phpBB

Development Discussion Board

phpBB's testing ground of bleeding edge code
Advanced search

SPAMBOTS - how can we stop them - read FIRST post.

Temporary forum to obtain support while phpBB.com is offline.
Please use the support forum on phpBB.com
Forum rules
Temporary forum to obtain support while phpBB.com is offline.
Please use the support forum on phpBB.com

Re: SPAM registrations after upgrading to 3.0.4

Postby COD3M4ST3R-X » Wed Feb 04, 2009 7:53 pm

marcusbacus wrote:As some said could it have anything to do with the phpbb.com attacks? I also found that this new captcha was already broken too.

its just a rumour. There is no such vulnerability in PhpBB3.
I know say lots of sites using Phpbb3 and big ones none have this issue.
The attack was a total separate issue from PhpBB as it was related to a third party script that caused this issue.Kindly read the discussion topic on this issue in the discussion forum.
Last edited by camm15h on Wed Feb 04, 2009 8:10 pm, edited 1 time in total.
Reason: Edited slightly to avoid misleading.
Image
Long Live PhpBB!
User avatar
COD3M4ST3R-X
Registered User
 
Posts: 228
Joined: Wed Nov 05, 2008 7:52 am
Location: Lahore,Pakistan

Re: SPAM registrations after upgrading to 3.0.4

Postby trixom » Thu Feb 05, 2009 9:54 am

Hello,

I have installed the MOD, but I am still getting SPAM registrations. I followed the instructions but it does not look like
it works (I copied all the files and ran the install .php, I can see the .MOD tab with the settings). I have also tried
registering myself with known SPAM usernames and e-mail addresses and they all get through.

Further more I have lowered the fuzzieness of the CAPTCHA but again this is no help. I can hardly read the CAPTCHA
and I find it hard to believe a BOT could get through...

Regards,

T.
trixom
Registered User
 
Posts: 3
Joined: Wed Feb 04, 2009 11:58 am

Re: SPAM registrations after upgrading to 3.0.4

Postby mixstar » Thu Feb 05, 2009 10:29 am

Hmm, very strange, I never get any spam but then again my site is small.

  1. Is there a pattern to what sites get affected?
  2. Is it a particular sort of site?
  3. Is it a forum on it's own?
  4. Is it a website + forum?
  5. Have you got commercial advertising?
etc.

I just wonder why certain people get spammed and others don't?

Maybe if between you you could compile a list of affected sites and how those sites operate we may get a better picture of the causes?

A poll on the question may suffice but the right questions need asking in the first place.
User avatar
mixstar
Support Team
Support Team
 
Posts: 27
Joined: Thu Feb 05, 2009 7:51 am
Location: The Cogan Triangle

Re: SPAM registrations after upgrading to 3.0.4

Postby ChrisRLG » Thu Feb 05, 2009 10:36 am

baxterdown wrote:
ric323 wrote:Have you tried custom fields?


Yes I did, but I couldn't get it to do what I want. I would like to make a text field where the person registering has to enter a security code (string of characters like abc1234) I provide to them in advance. I tried creating a "Single text field" but that didn't work. I couldn't find where to enter the string... Am I doing it wrong?


That method with a code using the custom profile fields only works with numbers, not alpha.
User avatar
ChrisRLG
Registered User
 
Posts: 160
Joined: Wed Oct 11, 2006 9:47 am

Re: SPAM registrations after upgrading to 3.0.4

Postby luchtzak » Thu Feb 05, 2009 10:52 am

Why no AKISMET integration in a standard phpbb version ? Last days I have received 100's of spam accounts new registrations!

www.wordpress.org uses AKISMET already for a few years now with great succes!
luchtzak
Registered User
 
Posts: 12
Joined: Thu Feb 10, 2005 12:29 am

Re: SPAMBOTS - how can we stop them - read FIRST post.

Postby 3Di » Thu Feb 05, 2009 11:36 am

I noticed a spambot registration at my board today, I also noticed that spambot used 'timezone -12' that's a nautical time zone comprising the high seas between 180° and 172°30′W longitude, no human habitations are in this time zone hence no IPs, AFAIK.

There is a phpBB2 MOD I don't recall the name though that's used the same way to stop those spambots.
That code I implemented it years ago also in my 'IP Country Flag MOD for phpBB2' that I use at my phpBB2 demo-board, no spambots there since ages.

