TimeLordME, Iran and the Feds

Cosmo

Owner
Staff member
Hey guys,

In this. thread, there was a lot of random shitposting that didn't make much sense:

Vi-Alpha and AsinShouma seem to share an IP. TimeLordME decided these were terrorist plotting an attack, but reported his OWN posts instead of anything helpful.

I took a look at the thread yesterday and none of it made sense. Sounded like 2 bots talking to each other, or at least people who have no idea about English. Out of cution, I marked Vi-Alpha as a spammer which hid his threads and posts. Left AsinShouma alone to see hat they did.

TimeLordMe began blowing up my wife on Facebook and me through the contact form, saying they were a federal agent and all kind of other nonsense. Started blowing me up via PM this morning asking why I was hiding evidence and to delete their account, so I did.

After that, I received more contact forms through the site:

View attachment 380

I've since banned their primary IP. They were able to continue using the contact form, so I've set that as usable by registered members only.

Shortly after, AsinShouma asked me what happened. I gave them a short version but am now suspicious of t his account as well.

Through CloudFlare, I've blocked the following countries:

  • China
     
  • Iran
     
  • Tor (not a country, but it's considered one for the purposes of blocking)
     


Right after that, AsinShouma sent me a PM asking why I blocked their IP. This time their IP was from India.

Please keep an eye on this person and let me know if anything turns into more drama. This is a site to escape bullshit, not revel in it.

370595238_ScreenShot2020-08-10at6_45_53AM.png.b1183d0c873afe0c16a0734755b71d6e.webp

 
They replied with something along the lines of they are using the same proxy service or something, then a lot of other broken English messages about how Vi Alpha will be forgotten and other nonsense. 

Considering blocking some more countries.

 
I think it's just non-english speaking people thinking they're being more clever than they actually are. More annoying and noisy than anything else. I have Iran and China blocked, considering India, Russia and the "-stan" countries as well. I'll see how things go and figure out what to do.

 
TimeLordME tried re-registering under the username "angry fed" and posted some link to a US code pertaining to providing aid and comfort to terrorists. He canceled the registration but I still saw the attempted post. Dude is a moron, but actually seems to work for the Social Security Administration (he sent Hallie a picture of his ID or something on Facebook and saw one of his IPs resolving to one of their networks [ssa.gov]).

Nice to know we have a bunch of schizos running that department. This dude is from Ohio, and I'm banning every IP I see associated with him at the DNS level. I can see metrics on these bans and he's already tried accessing the site from the 2 IPs I've banned 20+ times.

I've also banned Tor, Iran, Pakistan, China, Hong Kong, Libya, Iraq, Venezuela and a couple others.

 
[QUOTE='Cosmo1598825723]TimeLordME tried re-registering under the username "angry fed" and posted some link to a US code pertaining to providing aid and comfort to terrorists. He canceled the registration but I still saw the attempted post. Dude is a moron, but actually seems to work for the Social Security Administration (he sent Hallie a picture of his ID or something on Facebook and saw one of his IPs resolving to one of their networks [ssa.gov]).
Nice to know we have a bunch of schizos running that department. This dude is from Ohio, and I'm banning every IP I see associated with him at the DNS level. I can see metrics on these bans and he's already tried accessing the site from the 2 IPs I've banned 20+ times.

I've also banned Tor, Iran, Pakistan, China, Hong Kong, Libya, Iraq, Venezuela and a couple others.
[/QUOTE]OK, thanks for letting us know!

 
I used TOR three times, was blocked once, got in through TOR twice.   Don't know if system recorded the IP's.   185.220.101.205  and 5.199.130.188   .  Deja Vu, feel like this kind of thing happened before....

 
Last edited by a moderator:
Holy smokes !  Is that normal?  Got to say looks like China wins for the most attempts.   Trophy ? Oh wait, seeds, send China as a consolation prize a mysterious pack of unidentified seeds.  (poison ivy)

 
Last edited by a moderator:
Yeah, some TOR endpoints don't register the "country code" (T1) which is what the firewall rule looks for. It's not perfect, but it catches enough of them to frustrate your average asshole.

 
Ichtion's IP says s/he is posting from Luxembourg.  Suspect he's using TOR.  ( see circuit in previous post ).   Pretty easy to change identities.   Just click on the little broom and bazinga, new circuit is created instantly.   If you trace the IP showing for this post, does it show as static or suspected proxy?

 
'KerrTexas]Ichtion's IP says s/he is posting from Luxembourg.  Suspect he's using TOR.  ( see circuit in previous post ).   Pretty easy to change identities.   Just click on the little broom and bazinga said:
https://db-ip.com/2a0b:f4c2:1::[/URL]

I think how you're getting past the T1 block is something like this:

https://blog.torproject.org/breaking-through-censorship-barriers-even-when-tor-blocked

To the best of my understanding, it's not possible to block ALL proxy IPs without an authoritative list to go by (which would be a lot of work to keep updated).

I'm okay with being able to get past the Tor block the way you showed as there's some legitimate reasons to want to hold on to your anonymity, The main goal is just to put a cork in the obvious bad traffic and make it a little more frustrating if your intent is to be an asshole.

Like China.

I'm sure I'll need to make other adjustments as the Vi-Alphas and TimeLordMEs of the world start to show their ass.
 
[QUOTE='Cosmo1598825723]Mein Name ist Ananas und ich hatte gerne ein Stuck Apfelsenf.
[/QUOTE]Apfelsenf? Lecker ! Wie ware es mit Apfelstrudel Herr Ananas?  Du, Du hast...

 
Top