AutoPligg Spam Tool: Pligg Spam Just Got A Whole Lot Worse

AutoPligg Spam Tool: Pligg Spam Just Got A Whole Lot WorseIf you have read any of our previous articles on Pligg Spam you will no doubt already be aware that Pligg has had more than it’s fair share of spam related problems in the past. Pligg webmasters now face a potentially devastating new threat in the guise of an fully automated Pligg Submission and Voting Spam Tool titled AutoPligg from syndk8.net. Whether you currently own or are simply pondering starting your very own pligg website you will want to read this article.

On the 23rd July the Pligg Demo website was hit with a new type of spam attack originating from a tool titled AutoPligg, AutoPligg automatically creates multiple user accounts, submits stories and then even votes upon those submitted stories from the multiple pligg accounts that it created. This is really bad as by voting upon the stories that AutoPligg submits to you pligg site AutoPligg also effectively promotes those spam entries to the main pligg homepage.

As you can see this tool is a nightmare for any pligg webmaster to defend against. with pligg failing to effectively deal with simpler forms of spam than AutoPligg this particular tool could cause a lot of problems for pligg site owners.

Below is how AutoPligg describes it’s product.

Register unlimited accounts, post as much stories as you want and even leave comments on those sites.

  • High quality 1 way links to your website
  • Automatically register for accounts. Even breaks CAPTCHAs!!
  • Create UNLIMITED profiles and indentities
  • Submit stories and comment to 1000′s of sites
  • Automated pinging after each submission
  • Stats to show succesful submissions
  • Proxy support
  • Increase your page ranking
  • Tag friendly
  • Flexible features
  • FREE lifetime upgrades
  • Access to the private forum
  • Get indexed in less than 24 hours flat! (google)
  • Get indexed in less than 48 hours flat! (yahoo)

Some of the more worrying features are Proxy support and Create UNLIMITED profiles and indentities.

We decided to digg a little deeper into AutoPligg.

The user name used for the attack at Pligg.com was “whadu” and searching google for “pligg whadu” returned some interesting results, whadu has been a busy bot.

We found a pligg site titled http://newstime.ro that has been hit by AutoPligg using the whadu user name, and as you will see the potential threat it poses to pligg webmasters is huge.

NewsTime Wahdu Profile Page http://newstime.ro/user.php?login=whadu

Home Page Of NewsTime http://newstime.ro/

120 submitted links 109 published.

NewsTime Fake Automated Voters

http://www.newstime.ro/story.php?title=Gears_of_War_2_GDC_Unreal_Tech_demo

You will notice that all stories on NewsTime have the same fake voters to gain promotion to the published section.

One pligg user pingskie has made a post in the pligg forums requesting a solution on how to block this tool, as yet their has been no reply you can read pingskie’s post here. It’s worth noting though that there is currently no solution to combat the AutoPligg tool at the moment, none of the available modules at pligg will work to defend your site as will none of the available hacks.

Due to an image (Shown Below) on the AutoPligg website we would strongly advise that you remove the “Powered By Pligg” text from the footer of your template, this is one of the methods described by AutoPLigg as to how to find Pligg sites with Google.

With the pligg project’s lack of development problems and general disarray this is the last type tool that they wanted or needed to see released, as for pligg users it’s just another thorn in the side that’s will most probably cause a vast majority of users problems at some point. If you like this article why not bookmark, share or digg it to let other pligg webmasters know about the existence of such a harmful tool.

The AutoPligg site has some videos available of the spam tool in action that you may want to watch.

Visit:
AutoPligg

Big thanks to graphicsguru of FoxieWire for the tip off on this tool.

Update: Pligg users are reporting  that using reCaptcha may stop this threat but this still theory, without confirmation though we cannot say 100% whether reCpatcha will stop an AutoPligg attack we really hope it does. It would be advisable to enable reCaptcha as it’s a better option than the standard pligg captcha to begin with. It’s also worth noting however that reCpatcha is breakable in the past it was with the use of a perl based script, reCaptcha like an captcha based confirmation is not bulletproof although it is better than most.

If you enjoyed this post, make sure you subscribe to my RSS feed!

Article Details

#

Author: on July 28th, 2008

Category: Pligg

Tags: , , , ,

  1. John says:

    More sensational headlines from socialCMScrap. reCAPTCHA comes with Pligg by default, if you are not using it then you are an idiot, and probably shouldn’t’ be running a website anyway. New types of spam attacks happen on a daily basis through out the web, this is nothing new. Blaming the Pligg developers for someone else’s stupidity is really lame. The AutoPligg site says it was released just a few days ago. Pligg has even confirmed they have a patch they are going to release for those wern’t smart enough to upgrade to their latest version so I suggest you edit your article to reflect the truth.

