Page 2 of 2 FirstFirst 12
Results 11 to 18 of 18

Thread: A slight change.

  1. #11
    Administrator
    STMahlberg's Avatar
    Join Date
    November 1st, 2010
    Location
    AREA 51
    Posts
    1,533

    Re: A slight change.

    Quote Originally Posted by Mr. Hankey View Post
    I saw that as well... People try to modify the html path to find unsecured php files or gain other methods to access the site....
    Can you lock out IP addresses?

    I know 2 of the Guests on now are Spammers... I looked up their IP.
    "My god! Do we really suck, or is this guy really that good?" - Mr Hertz - Shoot 'Em Up






  2. #12

    Re: A slight change.

    Quote Originally Posted by STMahlberg View Post
    Can you lock out IP addresses?

    I know 2 of the Guests on now are Spammers... I looked up their IP.
    Yes I can block by IP. In fact when I have noticed a huge number of the fake registrations coming from the same IP ranges I have in fact blocked those large ranges. Unfortunately the IP ranges tend to be everywhere. I wouldn't be surprised if this was being done via a botnet. Some of the ranges I was unable to block because some of our legitimate users fit into the range.

    Thankfully with the moderation setting I can select and delete large numbers of accounts all at once. The sad thing it looks like we are getting 25-50 / day so this will be a never ending process.

  3. #13
    Advisor - Stateside Division
    Bok's Avatar
    Join Date
    October 14th, 2010
    Location
    Wake Forest, NC
    Posts
    1,211

    Re: A slight change.

    On a number of occasions Free-DC will see a botnet attack where I've seen upwards of 300 users (guests) attempting to register at the same time. I get quite a lot of attacks on the stats site too, often with sql injection attempts. Unfortunately it's part of the modern internet. In our forum, I don't delete the users which are spammers but ban them permanently instead, that way their email address and id are at least taken up and can't be re-used

    I can ban IP's on the firewall which is cleaner and faster than the filtering done in the forums, just let me know which ones.

  4. #14
    Past Administrator
    Fire$torm's Avatar
    Join Date
    October 13th, 2010
    Location
    In the Big City
    Posts
    7,938

    Re: A slight change.

    Question. Are these botnet attacks coming from for-profit enterprises like mass marketing and the like? Or are they coming from jackasses that like giving site admins and moderators headaches?


    Future Maker? Teensy 3.6

  5. #15
    Gold Member
    Slicker's Avatar
    Join Date
    October 25th, 2010
    Location
    South of Cheeseland
    Posts
    1,253

    Re: A slight change.

    Quote Originally Posted by Bok View Post
    On a number of occasions Free-DC will see a botnet attack where I've seen upwards of 300 users (guests) attempting to register at the same time. I get quite a lot of attacks on the stats site too, often with sql injection attempts. Unfortunately it's part of the modern internet. In our forum, I don't delete the users which are spammers but ban them permanently instead, that way their email address and id are at least taken up and can't be re-used

    I can ban IP's on the firewall which is cleaner and faster than the filtering done in the forums, just let me know which ones.
    Ever thought of using the scrambled text within images to register? I forget what they call it in BOINC, but it was pretty easy to set up for the Collatz profile editing.
    Spring 2008 Race: (1st Place)

  6. #16
    Advisor - Stateside Division
    Bok's Avatar
    Join Date
    October 14th, 2010
    Location
    Wake Forest, NC
    Posts
    1,211

    Re: A slight change.

    Quote Originally Posted by Slicker View Post
    Ever thought of using the scrambled text within images to register? I forget what they call it in BOINC, but it was pretty easy to set up for the Collatz profile editing.
    We are using that too. It's an option within vBulletin to set Human Verification on and I set it to use Random Font/Size/Slant/Color.

    If it's not on here, I would definitely put it on. It stops most bots, but I find users still get through. Likely these are real users paid to join up in order to make basic posts with url links in to try and get people to various sites.

    Difficult to stop this automatically, though there is a new option in vBulletin I have not tried which scans posts for spam and removes it, only when the users have less than a set amount of posts. Looks promising and I've been meaning to try it out.

  7. #17
    Teratoma
    Guest

    Re: A slight change.

    I think there is the option to add an additional question as well. This can deter lazy spammers...or ones who can't answer simple questions like what is 1+1?

  8. #18

    Re: A slight change.

    These are definitely bots at least in a large number of cases as they have a pattern to the registrations. We are using the maximum complexity graphical imagery for the registration process.

    On a good note, it has been almost 24hrs without a spam signup.

Page 2 of 2 FirstFirst 12

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •