AutoPligg Spam Tool: Pligg Spam Just Got A Whole Lot Worse

AutoPligg Spam Tool: Pligg Spam Just Got A Whole Lot WorseIf you have read any of our previous articles on Pligg Spam you will no doubt already be aware that Pligg has had more than it’s fair share of spam related problems in the past. Pligg webmasters now face a potentially devastating new threat in the guise of an fully automated Pligg Submission and Voting Spam Tool titled AutoPligg from syndk8.net. Whether you currently own or are simply pondering starting your very own pligg website you will want to read this article.

On the 23rd July the Pligg Demo website was hit with a new type of spam attack originating from a tool titled AutoPligg, AutoPligg automatically creates multiple user accounts, submits stories and then even votes upon those submitted stories from the multiple pligg accounts that it created. This is really bad as by voting upon the stories that AutoPligg submits to you pligg site AutoPligg also effectively promotes those spam entries to the main pligg homepage.

As you can see this tool is a nightmare for any pligg webmaster to defend against. with pligg failing to effectively deal with simpler forms of spam than AutoPligg this particular tool could cause a lot of problems for pligg site owners.

Below is how AutoPligg describes it’s product.

Register unlimited accounts, post as much stories as you want and even leave comments on those sites.

  • High quality 1 way links to your website
  • Automatically register for accounts. Even breaks CAPTCHAs!!
  • Create UNLIMITED profiles and indentities
  • Submit stories and comment to 1000’s of sites
  • Automated pinging after each submission
  • Stats to show succesful submissions
  • Proxy support
  • Increase your page ranking
  • Tag friendly
  • Flexible features
  • FREE lifetime upgrades
  • Access to the private forum
  • Get indexed in less than 24 hours flat! (google)
  • Get indexed in less than 48 hours flat! (yahoo)

Some of the more worrying features are Proxy support and Create UNLIMITED profiles and indentities.

We decided to digg a little deeper into AutoPligg.

The user name used for the attack at Pligg.com was “whadu” and searching google for “pligg whadu” returned some interesting results, whadu has been a busy bot.

We found a pligg site titled http://newstime.ro that has been hit by AutoPligg using the whadu user name, and as you will see the potential threat it poses to pligg webmasters is huge.

NewsTime Wahdu Profile Page http://newstime.ro/user.php?login=whadu

Home Page Of NewsTime http://newstime.ro/

120 submitted links 109 published.

NewsTime Fake Automated Voters

http://www.newstime.ro/story.php?title=Gears_of_War_2_GDC_Unreal_Tech_demo

You will notice that all stories on NewsTime have the same fake voters to gain promotion to the published section.

One pligg user pingskie has made a post in the pligg forums requesting a solution on how to block this tool, as yet their has been no reply you can read pingskie’s post here. It’s worth noting though that there is currently no solution to combat the AutoPligg tool at the moment, none of the available modules at pligg will work to defend your site as will none of the available hacks.

Due to an image (Shown Below) on the AutoPligg website we would strongly advise that you remove the “Powered By Pligg” text from the footer of your template, this is one of the methods described by AutoPLigg as to how to find Pligg sites with Google.

With the pligg project’s lack of development problems and general disarray this is the last type tool that they wanted or needed to see released, as for pligg users it’s just another thorn in the side that’s will most probably cause a vast majority of users problems at some point. If you like this article why not bookmark, share or digg it to let other pligg webmasters know about the existence of such a harmful tool.

The AutoPligg site has some videos available of the spam tool in action that you may want to watch.

Visit:
AutoPligg

Big thanks to graphicsguru of FoxieWire for the tip off on this tool.

Update: Pligg users are reporting  that using reCaptcha may stop this threat but this still theory, without confirmation though we cannot say 100% whether reCpatcha will stop an AutoPligg attack we really hope it does. It would be advisable to enable reCaptcha as it’s a better option than the standard pligg captcha to begin with. It’s also worth noting however that reCpatcha is breakable in the past it was with the use of a perl based script, reCaptcha like an captcha based confirmation is not bulletproof although it is better than most.

If you enjoyed this post, make sure you subscribe to our RSS feed!

Article Details

#

Author: Lincoln on July 28th, 2008

Category: Pligg

Tags: , , , ,

  1. bbrian017 says:

    This is insane and scary at the same time!

    I have personally experienced this and it was written about here as well!

    They are really good and even get passed e-mail confirmation I seen it!

  2. sahil says:

    and were is rapid download link

    please give us this software for free …. :D

  3. Sick of Pligg says:

    Well Pligg is just a total waste of time and a spammer paradise. It is totally worthless form an admin stand point since you have no way to delete users, ban users, ban IP’s or require new posts to be approved before posting. One can only believe that Pligg is condoning this type of scripting. We, the end users and admins, have to show Pligg enough is enough and stop using this script since it poses so many security risks and promotes spammers to have a free reign on your web site at YOUR expense!

    So if you use Pligg, then you need to put down the crack pipe and wake up! It is a worthless program until this crap is fixed.

  4. Brian says:

    Well stop using Pligg then, either way, stop complaining. You don’t have to use it.

  5. All4Data says:

    I use the Pligg setup and I am always supportive of those who put their time into developing a software package for free and as open source.

    With my Pligg site I simply took away the ability to register on the site as the only true way I could cope with all the SPAM, it is not ideal as it defeats the purpose of the product.

    I am now taking a look at SWCMS, also a product that Lincoln promotes.

    I am not sure about the bad vibes between the 2 sets of developers however it does seem evident.

  6. Howto says:

    Pligg is opensource, you can change the captcha thing yourself :)

  7. ino says:

    Im not happy with pligg so far. I have been a spam target :( even with recaptcha

  1. Vote for this article at blogengage.com
  2. Need Help! how to block Auto Pligg submission from Syndk8 - Pligg Forum
  3. bloggingzoom.com
  4. Premiera AutoPligga | Wordpress SEO, pozycjonowanie i optymalizacja
  5. pligg.com
  6. newstube.de
  7. NetFxCafe » Blog Archive » AutoPligg Spam Tool - Pligg Spam Information
  8. www.entirelyopensource.com
  9. AutoPligg: Behind The Scenes Of The Pligg Spam Tool | Social CMS Buzz
  10. AutoPligg claims it can spam thousands of sites using the Pligg CMS — TechDugout
  11. Klubowicz.com » Blog Archive » Premiera AutoPligga
  12. BlogEngage Demonstrates Why Autopligg Is Bad And Enabling ReCaptcha Is Essential | Social CMS Buzz
  13. Bookmarking Deamon Claims It’s A Pligg Auto Submission Tool | Social CMS Buzz

Leave a Reply