Hi all,
there is a massive spamming of google groups ongoing. I received several complains as below. From the domain list it seems that all major Tor exit nodes are affected.
Running an Exit without custom WHOIS, all abuse message are received by my ISP and forwarded. So I have to temporarily ban google groups. How do other operators deal with this?
Regards, Torland
"This is some voluminous, off-topic flooding and harassment on the ba.broadcast Usenet newsgroup. It is being reported to abuse reporting mailboxes based on the contents of the NNTP-Posting-Host: and X-Complaints-To: headers, and lookup of the originating IP address via WHOIS and the Network Abuse Clearinghouse. They are sometimes also crossposted to unrelated newsgroups such as rec.arts.tv, soc.culture.new-zealand, and several other newsgroups in the nz.* hierarchy. It is disruptive, and completely off-topic, as well as causing disruptive, cascaded flame wars among those unrelated newsgroups.
This user has also been posting from other sources, including 100tb.com, 51.net, 62.net, all.de, bahnhof.se, bayern.de, boingboing.net, broadviewnet.net, ccc.de, formlessnetworking.net, hessmo.com, noisetor.net, oceanic.net, plebia.org, privacyrepublic.org, riseup.net, ru.is, sbcglobal.net, servers.com, snydernet.net, solidonetworks.com, stanford.edu, stargrave.org, torland.me, torservers.net, dmzglobal.com, telstraclear.net, xtra.co.nz, clear.net.nz, orcon.net.nz, netgate.net.nz, freeparking.co.nz, powerusenet.com, giganews.com, thundernews.com, altopia.com, comcast.net, groups.google.com, and tigerusenet.com. It appears that you are merely the latest of his victims.
The charter of ba.broadcast is as follows:
"This group is here for discussions, comments and program reminders about broadcast media in the San Francisco Bay Area, both radio and television. It also includes cable systems and TVRO/BCRO in the SF Bay Area. It does not include scanner, ham radio or other action here in the SF Bay Area; these may be addressed in another newsgroup at another time. Issues of national interest should be posted to one of the groups in rec.arts.tv or rec.radio."
(see: http://groups.google.com/group/ba.broadcast/browse_thread/thread/ddfbd8175e2...)
The charter does not include sexual innuendo and libel, abusive threats, bigotry and minority bashing, or any off-topic discussion of subjects not reasonably related to broadcasting in the Bay Area, which now consitute the overwhelming majority of current message traffic on ba.broadcast, to the detriment and exclusion of on-topic participation by others.
Please take appropriate action to put a stop this this misbehavior originating from your site that is disrupting ba.broadcast.
[... Offending article removed ...]
On 07.09.2012 00:15, tor-admin wrote:
Running an Exit without custom WHOIS, all abuse message are received by my ISP and forwarded. So I have to temporarily ban google groups. How do other operators deal with this?
We receive the same reports and answer them like always; now, as they are still coming in, we ignore them.
Thus spake Moritz Bartl (moritz@torservers.net):
On 07.09.2012 00:15, tor-admin wrote:
Running an Exit without custom WHOIS, all abuse message are received by my ISP and forwarded. So I have to temporarily ban google groups. How do other operators deal with this?
We receive the same reports and answer them like always; now, as they are still coming in, we ignore them.
Yes, we even have a template for the Google Groups case on the wiki: https://trac.torproject.org/projects/tor/wiki/doc/TorAbuseTemplates#GoogleGr...
But if the same person keeps sending you the same abuse message as opposed to actually trying to get Google to block the offending authenticated Google account, well that person has spamming issues of their own.
Are Google Groups accounts easier to create than Gmail accounts for some reason? I was under the impression Gmail has hated on account creation over Tor for some time now..
If that is still true, it's likely this new abuser uses both Tor and non-Tor... Thus simply blocking Tor from Usenet (even if we could) as the abuse complaint demands is unlikely to stop the abuse.
tor-relays@lists.torproject.org