Skip to main content
GameDev.net gamedev.net
🔒 Locked

Why can't bots be stopped? How do they work ? Yahoo chat is even ruined

Started by angrytofu Apr 26, 2007 at 8:19 PM 14 replies 8.9k views
Original Post
angrytofu
angrytofu
I am on ICQ and I get some bot messaging me every hour. Why is it so hard for them to get rid of bots? Why not have one of those 'fuzzy image' verifications before a user can log on.. ? How do they work ? Is there some program out there launching 1000 instances of ICQ and reading in a online user list? Can't the ICQ detect when a large amount of messages are sent from a IP ? And with Yahoo chat 10 years ago I used to talk to people on there. Now if you try to goto a room it is about 80% bots and no one goes there. Why cant yahoo do something about this ? Is it that hard? I don't think I have any bots harass me on MSN messenger though.
http://www.mattherb.com now with CATCAM!
ranakor
ranakor
as for bypassing icq login & fuzzy images & instances , in most cases, it's absolutely not how it works , most bots (i assume if it's like for other clients) simply reverse engineer the protocol & build themselves upon it to comunicate with the server , so the dude with the bot doesn't use icq nor has it installed , his own program acts as icq & sends date pretending to be icq to the icq servers whom have no way of checking wether that's true.

as for checking amount of data from an ip that's feasible but it'd be pretty hard to lower the amount you can send too much , i know quite a few people who legitimally have 50+ ppl (& 20+ online) on their list , & anything past that number i assume it becomes worth it to use proxies to change ip whenever you get banned anyway , it's prolly doable , but prolly not worth the hassle to them either

and for icq ... check do not accept messages from people not on your buddy list? i never got a message from a bot when i used it
Maega
Maega
Quote:
Original post by ranakor
as for bypassing icq login & fuzzy images & instances , in most cases, it's absolutely not how it works , most bots (i assume if it's like for other clients) simply reverse engineer the protocol & build themselves upon it to comunicate with the server , so the dude with the bot doesn't use icq nor has it installed , his own program acts as icq & sends date pretending to be icq to the icq servers whom have no way of checking wether that's true.

as for checking amount of data from an ip that's feasible but it'd be pretty hard to lower the amount you can send too much , i know quite a few people who legitimally have 50+ ppl (& 20+ online) on their list , & anything past that number i assume it becomes worth it to use proxies to change ip whenever you get banned anyway , it's prolly doable , but prolly not worth the hassle to them either

and for icq ... check do not accept messages from people not on your buddy list? i never got a message from a bot when i used it


Even if the bot used the ICQ client, the fuzzy image thing would be simple because I could just type in the stuff from the image for the bot and then it would go on its merry way messaging people.
Ravuya
Ravuya
Quote:
Original post by Maega
Quote:
Original post by ranakor
as for bypassing icq login & fuzzy images & instances , in most cases, it's absolutely not how it works , most bots (i assume if it's like for other clients) simply reverse engineer the protocol & build themselves upon it to comunicate with the server , so the dude with the bot doesn't use icq nor has it installed , his own program acts as icq & sends date pretending to be icq to the icq servers whom have no way of checking wether that's true.

as for checking amount of data from an ip that's feasible but it'd be pretty hard to lower the amount you can send too much , i know quite a few people who legitimally have 50+ ppl (& 20+ online) on their list , & anything past that number i assume it becomes worth it to use proxies to change ip whenever you get banned anyway , it's prolly doable , but prolly not worth the hassle to them either

and for icq ... check do not accept messages from people not on your buddy list? i never got a message from a bot when i used it


Even if the bot used the ICQ client, the fuzzy image thing would be simple because I could just type in the stuff from the image for the bot and then it would go on its merry way messaging people.
Or you could do what most spammers do with captchas, and rig up a site that trades a user porn passwords in return for entering the captcha.
evolutional
evolutional
Quote:
Original post by Ravuya
Or you could do what most spammers do with captchas, and rig up a site that trades a user porn passwords in return for entering the captcha.


Wow, does this actually happen? Pretty smart idea really
Zipster
Zipster
So you tell us about these websites where people are given porn passwords for helping spam bots, but you don't tell us where they are? You're killin' us here!

I actually tried to come up with a clever slogan for such a site, but I couldn't think of anything relating to spam that remotely rhymed with "get your rocks off" or some variation thereof.
Extrarius
Extrarius
As far as captchas, there was a group at some school that studied them and was able to defeat 75% or 80% using basic OCR algorithms, and iirc they got up to 90% once they started tuning them for their specific project.

As ranakor said, there are plenty of ways to connect to a chat protocol without using the original program. For example, I use Miranda IM, which includes full source for ICQ and many other protocols. It would be almost trivial to modify the source to be a batch-message program.
"Walk not the trodden path, for it has borne it's burden." -John, Flying Monk
angrytofu
angrytofu
Well I think limiting messages sent to no more than 50 users per day is reasonable. I am assuming as it is now the bots are sending to atleast 5000 a day.. otherwise I would not be getting so many. There alot of talk about stopping spam email but I never hear much about the war on spam bots and how they can be stopped

I don't mind if new people find me and talk to me.. So that is why I don't limit it to my contacts


Quote:
Original post by ranakor
as for bypassing icq login & fuzzy images & instances , in most cases, it's absolutely not how it works , most bots (i assume if it's like for other clients) simply reverse engineer the protocol & build themselves upon it to comunicate with the server , so the dude with the bot doesn't use icq nor has it installed , his own program acts as icq & sends date pretending to be icq to the icq servers whom have no way of checking wether that's true.

as for checking amount of data from an ip that's feasible but it'd be pretty hard to lower the amount you can send too much , i know quite a few people who legitimally have 50+ ppl (& 20+ online) on their list , & anything past that number i assume it becomes worth it to use proxies to change ip whenever you get banned anyway , it's prolly doable , but prolly not worth the hassle to them either

and for icq ... check do not accept messages from people not on your buddy list? i never got a message from a bot when i used it


http://www.mattherb.com now with CATCAM!
angrytofu
angrytofu
So if its impossible to stop them then the amount of bots must have a correlation to the ratio of users that purchase the service spammed.