That's why I wrote the same for phpBB3, you can find it here: http://gold.io3di.com/viewtopic.php?f=8&t=94 .. at my phpbb3 demo-board, later on today I will put it also there into my board's files, I'm too lazy to do that immediately.

Tested on phpbb 3.0.4 localhost, though.

Regards.
Give Peace A Chance.. Pass ON It! ° phpBB wiki in Italiano ° Ich bin ein Berliner
Image
User avatar
3Di
 
Posts: 467
Joined: Tue Nov 01, 2005 9:50 pm
Location: Berlin - Milan

Re: SPAMBOTS - how can we stop them - read FIRST post.

Postby CTCNetwork » Thu Feb 05, 2009 11:53 am

Hi,

Another problem I thing will be that with many of these spam registrations, they don't post. They don't even log back into the forum once registration has been completed.
They are just filling up the member list with dead wood.

Des. . . ;)
Density:- Not just a measurement~Its a whole way of Life.! ! !
Uninvited PM's are Deleted. Uninvited IM's - You get a warning - and get blocked. Capiche?
User avatar
CTCNetwork
Registered User
 
Posts: 65
Joined: Thu Mar 18, 2004 9:41 pm
Location: Nottingham

Re: SPAMBOTS - how can we stop them - read FIRST post.

Postby ClabbeW » Thu Feb 05, 2009 11:57 am

Guys !

Kind of a newbee - running the 3.0.4 - have started to get the same problems with spammers just the last couple of days (as most others it seems).

Anyhow have followed instructions in this page:
Knowledge Base - Custom Profile Fields as an Anti-Spammer Tool

BUT - when I've saved these custom profile fields it still doesn't appear in my registration page ?!?!
OK - I use the 'black pearl' style, but as these would be 'custom profile fields' (one dropdown box + one numbers choice) in the phpBB original setup, I expect that wouldn't be a problem no matter which style you my use ?! Right ?!
Do I have to "activate" these changes some way - because through the instructions you can't tell ?? In them it seems you're done after you've saved your changes...

Please advise - thanks !!
ClabbeW
Registered User
 
Posts: 8
Joined: Thu Feb 05, 2009 8:30 am

Re: SPAMBOTS - how can we stop them - read FIRST post.

Postby 3Di » Thu Feb 05, 2009 11:59 am

CTCNetwork wrote:Hi,

Another problem I thing will be that with many of these spam registrations, they don't post. They don't even log back into the forum once registration has been completed.
They are just filling up the member list with dead wood.

They do log back in order to be activated hence listed into the memberlist. They also full fill the profile fields. I de-activated that spambot now via ACP, in order to see what happens and take care of that in case. The MOD I above linked it's just a start, I'm considering to strongly improve it if I will get some feedback.

Regards.
Give Peace A Chance.. Pass ON It! ° phpBB wiki in Italiano ° Ich bin ein Berliner
Image
User avatar
3Di
 
Posts: 467
Joined: Tue Nov 01, 2005 9:50 pm
Location: Berlin - Milan

Re: SPAMBOTS - how can we stop them - read FIRST post.

Postby CTCNetwork » Thu Feb 05, 2009 12:02 pm

Hi,
3Di wrote:
CTCNetwork wrote:Hi,

Another problem I thing will be that with many of these spam registrations, they don't post. They don't even log back into the forum once registration has been completed.
They are just filling up the member list with dead wood.

They do log back in order to be activated hence listed into the memberlist. They also full fill the profile fields. I de-activated that spambot now via ACP, in order to see what happens and take care of that in case. The MOD I above linked it's just a start, I'm considering to strongly improve it if I will get some feedback.

Regards.

Not for me, as I currently have admin activation set to on. But even accounts that I have activated never a login or visit.

However, a useful tool may be the Stop Forum Spam site and its database of known spammers:
Stop Forum Spam..
You need to register to get an API but you can then submit your forums spammer details to the database.

Worth considering, perhaps.

Des. . . ;)
Density:- Not just a measurement~Its a whole way of Life.! ! !
Uninvited PM's are Deleted. Uninvited IM's - You get a warning - and get blocked. Capiche?
User avatar
CTCNetwork
Registered User
 
Posts: 65
Joined: Thu Mar 18, 2004 9:41 pm
Location: Nottingham

Previous Next

Return to phpBB 3.0.x Support

Who is online

Users browsing this forum: No registered users and 10 guests