Red flag?! Spam attack on multiple xenforo boards if not all

Bram

Well-known member
Licensed customer
Dear @XenForo team

Our boards are currently flooded by old accounts with zero posts all posting spam messages containing this link
Code:
www.bece.com.au

At first i thought this was local problem but visiting other xenforo boards i know i see all of them being receiving a lot of messages with this url.

This might be a wave of spam coming in and they are all avoiding the spam cleaner becuase they are years old accounts.
 
Old accounts do not automatically bypass spam checking measures.

It is possible to configure XF to do that, but it's not something we do by default.
 
They are caught in our approval queue, but i am just posting it here so you guys and other forum owners running Xenforo are aware this happens now in the last hour.
 
Our boards are currently flooded by old accounts with zero posts all posting spam messages containing this link
We found two posts like this, both posted today.

How does this happen? One of the accounts has a legitimate post in the past. Does it mean those accounts are compromised?
 
and they are all avoiding the spam cleaner becuase they are years old accounts.
The spam cleaner can be set up to ignore the user registration date or post count so you can mark anyone as spammer.
1622174052731.webp
if you are affected as well ban this ip: 5.188.84.240
If you mark this user as spammer the IP will be submitted to StopForumSpam if you set up the API key:
1622174032363.webp
 
We found two posts like this, both posted today.

How does this happen? One of the accounts has a legitimate post in the past. Does it mean those accounts are compromised?
An affected user said his account got hacked due to an apple data leak and the force behind it seems to be originating from the Ukrain.

This is why people should stop using the same password for all their accounts as this is the end result.
 
Back
Top Bottom