vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Spammers (https://vborg.vbsupport.ru/showthread.php?t=190380)

Thamelas 10-01-2008 09:03 PM

I am getting hit right now. 2 more registering. This has to be human controlled, or they have found a way around all registration security.

Yogesh Sarkar 10-01-2008 09:13 PM

Getting hit by spambots as well for the first time since I switched to vbulletin over a year back, spambots advertising porn. One characteristic I have found in every one of them is that all say "Man" under the biography section and have ip address from all over the world with majority of the email addresses belonging to gmail.

Managed to slow them down by modifying the usual no spam questions with new one.

khosk 10-01-2008 09:33 PM

I am getting spam all of a sudden on my two vBulletin forums, started about 2 hours ago.

Thamelas 10-01-2008 09:41 PM

Same with me. They all say "Man" in the biography box, are spamming porn, and the IP's are from all over the world.

khosk 10-01-2008 10:47 PM

I'm looking at my logs and this spambot never even calls the captcha image, someone has found a flaw in the registration process that lets it bypass this step.

Swampfox 10-01-2008 10:50 PM

No, they decode the captcha images in a matter of seconds

I posted the fix for this a few pages back, you're wasting your time with email verification and captcha

someone check the spammers user profile in the admincp, see if they are selecting GMT-12 as the time zone, if so the mod i posted earlier will stop them cold

khosk 10-01-2008 10:55 PM

Here are the logs, you can see no image.php so the bot never even looked at the captcha.

oh well it's cutting off part of the logs. The first two lines call a parameter s with two different long hexadecimal strings.

PHP Code:

84.19.188.30 - - [01/Oct/2008:18:38:44 -0400"GET /forum/register.php?  HTTP/1.0" 200 18156 "http://volkovtrio.com/sound/pre/index.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; ru) Opera 8.01"
84.19.188.30 - - [01/Oct/2008:18:38:48 -0400"GET /forum/index.php? HTTP/1.0" 200 45797 "http://www.erisaboard.com/index.php?" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; ru) Opera 8.01"
84.19.188.30 - - [01/Oct/2008:18:39:01 -0400"GET /forum/register.php HTTP/1.0" 200 17854 "http://www.erisaboard.com/register.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; ru) Opera 8.01"
84.19.188.30 - - [01/Oct/2008:18:39:02 -0400"POST /forum/register.php?do=register HTTP/1.0" 200 23413 "http://www.erisaboard.com/forum/register.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; ru) Opera 8.01"
84.19.188.30 - - [01/Oct/2008:18:39:05 -0400"POST /forum/register.php?do=addmember HTTP/1.0" 200 23907 "http://www.erisaboard.com/forum/register.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; ru) Opera 8.01"



jkcerda 10-01-2008 10:58 PM

:mad:I shut off registrations, 30 in about 16 hours:mad:

Thamelas 10-01-2008 11:00 PM

This needs to be reported to Jelsoft ASAP. Its rediculous and needs to be fixed like yesterday!

jkcerda 10-01-2008 11:00 PM

I have over 7 trying to register & other "guest" trying to start threads or events:mad:

Swampfox 10-01-2008 11:03 PM

Maybe they are using a newer bot software, if so there may be a weakness that we can use to block them, such as the "Man" in the profile field

Can someone please check and post the timezone they are selecting when they register?

Yogesh Sarkar 10-01-2008 11:04 PM

Quote:

Originally Posted by khosk (Post 1635114)
I'm looking at my logs and this spambot never even calls the captcha image, someone has found a flaw in the registration process that lets it bypass this step.

That was I was thinking of as well and from the looks of it, it can bypass nospam as well.

jkcerda 10-01-2008 11:05 PM

different time zones,-12 , +8 , -3:30

Swampfox 10-01-2008 11:09 PM

Block all 3 of those, no english speaking countries involved, and a legitimate member is smart enough to just select a different time zone, the bots are automated and wont be able to

jkcerda 10-01-2008 11:10 PM

Quote:

Originally Posted by Swampfox (Post 1635137)
Block all 3 of those, no english speaking countries involved, and a legitimate member is smart enough to just select a different time zone, the bots are automated and wont be able to

what MOD do I need to do that?

Swampfox 10-01-2008 11:11 PM

<a href="https://vborg.vbsupport.ru/showthread.php?t=141554" target="_blank">https://vborg.vbsupport.ru/showthread.php?t=141554</a>

jkcerda 10-01-2008 11:16 PM

thanks, ill give it a try

Piper0005 10-01-2008 11:17 PM

If that does not work I recommend trying vbStopForumSpam. I installed it a few hours ago and it has stopped over 25 spam registrations already. (its in the vbulletin 3.6 mods but works with my site which is 3.7)

https://vborg.vbsupport.ru/showthread.php?t=176481

fmckinnon 10-01-2008 11:30 PM

I've been getting nailed w/ this issue, too ... installed vbStopForumSpam and the Time Zone one.

Eric HRF 10-01-2008 11:57 PM

Quote:

Originally Posted by Piper0005 (Post 1635145)
If that does not work I recommend trying vbStopForumSpam. I installed it a few hours ago and it has stopped over 25 spam registrations already. (its in the vbulletin 3.6 mods but works with my site which is 3.7)

https://vborg.vbsupport.ru/showthread.php?t=176481

Will install that! So far I've just banned russia and china ip addresses. Hate doing that.

Yogesh Sarkar 10-02-2008 12:24 AM

This keeps getting interesting, just saw an ip address trying to register on my forum and it turns out it is a webserver at the planet and belongs to imageshack!

