Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
  #21  
Old 03-27-2012, 12:18 AM
BirdOPrey5's Avatar
BirdOPrey5 BirdOPrey5 is offline
Senior Member
 
Join Date: Jun 2008
Location: New York
Posts: 10,610
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Pandemikk View Post
I don't understand...

You make a Q&A and get spambots signing up... You disable registrations... They stop. How exactly is it vBulletin's fault that your Q&A is so simple that spambots can sign up no problem?

Use reCAPTCHA or something. Stop blaming others for your own faults.
Q&A works far better than ReCaptcha, and he already said the answer is impossible without emailing him.

The weak link in the chain is only 1 human spammer needs to email him and get the answer 1 time- then they can re-use the same answer forever if it is never changed making it worthless.
Reply With Quote
  #22  
Old 03-27-2012, 12:48 AM
blind-eddie's Avatar
blind-eddie blind-eddie is offline
 
Join Date: Apr 2006
Location: Michigan
Posts: 2,310
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Paranoia at its finest. Seen it many times.
I went to your site, you have all forums closed from public view & what people to click the contact me button and send you the user name they are going to use as well as an email address to have you create an account for them... good luck with that....I can't see the contact me button get pushed that often regarding registration. Just my 2 cents.
Sheltering your site will close your site.

What I am seeing in the thread is a pointing game & you are not willing to listen to anything the previous posters have written and want to blame vbulletin.... I would suggest to you to submit a ticket on vbulletin.com if you really think this is the issue....I can't see the ticket going very far.
Appreciate what the members here are advising you to do, they speak from experience.
We have all been there.

I get little( 1 a month) to no spammers at all on any vb site I have or any that I may manage. The tools and advise are here for you to use, free of charge.....

Good Luck to you.
Reply With Quote
  #23  
Old 03-27-2012, 02:59 AM
Simon Lloyd's Avatar
Simon Lloyd Simon Lloyd is offline
 
Join Date: Aug 2008
Location: Manchester
Posts: 3,481
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I've had my site now for a little over 3.5 years and i have a total of 108 spammers, they were all human as i use Q&A, my questions change every 6 months, i use vb3.8.7 (always upgraded but will never upgrade to the beta they call vb4), i do have bad behaviour installed and vbstop forum spam, but both are just set in logging mode they do nothing to the user, so i guess with that plain old Q&A that vb supplied i've had on average 30 human spammers a year, not bad eh?

I know you dont want to believe it but one of your signed up members is either a spammer or given the secret answer to a spammer, if you dont want to use Q&A why not install a picture Q&A, you know how it goes "click on the cat" and you have to click the correct pic, if you right click the pic and check the properties they're named something like 1zY5xoo234.jpg so no clues for the automated bot, only humans can get past that.

At the end of the day you will NEVER stop human spammers, thats the joys of being a forum owner.
Reply With Quote
  #24  
Old 03-27-2012, 03:35 AM
Pandemikk Pandemikk is offline
 
Join Date: Jul 2009
Posts: 292
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by BirdOPrey5 View Post
Q&A works far better than ReCaptcha, and he already said the answer is impossible without emailing him.

The weak link in the chain is only 1 human spammer needs to email him and get the answer 1 time- then they can re-use the same answer forever if it is never changed making it worthless.
So how exactly does that make it better than ReCaptcha?
Reply With Quote
  #25  
Old 03-27-2012, 07:46 AM
BirdOPrey5's Avatar
BirdOPrey5 BirdOPrey5 is offline
Senior Member
 
Join Date: Jun 2008
Location: New York
Posts: 10,610
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

From feedback from webmasters and my own use it for well over a year now it has been apparent ReCaptcha has been exploited in some way-

https://www.vbulletin.com/forum/show...-to-Combat-It?

My theory is the bots are copying the image and displaying it on file-sharing websites where thousands of people eagerly type in the answers every minute of the day.

That's one guess.

I've also seen a video showing that the vast majority of the time you really only need to type in the "easy" half of ReCaptcha for it to go through- in which case basic OCR can be enough, when coupled with multiple tries..
Reply With Quote
  #26  
Old 04-28-2012, 09:43 PM
mike2902's Avatar
mike2902 mike2902 is offline
 
Join Date: Apr 2009
Posts: 186
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Ok let me try to make this more clear for those of you that dont seem to understand and think its my fault. I had the question and answer system in place and all was fine. All of a sudden spam registrations went through the roof. So I changed my questions. That did not help. So I figured they were human spammer answering the questions. So I changed the "answer" to the question to something that cant be guessed. There is no "answer". You have to email me personally from the contact uslink at the bottom of the main page and ask for the answer. Registrations were still going through even though I hadnt been contacted by anyone for the pass phrase that is necessary to complete registration. At least I thought it would be necessary to complete registration. And just so none of you say I gave out the answer one time and forgot I just changed the answer just now. Its a nonsense phrase that could never be guessed. I changed the answer and turned registration back on at 3:19 EST. Im going to the store and im betting when I get back I will have new spam registrations that should be impossible.

OK its now 6:39 and I just got home. I have 3 new registrations. Now tell me how can I have 3 new registrations when I have a question and answer system in place and the "answer" is not know to anyone. I havent given it to anyone, I just got home. So whats wrong with the question and answer system???

_________________________________

There is a new user, guccibags at HO.net

To view their profile, go here:

http://www.hangin-out.net/member.php?u=1041

Email Address : arnobeck369@gmail.com

_______________________

There is a new user, charleslsq at HO.net

To view their profile, go here:

http://www.hangin-out.net/member.php?u=1040

Email Address : ertfdgrkuuuu@gmail.com


____________________

There is a new user, Zonia LemmeDDFC at HO.net

To view their profile, go here:

http://www.hangin-out.net/member.php?u=1042
Reply With Quote
  #27  
Old 04-28-2012, 09:52 PM
borbole's Avatar
borbole borbole is offline
 
Join Date: Jan 2010
Posts: 2,559
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The good old days when the spammers were stopped with a simple captcha or a q&a challenge are over. Spammers have become more sophisticated not to mention the human spammers who will bypass any kind of restrictions. As mentioned above, there is no way of stopping them.
Reply With Quote
  #28  
Old 04-28-2012, 09:52 PM
kh99 kh99 is offline
 
Join Date: Aug 2009
Location: Maine
Posts: 13,185
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I just registered on your site and there was no question. You did actually try it yourself didn't you?

ETA: BTW, sorry for any inconvenience - you can delete the user I created.
Reply With Quote
  #29  
Old 04-28-2012, 10:36 PM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You seem to only have one question, did you fill in the regex part of the question instead of adding answers?

Do you understand how the Q&A system works?

You're supposed to have 5-100 questions, with at least one valid answer.

Each time a user tries to register they get 1 of those questions randomly.

If you have one question, and one answer. Once someone FINDS the answer, or if your Question is bad because you don't have a valid answer or you have an invalid regex setting, you have NO SECURITY AT ALL.
Reply With Quote
2 благодарности(ей) от:
CAG CheechDogg, In Omnibus
  #30  
Old 04-29-2012, 12:20 AM
souperman souperman is offline
 
Join Date: Mar 2011
Posts: 131
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I use Q&A and timers. If the registration is under 5 seconds, then I ban the user and ip.

The best protection is Q&A and have at least 10 questions.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 07:41 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03918 seconds
  • Memory Usage 2,254KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (10)post_thanks_box
  • (2)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete