The Nexus Forums: Security changes, limits on downloads per file and other tidbits - The Nexus Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Security changes, limits on downloads per file and other tidbits Official comment topic

#1 User is offline   Dark0ne 

  • Webmaster
  • Icon
  • Group: Admin
  • Posts: 9,248
  • Joined: 15-July 03

Posted 12 February 2008 - 11:18 PM

The past few days have been a bit of a fixer session for me on the site. Here's a quick run-down of the fixes that didn't make the news until now because they were a little small:
  • Ordering files by rating will now recognise files with a rating of 10, and order them by their total ratings too, so files with the same rating will be ordered by the number of ratings they have
  • Morrowind mods are now properly recognised on the Updates Recently log
  • A fix was applied to stop duplicate entries for the same file appearing on the Updates Today page
  • A fix was applied to the "Give editing access to other members" feature on the "Edit File" page that allows you to give editing access to a single other member on the site
  • There is now a new section under your uploaded files for files that you have editing access to, as governed by the "Give editing access to other members" feature on specific files


If you find a bug on this site or you believe a feature is not working as intended please use the feedback forum to make it known. I cannot fix a problem if I do not know about it!

Buddah brought my attention to another problem on the site that requires a mention. There are a few files on this site that have come victim to the nasty site bots from Russia and China. These are nasty bitches that deliberate autonomously spam the site in order to leech its bandwidth in an attempt to bring the site down. You can recognise such files by checking the total downloads counter against the total views counter; if the downloads are greatly higher than the views then a bot has been trying to get its way with the site via this file.

This is not the uploaders fault and steps are being taken to identify the files that have unrealistic download counters and to try and provide a more accurate reading.

In response to this issue I have tightened security on the site and added a few flood control features to the downloading code. A limit of 50 downloads has been placed on files so that members and guests can only download a single file a maximum of 50 times before they are blocked from downloading. Similarly members logged as hitting this limit are automatically moved to a seperate member group, "Suspects", so I can further monitor their activity.

Around 10:30pm GMT security checks on the login cookies were placed on all pages of the site, consolidating the site security. Some members might have been a bit scared when redirected to a "You've been banned" page. I apologise for this, the blurb was misleading and has since been changed.

These changes should help further the accuracy of stats, the prevention of bandwidth leeches and aggressive bots, and the security of the site.
0

#2 User is offline   dikr 

  • Regular
  • PipPip
  • Group: Members
  • Posts: 70
  • Joined: 10-September 07

Posted 13 February 2008 - 12:16 AM

Sad to hear people are actually making an effort to try and bring this portal down,.. you'd think they'd have some better things to do. At least one reckons there should be more 'justifiable' targets to hit than a free spirited modding community like ours :-/
0

#3 User is offline   batlham 

  • Addict
  • PipPipPip
  • Group: Members
  • Posts: 272
  • Joined: 27-June 06

Posted 13 February 2008 - 01:13 AM

yea..good show man.

One of my files were hit..and it went up like a skyrocket on counts.
Lucky I saw it as it was happening so it could be stopped.
0

#4 User is offline   buddah 

  • Official Old Fart
  • Icon
  • Group: Admin
  • Posts: 5,345
  • Joined: 21-February 05

Posted 13 February 2008 - 02:13 AM

Please don't check my download stats, I will be banned immediately ! ! ! ! !

Seriously, the report functions are an early warning system: If something doesn't seem to be operating/recording properly let us know....these attacks that leach bandwidth increase the costs of keeping the site operational.

When and if you use the report function, please include some comment indicating the problem or area of concern you are reporting as it gives us a place to start.

All reports are taken seriously and are dealt with as quickly as possible, most are dealt with by the moderators within our abilities, but the site problems are dealt with by Dark0ne. Your efforts as an active member of the community are greatly appreciated. Collectively you see everything good and bad on the site, so your input is quite important to keep this mad house running as effectively as possible, keep those reports coming in so as a community we can make Nexus a pleasant experience for everyone.

Thanks for your help.

Buddah
0

#5 User is offline   yearg 

  • Journeyman
  • Pip
  • Group: Members
  • Posts: 43
  • Joined: 18-December 06

Posted 13 February 2008 - 03:15 AM

one thing, who the heck would download a file more than 50 times except for those bots?
0

#6 User is offline   Ra) 

  • Regular
  • PipPip
  • Group: Members
  • Posts: 97
  • Joined: 30-May 06

Posted 13 February 2008 - 07:03 AM

Long live TesNexus! Hooray! Best Elder Scrolls site ever! :)
Thanks a lot, DarkOne.

-Dume
0

#7 User is offline   Sage Rime 

  • Addict
  • PipPipPip
  • Group: Members
  • Posts: 286
  • Joined: 22-April 06

Posted 14 February 2008 - 05:03 AM

Nice to see this was manageable.

I really started to doubt some files after I saw the +80,000 downloads and 14,000 views.

I guess I was right to report them this time, instead of just being paranoid. :D

Sage Rime
0

#8 User is offline   worm82075 

  • Proud Proliferater Of The BGMC
  • Icon
  • Group: Premium Member
  • Posts: 578
  • Joined: 09-February 06

Posted 14 February 2008 - 06:09 AM

I have noticed a lot of other little tweaks and changes to the site in the last week or so. For example the upload progress meter made it all the way up to 180-190 mb of a 250 mb file before it gave out, thats a big improvement. Your are ever vigilant and oh so diligent and I thank you for all your hard work. I can think of only one way to show my gratitude and express my hope that TES NEXUS is still the best ES site on the web when TES X arrives in oh say 2020. That would be to purchase a lifetime membership. In 2-3 days when PayPal clears I will properly show my gratitude by spending a mere 39.99UK/77.58US. The price of a two year membership? That's insane. If you asked me for another 80 bucks in two YEARS I would probably give it to you. And incidentally if this site were ever to get in trouble I for one would definitely give to an emergency member funds drive.

Praise be to the Dark0ne
Long live TES Nexus
0

#9 User is offline   KevinDAmery 

  • Regular
  • PipPip
  • Group: Members
  • Posts: 70
  • Joined: 18-June 06

Posted 15 February 2008 - 12:40 AM

Just had a thought regarding stopping the bots: maybe instead of (or in addition to) limiting the total number of downloads for one file, you could limit the number of times an account can download the same file per day. My thinking is that some modders update their mods regularly, and if they don't change the file name then legitimate users may eventually hit the 50 DL limit--but there's no way anyone would attempt to DL the same file more than a couple of times in one day (assume that maybe their browser barfs so the first DL attempt fails, so they try again... but they aren't going to do that too many times.)
0

#10 User is offline   Galahaut 

  • Addict
  • PipPipPip
  • Group: Members
  • Posts: 396
  • Joined: 16-February 05

Posted 15 February 2008 - 01:42 AM

Edit: Oops, misread that.
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users


Skin by Skinbox
Quality & cheap IPB skins, premade vBulletin styles, cheap Web templates and more! - Skinbox