I guess it is some kind of spamming trojan/virus which is using people's computers and server to do this. I have already submitted an abuse report with imageshack, lets see how they respond to this.

Ohiosweetheart 10-02-2008 12:44 AM

Quote:

Originally Posted by Thamelas (Post 1635077)
Same with me. They all say "Man" in the biography box, are spamming porn, and the IP's are from all over the world.

I'm getting Man in the biography box and test in some of the location boxes. the rest are around the globe. :rolleyes:

dougeetx 10-02-2008 12:54 AM

Same here...on several of my boards...

AsmodeusLore 10-02-2008 01:14 AM

Same issue here.

Plenty of new spam, but practically none before today.

I'm hoping to avoid the timezone mod. I really don't want to get into an arms race with spammers. If i block timezone, they'll change to a different timezone, then i need a new method.

TMH63 10-02-2008 01:24 AM

I just installed the timezone hack. And I want to lock my forums down GOOD! I could care less about any timezone outside the US or Canada, so my question is....... Will entering these as you see them work fine? All the example gives in the software is,
Quote:

Example: 1,3,-2
-12, -11, -4:30, -3, 12, -1, +1, +2, +3, +3:30, +4, +4:30, +5, +5:30, +5:45, +6, +6:30, +7, +8, +9, +9:30, +10, +11, +12



Thanks!

dougeetx 10-02-2008 01:29 AM

I've turned on the Question/Answer human verification. It seems to have stopped them for now.

jkcerda 10-02-2008 01:31 AM

wow, many trying to register, I have registrations off untill I install the MODS:mad::mad:

CP, 10-02-2008 01:34 AM

Spam is on the rise now... just yesterday and today we have been getting an influx of over 30 spam registrations from russia.... and the email they register with always resolves to gmail or some other free email service.

We have email verification and they seem to also verify their email accounts some how and spam...

Meestor_X 10-02-2008 01:39 AM

They are also getting by the "Moderate New Members" setting in AdminCP.
As well, there seems to be some evidence that they are "bypassing" image verification AND the Question/Answer.

See here: http://www.vbulletin.com/forum/showt...69#post1631469

ShadMan 10-02-2008 01:46 AM

Those of you using cPanel to block, are you using the IP Deny tool? If so, are you entering each individual range from the zone tables on the IPDeny site? My cPanel will only let me enter one range at a time, and there are tons for China alone. I can copy the entire list into my firewall deny table directly, but my firewall crashes after about 1000 entries or so, which is just enough to block China and Russia maybe. Maybe I should just set a Deny All and put the USA IPs in the Allow. ;)

FYI - I had over 50 spam registrations today, with only 1 prior to today in the 4 months my forum has been open. I enabled ReCaptcha about 45 minutes ago, and none since.

AsmodeusLore 10-02-2008 02:04 AM

Re they getting around Image Validation only, or are they getting around reCaptcha too?

dougeetx 10-02-2008 02:09 AM

Turn on human verification with Question/Answer and put in a simple question like "what's 2 plus 3". Make sure to spell it out instead of using symbols just in case it looks for that.

TMH63 10-02-2008 02:22 AM

Quote:

Originally Posted by dougeetx (Post 1635254)
Turn on human verification with Question/Answer and put in a simple question like "what's 2 plus 3". Make sure to spell it out instead of using symbols just in case it looks for that.


Where do you modify the questions/answers at specifically?

GSeybold 10-02-2008 02:25 AM

Most of my spam comes from China, Russia, and Pakistan. Alot from Pakistan. So these countries are banned. I have found that this does not hurt my new registrations in the least. I also do not allow gmail as most of my spammers use gmail accounts. This has helped ALOT as well. Every once in a while I get someone pissed because they can't register using Gmail but we take care of this by registering them manually once we've checked out their registration. You also want to censor the following because they hit many forums hard. In one day we had over a hundred spammers for addition recovery. Little did they know two can play at this game. A-holes! LOL

addictionrecovery.net addictionrecovery Buddhism rack111

bangaloreflowerplaza@gmail.com
kingphonestore@hotmail.com
maks.digitalinfozz@yahoo.com
dukepikaso@aol.com
puneonnet@hotmail.com
saadepunjab@gmail.com
chennaiflowerplaza@gmail.com 05

Doughboy 10-02-2008 02:26 AM

I've been nailed today on two of my vb installations, including on a board that has never had a spam bot post before.

I made a post in another forum:
https://vborg.vbsupport.ru/showthrea...49#post1635249

Cosoft 10-02-2008 02:53 AM

Same issue here.
Plenty of new spam, but practically none before today.

Regards

Meestor_X 10-02-2008 02:57 AM

Me too. Never had a problem until yesterday.

DJMIKE 10-02-2008 02:58 AM

me too

moonbase 10-02-2008 04:25 AM

We have had none until yesterday. They say "Man" in the Bio and "Test" in the user name.

These two IP addresses are almost always attached to them:

142.163.3.122 - bad search bot?

200.63.42.75 - Hacker?

I know of a few boards that had this and then a attack on the Site Admin password/log-in and the sites were hacked.

There is something going on. We all need to find help for this.

jkcerda 10-02-2008 04:46 AM

my registrations are still off, checked who is online & had about 8 trying to register:mad:


All times are GMT. The time now is 12:59 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01463 seconds
  • Memory Usage 1,829KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_php_printable
  • (6)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete