vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Check Proxy RBL on New User Registration (https://vborg.vbsupport.ru/showthread.php?t=152463)

lazytown 07-16-2007 09:17 PM

Check Proxy RBL on New User Registration
 
The following mod was removed due to security concerns (please do not reveal any specific security holes in this thread).

Check Proxy RBL on New User Registration.
https://vborg.vbsupport.ru/showthrea...hreadid=131852

As it had 173 installs and was vital to reduce spam for many forums, I'm sure many of you are wondering what is next. I was surprised a thread about this didn't already exist.

Since the original mod thread was closed (???) I thought this could be the place to discuss alternatives or how/when the mod might be patched.

MANY forums were using this mod to greatly reduce spam and have no viable alternative (captcha/nospam only works for bots -- much spam is now coming from humans in China/etc). Perhaps this could spur development of a new/better mod or someone to offer to patch it. I thought about writing something using a mod alongside project honeypot. Project Honeypot seems to be a lot more accurate for forum type spam -- though it isn't available without registration.

-vissa

d8tabyte 07-17-2007 04:48 AM

Why not just use the akismet mod coupled with a promotion strategy.

lazytown 07-17-2007 04:55 AM

Quote:

Originally Posted by d8tabyte (Post 1293391)
Why not just use the akismet mod coupled with a promotion strategy.

Thank you. Very interesting mod I never noticed before (it says its 3.5x, but posts say it works with 3.6x) . I'll have to check it out. What do you mean by "coupled with a promotion strategy?"

This is one reason why I created this thread -- some useful info for those of us looking for spam solutions.

-vissa

d8tabyte 07-17-2007 11:59 AM

you move all existing users with more than 1 post to a usergroup called registered promoted or what ever you want. then set up the registered usergroup with limited permissions and to be monitored by akismet. Make it so they have to make like 5 posts to be promoted to the second usergroup.

This will contain your spam sign ups, monitor them and give them reduced privileges such as not b3eing able to edit their posts, or having reduced number of PM's etc.

Freezerator 07-17-2007 03:13 PM

Quote:

Originally Posted by d8tabyte (Post 1293582)
you move all existing users with more than 1 post to a usergroup called registered promoted or what ever you want. then set up the registered usergroup with limited permissions and to be monitored by akismet. Make it so they have to make like 5 posts to be promoted to the second usergroup.

This will contain your spam sign ups, monitor them and give them reduced privileges such as not b3eing able to edit their posts, or having reduced number of PM's etc.

I'd rather prevent them registering at all...

Spinball 08-03-2007 04:31 AM

Quote:

Originally Posted by Freezerator (Post 1293710)
I'd rather prevent them registering at all...

Agreed. Just returned from holiday to find one of the most important hacks removed.
It blocked most of our spam - which was several every day. It's so important.
Do the rules prevent someone from fixing it?

Dismounted 08-13-2007 05:56 AM

Quote:

Originally Posted by Spinball (Post 1308716)
Do the rules prevent someone from fixing it?

People may fix insecure mods (assuming they know what the problem is of course) but they cannot release the fix themselves, it must be posted (by staff, in the main post) as either a find/replace file, or as a fixed full copy - the same as if it had been fixed by staff.

StevenTN 08-15-2007 11:36 AM

I would like to know why it was specifically removed, so I can make a much more informed decision, rather than question whether or not it's really insecure. Having it removed due to unspecified security concerns, and not even allowing others to post a fix, is extremely bad policy in this day of age.

If we used that general of a reason for everything, I wouldn't be using vBulletin at all. In fact, the saving grace with vBulletin itself is at least they publish their security issues, and either advise on additional action, or issue a patch/new version.

d8tabyte's suggestion wouldn't work for us, given that we can't have someone monitoring registrations 24/7. In fact, the moderators and I we have were getting burnt out on dealing with the advertising that was posted by spambots. That is why we started to employ the blacklist, with great success.

Seiyaboy 11-25-2007 02:00 AM

Sorry, but I desperate need that mod. I once installed it but then uninstalled it, but it seems that there are some leftover codes somewhere that has been continuing to place registering members on the moderation list. Unless I get the original code, I won't be able to revert the changes done to my forum.

Anyone who still kept a copy of it, please send me a copy. I'm seriously in need of it.

chvlad 11-25-2007 06:33 AM

Quote:

Originally Posted by vissa (Post 1293148)
The following mod was removed due to security concerns (please do not reveal any specific security holes in this thread).

Check Proxy RBL on New User Registration.
https://vborg.vbsupport.ru/showthrea...hreadid=131852

As it had 173 installs and was vital to reduce spam for many forums, I'm sure many of you are wondering what is next. I was surprised a thread about this didn't already exist.

Since the original mod thread was closed (???)

It's surprise for me two. I'm using this plug-in & I don't download the last 4.0 update.
Where can I download this update? Can anybody help?


All times are GMT. The time now is 10:09 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01144 seconds
  • Memory Usage 1,740KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (5)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete