myfreeforum.org Forum Index
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups  Who is OnlineWho is Online   Join! (free) Join! (free)  
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
For an excellent guide to using your myfreeforum forum, you can visit
howtodoit
The howtodoit "readonly" forum provides answers and walkthroughs for all common questions.
  • Welcome
  • Country: US
    US
    Address: 38.107.191.116
  • Server Appeal

Phpbb3: spam problems
Page 1, 2, 3  Next
 
Post new topic   Reply to topic    myfreeforum.org Forum Index -> What's new? Announcements!
View previous topic :: View next topic  
Author Message
admin (no pm's please)
Site Admin
Site Admin


Virtual Cash: 22420

Joined: 22 May 2005
Posts: 25341



Add Karma

rated by 212 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Mar 05, 2009 10:53 am    Post subject: Phpbb3: spam problems Reply with quote

http://blog.bbprotection.net/2009/02/25/phpbb3-captcha-cracked/

As suspected image verification on phpbb3 has been cracked and the developers are being pretty slow in dealing with things

On phpbb2 to avoid this sort of issue arising we implemented our own customized anti-spam system.

Which may make for another "told you not to change to phpbb3" moment   but does not address the immediate issue.

The official thread is here:

http://www.phpbb.com/community/viewtopic.php?f=46&t=1437125

I think the custom profile field approach is simplest for now.

It seems pointless for us to implement an anti-spam mod, when the developers must surely add an official system soon.



_________________

Family Friendly Shareware | | Web Design/Services | Free Forums

Back to top
View user's profile Private message Visit poster's website
admin (no pm's please)
Site Admin
Site Admin


Virtual Cash: 22420

Joined: 22 May 2005
Posts: 25341



Add Karma

rated by 212 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Mar 05, 2009 11:00 am    Post subject: Reply with quote

For good measure create two custom profile fields. One will be a "radio" box, the other a question that must be answered correctly.

For the customer profile field option set up a "Boolean" field like:




Note it displays at registration and is required.

On the next screen DO NOT enter a default value.


Next the maths question




Make the question your own, and in the next screen enter the answer as both minimum and maximum allowed value.
_________________

Family Friendly Shareware | | Web Design/Services | Free Forums

Back to top
View user's profile Private message Visit poster's website
Zina2008
Apprentice
Apprentice


Virtual Cash: 1120

Joined: 17 Dec 2008
Posts: 105


Location: Scotland
Add Karma

rated by 3 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Mar 05, 2009 6:17 pm    Post subject: Reply with quote

Am I correct in thinking that if the question is phrased in words (e.g. "What is two and two?") and the answer in figures (e.g. "23") the Bots will find it harder to make the link and supply an answer?

I have also added profile fields which are compulsory, and relate to the board's content. If the would-be member can't tell me which area he's interested in, there's not much point in his being there, so out he goes.

Back to top
View user's profile Private message
admin (no pm's please)
Site Admin
Site Admin


Virtual Cash: 22420

Joined: 22 May 2005
Posts: 25341



Add Karma

rated by 212 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Mar 05, 2009 7:02 pm    Post subject: Reply with quote

Zina2008 wrote:
Am I correct in thinking that if the question is phrased in words (e.g. "What is two and two?") and the answer in figures (e.g. "23") the Bots will find it harder to make the link and supply an answer?

I have also added profile fields which are compulsory, and relate to the board's content. If the would-be member can't tell me which area he's interested in, there's not much point in his being there, so out he goes.


The bots won't be clever enough hopefully to even figure out 2+2.  But it is a running battle.
_________________

Family Friendly Shareware | | Web Design/Services | Free Forums

Back to top
View user's profile Private message Visit poster's website
interlog
Pupil
Pupil


Virtual Cash: 510

Joined: 05 Feb 2008
Posts: 49



Add Karma

rated by 2 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Mar 05, 2009 11:29 pm    Post subject: Reply with quote

It was only a matter of time before the phpBB3 CAPCHA was broken. It lasted well over a year before it did which is not bad going.

Developers thinking I believe is to reduce the number of upgrades (unless an upgrade is security critical which spam is not) following complaints from users and bundle fixes to bugs in as few as possible upgrades.

Back to top
View user's profile Private message
Zudane
Moderator
Moderator


Virtual Cash: 14190

Joined: 10 May 2008
Posts: 1360



Add Karma

rated by 18 members
Add Comment
Show Comments

online/offline
PostPosted: Sat Mar 07, 2009 9:30 am    Post subject: Reply with quote

Oooh.. just implemented that onto my own ^_^ I hope it helps, I've been getting 10+ a day lately all with gmail domains -.-
_________________


Harsh Reality - Unleash your creativity!