So then do the yahoo chat bots work in the same way? Just reverse engineer.. Isnt a yahoo account required atleast to access the chat room? Therefore yahoo could easily detect who are bots and automatically delete them ?




Quote:
Original post by Extrarius
As far as captchas, there was a group at some school that studied them and was able to defeat 75% or 80% using basic OCR algorithms, and iirc they got up to 90% once they started tuning them for their specific project.

As ranakor said, there are plenty of ways to connect to a chat protocol without using the original program. For example, I use Miranda IM, which includes full source for ICQ and many other protocols. It would be almost trivial to modify the source to be a batch-message program.


http://www.mattherb.com now with CATCAM!
chollida1
chollida1
Quote:
Original post by angrytofu
Well I think limiting messages sent to no more than 50 users per day is reasonable. I am assuming as it is now the bots are sending to atleast 5000 a day.. otherwise I would not be getting so many.



I doubt that would work. Larry Wall posts what seems like 5000 times a day on the Perl6 icq:).

Perhaps limiting new/untrused users might work?

Cheers
Chris
CheersChris
wilhil
wilhil
Quote:
Original post by Zipster
I actually tried to come up with a clever slogan for such a site,



Spam & Spunk
Do click, Get clit
Clicky for titty

ahh, came up with loads when reading through, and cant think of them now..... very tired and bored! :(
>wilhil<
curtmax_0
curtmax_0
Quote:
Original post by Extrarius
As far as captchas, there was a group at some school that studied them and was able to defeat 75% or 80% using basic OCR algorithms, and iirc they got up to 90% once they started tuning them for their specific project.


I'd have to call BS on this. I've heard about this "report" from a variety of people. If it's true, then why do high traffic sites still use CAPTCHAs?

I actually researched this myself a few months back. I got a couple of OCR programs and tested them against various CAPTCHA images. I found that even slight distortion of letters caused most of the OCRs to crap out (This wasn't even using different fonts than Arial), the more stubborn OCRs were completely defeated by adding a little bit of noise and a bit more distortion, although they still had one or two letters wrong with the "weaker" CAPTCHAs.....

Remember, to mess up an OCR algorithm with a CAPTCHA, it only needs to read a single letter wrong. It's all or nothing when reading the CAPTCHA...

In additions, most of these OCR methods are rather time consuming. I mean, just messing with them yourself isn't, but let's say you had a 1% success rate. You would have to run 100 cycles of the algo just to get one account....
Extrarius
Extrarius
Quote:
Original post by curtmax_0
Quote:
Original post by Extrarius
As far as captchas, there was a group at some school that studied them and was able to defeat 75% or 80% using basic OCR algorithms, and iirc they got up to 90% once they started tuning them for their specific project.


I'd have to call BS on this. I've heard about this "report" from a variety of people. If it's true, then why do high traffic sites still use CAPTCHAs?[...]
Spammers aren't into academic things like image recognition technology when there are easier ways to get around that kind of thing (use other systems that aren't protected, or just trick people into decyphering them for you). Basically, those that could defeat CAPTCHAs aren't interested in doing so outside of academia.
Quote:
[...]I actually researched this myself a few months back. I got a couple of OCR programs and tested them against various CAPTCHA images. I found that even slight distortion of letters caused most of the OCRs to crap out (This wasn't even using different fonts than Arial), the more stubborn OCRs were completely defeated by adding a little bit of noise and a bit more distortion, although they still had one or two letters wrong with the "weaker" CAPTCHAs.....

Remember, to mess up an OCR algorithm with a CAPTCHA, it only needs to read a single letter wrong. It's all or nothing when reading the CAPTCHA...[...]
The problem is you're using general OCR software intended to read perfectly formed letters from printed material and not custom designed software that was built to deal with CAPTCHAs using the latest in image recognition algorithms. Also, remeber that even a 1% success rate means billions of billions of spam because it only take 1 account to spam a ton and there are hundreds of thousands (if not more) zombie machines out there that spammers can use to continually bombard everything.
Quote:
[...]In additions, most of these OCR methods are rather time consuming. I mean, just messing with them yourself isn't, but let's say you had a 1% success rate. You would have to run 100 cycles of the algo just to get one account....
Sure, consumer software isn't designed to defeat CAPTCHAs. That is a good thing, but it doesn't mean they can't be easily defeated with well-known algorithms. Even if it takes 1 hour to run the algorithm per attempt and your success rate is only 1%, it's only using extra cpu cycles on slave machine and it is bringing in essentially "free" money. SPAM doesn't exactly have a great return rate as it is, so they're used to those kind of ratios.
"Walk not the trodden path, for it has borne it's burden." -John, Flying Monk
d000hg
d000hg
I'm sure software could read even the harder distorted image text, using learning techniques & pattern recognition. But it would be a hard thing to do, and there are so many easier options at the moment.
Arek the Absolute
Arek the Absolute
A New CAPTCHA Approach

Thank you, XKCD.
-Arek the Absolute"The full quartet is pirates, ninjas, zombies, and robots. Create a game which involves all four, and you risk being blinded by the sheer level of coolness involved." - Superpig
Avatar God
Avatar God
I'm just glad you included the alt= text. [grin]

gsgraham.comSo, no, zebras are not causing hurricanes.

Topic Locked

This topic has been locked by a moderator. New replies are not allowed.

Sign in to reply to this topic.