken of the list without much trouble. If an email address or ip keeps getting added in error we can whitelist it to prevent it from being added again.


I was wondering if anyone has considered that botscout could be misused to maliciously apply 'spammer' status to an ip or ip range.

As botscout applies a spammer status to any ip that is tested with a known spammer email, it would be easy for someone to modify the code to autosubmit & set any ips they wanted to spammer status.

Has this been looked into? has the option of not flagging ip's so quickly been considered?
Logged

Please don't PM me for assistance- post your questions in the forum where others can see them.
Wizzle
Newbie
*
Posts: 17


View Profile WWW
« Reply #2 on: April 14, 2011, 02:23:36 pm »

That brings up another question. If I submit myself while testing a mod, is there anyway I can manually remove myself. Or would it just be better to ask to have my test info white listed, or something like that.

Just asking...as I seem to do that a lot! LOL!
Logged
Mike
Administrator
Sr. Member
*****
Posts: 280



View Profile
« Reply #3 on: April 14, 2011, 02:59:13 pm »

We're looking at automated removal of 3rd-party or trusted-party records, but it comes with a lot of logistical and security issues that we haven't fully worked out yet. In the meantime just email us and ask for removal- we usually get it done within a couple of hours, often sooner.

That brings up another question. If I submit myself while testing a mod, is there anyway I can manually remove myself. Or would it just be better to ask to have my test info white listed, or something like that.

Just asking...as I seem to do that a lot! LOL!
Logged

Please don't PM me for assistance- post your questions in the forum where others can see them.
Pages: [1] Print 
BotScout  |  General Category  |  BotScout Discussion (Moderator: MysteryFCM)  |  Topic: Possible root for misuse of botscout « previous next »
Jump to:  


Login with username, password and session length

BotScout - Possible root for misuse of botscout

SEO light theme by © Mustang forums. Powered by SMF 1.1.16 | SMF © 2011, Simple Machines