  2. Catchpen says:

    Go troll on your own forum since that’s the only way you don’t get banned from it. Your way of words sound uselessly familiar.

  3. raatenstaat says:

    if you’re to stupid to block such things by activating recaptcha, you better shut down your site. this is no troll crap, this is reality.

  4. PliggNZ says:

    There’s a report that AutoPligg needs the “God” user account with default password to do those things. If it’s true then you can simply block it by changing your default “God” password.

    @Lincoln
    You should have bought and tried the software first before making your post. Or if it’s your own software, then you should have tested it fully before making such crap.

  5. I have been looking into this tool and it dosent use the god password.

    It just posts to pligs like a normal user.

    The coding in it is good but it looks like the guy who wrote it made it work slowly rather than hit the sites too fast.

    A better capture will fix this because the professional seos in those sites dont want to hit live sites.

    If this makes pligg better and someone actually continues the development we have a lot to thank these toolshed guys for.

    Sometimes we need a small slap to wake us up and stop us getting lazy.

  6. Pligg Super Fan says:

    I didnt see the problem there, the example story was a legit story. I saw some increase in my pligg powered sites, but nothing spammy, normal stories. If the stories are not spam, i really don’t understand what the problem is.

  7. Seth says:

    I can 100% confirm this tool does not require a god account like was suggested, PliggNZ maybe you should buy the software then at least you wouldn’t have to post weak reports and simple suggestions with no factual or practical basis. Either get the facts straight and do your own research or reserve your comments for inside your own skull where they would probably be most appreciated.

    You also say reCaptcha cannot be broken search google ;) , even if reCpatcha was 100% secure it wouldn’t matter as you can bypass the entire pligg registration process by using a pyCurl script ;)

  8. I think the recaptcha will not work for long. If they can break the first one there going to be breaking them all.

    What pligg owners should be thinking about is a way to get the owners of this tool to raise there price a lot more then it is. 189 is cheap for what it can do so what needs to be done is it put out of reach for the average person. Reducing the amount of spam your getting may be the best thing.

  9. vorax says:

    i just and to my .htaccess

    deny from 93.103.6.86
    deny from 85.242.224.75
    deny from 202.156.11.5
    deny from 203.150.228.110
    deny from 96.9.131.37
    deny from 75.126.17.170
    deny from 202.156.10.13
    deny from 67.18.18.82
    deny from 78.129.168.58
    deny from 203.211.130.33
    deny from 67.220.194.34
    deny from 81.193.63.64
    deny from 208.109.181.17
    deny from 72.37.245.134

    rename my submit.php, register
    and end of problem

  10. Duh says:

    You can configure it to use proxies, this won’t work. Only RECAPTCHA works.

    “deny from 93.103.6.86
    deny from 85.242.224.75
    deny from 202.156.11.5
    deny from 203.150.228.110
    deny from 96.9.131.37
    deny from 75.126.17.170
    deny from 202.156.10.13
    deny from 67.18.18.82
    deny from 78.129.168.58
    deny from 203.211.130.33
    deny from 67.220.194.34
    deny from 81.193.63.64
    deny from 208.109.181.17
    deny from 72.37.245.134″

  1. Vote for this article at blogengage.com
  2. Need Help! how to block Auto Pligg submission from Syndk8 - Pligg Forum
  3. bloggingzoom.com
  4. Premiera AutoPligga | Wordpress SEO, pozycjonowanie i optymalizacja
  5. pligg.com
  6. newstube.de
  7. NetFxCafe » Blog Archive » AutoPligg Spam Tool - Pligg Spam Information
  8. www.entirelyopensource.com
  9. AutoPligg: Behind The Scenes Of The Pligg Spam Tool | Social CMS Buzz
  10. AutoPligg claims it can spam thousands of sites using the Pligg CMS — TechDugout
  11. Klubowicz.com » Blog Archive » Premiera AutoPligga
  12. BlogEngage Demonstrates Why Autopligg Is Bad And Enabling ReCaptcha Is Essential | Social CMS Buzz
  13. Bookmarking Deamon Claims It’s A Pligg Auto Submission Tool | Social CMS Buzz

Leave a Reply

You must be logged in to post a comment.