![]() |
I'm really excited about releasing this to my community. They will LOVE it! So, great work!
I'm having a problem with BB Code not being formatted correctly and broken links (see attached screenshots). Is there something I'm doing wrong? I'm using MS Outlook and VB 3.8. Thanks! :) |
Quote:
I am still not understanding how the script would prevent someone with an email address on same domain and a fake header, from posting as someone else. I would think that a better approach would be to issue a unique hash to each user on the forum and when the email is sent to them this hash must be somewhere in the email so that when users reply the software will authenthicate the user. Or something along the lines. Great job by the way on the scrip, I have not been this excited about a hack in a long time!!!!! |
Quote:
I looked in depth at the form hack and the WoW hack based on form hack and they both require turning off the CAPTCHA image verification to allow guest posting Here's some screenies of what the m2f backend settings and config are like and it really keeps the system from getting spammed. https://vborg.vbsupport.ru/external/2007/08/20.jpg https://vborg.vbsupport.ru/external/2007/08/21.jpg https://vborg.vbsupport.ru/external/2007/08/22.jpg |
Quote:
|
Quote:
I estimate a release by tuesday :) Also, yes, it'll be in the options :) It'll have to be to allow for multiple languages heh :) |
I am also a little concerned about spam, if a spam boot gets hold of the email. They will start spamming it, the script will receive each email and basically return an error to each of the bogus email addresses sent by the spam software, this will cause my board to become a spamming hub as I will be replying to bogus addresses and in essence become a spammer myself. Maybe setup the software to delete any emails that are not in the db, or simply configure a forum to dump posts from unknown emails?
|
Quote:
I will do some testing on my board, but if there is a way for someone to bypass the filter and post as another user, then we are approaching this from the wrong angle. Security must prevail over functionality and ease of use. I love the idea of this mod and it is working flawlessly on my site so far!!! |
Quote:
Code:
imap_delete($mailbox,$msgno); As mentioned, the scripts next creation will handle any "returned mail" errors that you would get from an invalid email address :) I really really appreciate your input!! Your bringing up some great points! Quote:
Or forwarded messages to create new threads would also not work for that system :( I'm not opposed to a more secure system to receive posts... just wanna make sure it's feasible :) The previous "Mail Reply" system by Colin F, created a new user profile field that people could put in a password. It hashed that onto the subject line of posts sent to users that when they replied validated the reply. He then had users have to put something like -pmypassword at the end of subject lines of new threads if I recall right. That seems infeasible, and definatley not user friendly enough to compete with yahoo groups. I'm curious... will false headers from the same domain work to post to yahoo groups? has anyone tried? |
Well how about this, regular threads would get a random password attached to the subject line. New threads one must add a user password to subject line. If I have to type a whole email to make a post, I do not see why functionality would be sacrificed due to requiring that I type a password on the subject line right after my topic.
It would not be fully automated, but it would definitely beat, having a competitor spam the board with an email bomber. Can you imagine the work to clean that mess? Allot of sites are ran on shared accounts, all I would have to do is get an account on the shared server and then fake the headers and that could spell trouble for an unsuspected site. I am not trying to be difficult, competition is though as it is, just do not want to give other sites a way to mess with my forum. |
I'm mixed, I'd rather try to avoid having users that are sending threads to the forum have to do alot extra, or remember a password.
Heck, I have users now that have to reset their passwords weekly because they can't remember them :) I'd love to hear from others on if they think that this would be nessecary. Or if anyone else has any alternate ideas :) Secondly, if you have a "competitor" on a shared server spamming your board... I'd really wonder why your host isn't doing something about that, as the end result would be them crippling their servers ;) I understand your not trying to be difficult. :) I just don't find the system your suggesting to be feasible, and would like to find an alternative :) |
All times are GMT. The time now is 07:17 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|