Harsh Reality
Back to top
View user's profile Private message Visit poster's website
admin (no pm's please)
Site Admin
Site Admin


Virtual Cash: 22420

Joined: 22 May 2005
Posts: 25341



Add Karma

rated by 212 members
Add Comment
Show Comments

online/offline
PostPosted: Sat Mar 07, 2009 9:40 am    Post subject: Reply with quote

On my spammed forum, it has been totally clear since these measures were put in place.
_________________

Family Friendly Shareware | | Web Design/Services | Free Forums

Back to top
View user's profile Private message Visit poster's website
P Shivers
Student
Student


Virtual Cash: 540

Joined: 28 Jul 2008
Posts: 54



Add Karma

rated by 0 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Mar 12, 2009 4:40 pm    Post subject: Reply with quote

I have been noticing a lot of inactive users that I am just deleting, but I am wondering if I am just catching them before validation of email or if they are not able to validate the email. I really don't mind, as long as they are not posting. I would rather delete inactive members than ask for more info at registration.
I was waiting to see if they could get past the validation before adding the questions at registration and it seems that, for now, they aren't getting past.
_________________
http://arachnophiles.myfreeforum.org


Back to top
View user's profile Private message
Zina2008
Apprentice
Apprentice


Virtual Cash: 1120

Joined: 17 Dec 2008
Posts: 105


Location: Scotland
Add Karma

rated by 3 members
Add Comment
Show Comments

online/offline
PostPosted: Thu Mar 12, 2009 4:52 pm    Post subject: Reply with quote

If they're using a fake e-mail address - as most do - they won't be able to validate because they will never receive the validation e-mail. You may well find that you will get it instead, with a note that it has bounced back.

However the (allegedly) human species of spammer may use a real one and get in that way. So if you're getting more of these things than usual, and you're worried about it, make sure that new members have to be validated by an Admin.

Alternatively, you can set it so that all new members are put on moderation. They will be able to post, but only in a hidden area where ordinary members won't see what they have to say, until such time as you decide you can trust them on the open forums.

I still say capital punishment is the best long-term solution, mind.

Back to top
View user's profile Private message
NickXmL
Pupil
Pupil


Virtual Cash: 300

Joined: 20 Sep 2008
Posts: 26


Location: Connecticut
Add Karma

rated by 1 members
Add Comment
Show Comments

online/offline
PostPosted: Mon Mar 23, 2009 9:55 pm    Post subject: Reply with quote

Where in the ACP do you implement this?

I am confused as to where I reach the shown page in PHPBB3.

Thanks in advance,
Nick
_________________
To Help Flight Sim Forum, click the sig once a day

Back to top
View user's profile Private message Visit poster's website
admin (no pm's please)
Site Admin
Site Admin


Virtual Cash: 22420

Joined: 22 May 2005
Posts: 25341



Add Karma

rated by 212 members
Add Comment
Show Comments

online/offline
PostPosted: Mon Mar 23, 2009 10:07 pm    Post subject: Reply with quote

Users and Groups/Custom profile fields.
_________________

Family Friendly Shareware | | Web Design/Services | Free Forums

Back to top
View user's profile Private message Visit poster's website
NickXmL
Pupil
Pupil


Virtual Cash: 300

Joined: 20 Sep 2008
Posts: 26


Location: Connecticut
Add Karma

rated by 1 members
Add Comment
Show Comments

online/offline
PostPosted: Mon Mar 23, 2009 11:23 pm    Post subject: Reply with quote

Thanks, but which field type should the math question be?

Thanks in advance,
Nick
_________________
To Help Flight Sim Forum, click the sig once a day

Back to top
View user's profile Private message Visit poster's website
admin (no pm's please)
Site Admin
Site Admin


Virtual Cash: 22420

Joined: 22 May 2005
Posts: 25341



Add Karma

rated by 212 members
Add Comment
Show Comments

online/offline
PostPosted: Tue Mar 24, 2009 12:18 am    Post subject: Reply with quote

Numeric
_________________

Family Friendly Shareware | | Web Design/Services | Free Forums

Back to top
View user's profile Private message Visit poster's website
Zudane
Moderator
Moderator


Virtual Cash: 14190

Joined: 10 May 2008
Posts: 1360



Add Karma

rated by 18 members
Add Comment
Show Comments

online/offline
PostPosted: Tue Mar 24, 2009 12:54 am    Post subject: Reply with quote

I got to the point of adding a -massive- list of spam domains to the ban list, and was still getting a bunch of gmail spam accounts that never activated.

The longer it is since you started to get spam, the more spam lists your on and the more you get - stop it when they are small!

I added two simple fields - both briefly explaining they stop spambots, and in 2 weeks I haven't seen a single account even register as a spam account!  And all real accounts haven't complained about the anti-spam fields ^_^

I would highly recommend adding the anti-spam questions for phpbb3.
_________________


Harsh Reality - Unleash your creativity!

Harsh Reality
Back to top
View user's profile Private message Visit poster's website
Rextreme
Newbie
Newbie


Virtual Cash: 30

Joined: 24 Mar 2009
Posts: 3


Location: Australia
Add Karma

rated by 0 members
Add Comment
Show Comments

online/offline
PostPosted: Tue Mar 24, 2009 2:32 am    Post subject: Reply with quote

I have created the two custom profile fields as recommended but they are not showing up on registration. Any ideas? Thanks


ETA...Its okay, I have worked it out. This forum is great- thanks.  



Back to top
View user's profile Private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    myfreeforum.org Forum Index -> What's new? Announcements! All times are GMT
Page 1, 2, 3  Next
Page 1 of 3
 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Card File  Gallery  Forum Archive
Powered by phpBB © 2001, 2005 phpBB Group
Create your own free forum | Buy a domain to use with your forum