Underlight Discord Chat: http://discord.underlight.com/
Production Server: Online (Version 3.1.15)
Player Test Realm Server: Offline (Version 3.1.15)

Security Changes to Private Messages on Forums

Locked
User avatar
Koi-JorKyrin
System Administrator
Posts: 264
Joined: Sat Feb 01, 2014 6:33 pm

Security Changes to Private Messages on Forums

Post by Koi-JorKyrin »

Good morning,

To address the issue with spamming via forum Private Messages (to your emails from forums system), we have disabled Private Messages to Newly Registered Users. While we have captcha in place (and is never perfect) for actual human beings that register and spam us, it is difficult to block them out. Today we have taken extra steps to block sending of PMs to multiple users and groups. So this will at least make it harder to mass send spam to the UL community through the forums. There are members that will not like this change as they use this feature of the boards, but I believe from a security stand-point, this needs to be disabled and is disabled. Also 'Newly Registered Users' are now no longer able to send PMs, at least until registered (goes through the automated email validation authorization). Once registered, the spammers would only be able to send to one person at a time, and not to mass amounts of members or groups. So this is an improvement, not an elimination of the problem.

The next step is to completely disable private messages, if these mitigations do not work.

Regards,
Koi - Jor'Kyrin
System Administrator
KoiWare, LLC
User avatar
Koi-JorKyrin
System Administrator
Posts: 264
Joined: Sat Feb 01, 2014 6:33 pm

Re: Security Changes to Private Messages on Forums

Post by Koi-JorKyrin »

Also as a side note. For those who report posts, I do take action on them and ban when necessary. So please continue to report any private message and or forums related spam or outside harassment.

-JorK
Koi - Jor'Kyrin
System Administrator
KoiWare, LLC
Locked