Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
  #1  
Old 05-15-2008, 07:26 AM
vbuserkid vbuserkid is offline
 
Join Date: Apr 2008
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Stopping Spam Members Joining?

Right I've been running Vbulletin for quite a while now and never had any problems with spam members joining, now all of a sudden I'm getting bombarded with them! I have the settings turned to verify by email for registration.

Any other tips or is tehre a way of stopping them join?
Reply With Quote
  #2  
Old 05-15-2008, 07:52 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Which type of verification are you using? (CAPTCHA, reCAPTCHA, or Q&A)
Reply With Quote
  #3  
Old 05-15-2008, 09:22 AM
cheat-master30's Avatar
cheat-master30 cheat-master30 is offline
 
Join Date: Mar 2007
Location: Information Classified
Posts: 1,715
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

My advice is to use the question and answer system, and use custom questions for your forum that cannot be answered with a dictionary. And then, if you still need back up, email validation and/or moderating the first five posts of each user. This is how I personally have never had one spam bot account or post for about six months.
Reply With Quote
  #4  
Old 05-15-2008, 11:11 AM
mikesz mikesz is offline
 
Join Date: Jan 2006
Posts: 45
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

With the captcha AND the SPAM question MOD installed, I was STILL getting 4 to 5 bogus registration EVERY day. I finally added a script to my registration form that traps the bogus submissions and NUKES them before they can submit the junk. I have a record of the IP address and other stuff they used so my "badguy blacklist" is dynamic and pretty much up to date. In addition to the IP address, I wrote some filters that check for known badguy foot prints which enables me to determine a bogus registration by other means as well. I have added a honeypot to mix too (it takes out a fair number of them including badbots that ignore robots.txt). Since last November I have completely eliminated the daily flow of badguys from my site. Zero, not one! I have collected almost 10000 IP addresses of attempts to illicitly access my site. The email addresses they use are almost always forged from the data I have been able to collect over that time period.

Since upgrading to 3.7.0 I have not yet turned of MY system to see if the vB system does what it is suppose to do and am not sure if I will, given that I have some thing that absolutely works and like they say, "if it works, don't fix it" ... I may do some testing at some point to see if 3.7.0 catches the badguys but I don't have a priority for it now.

regards, mikesz
Reply With Quote
  #5  
Old 05-15-2008, 02:02 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I use Is Bot. It is the number one needed mod as far as I'm concerned.
Reply With Quote
  #6  
Old 05-15-2008, 03:12 PM
cheat-master30's Avatar
cheat-master30 cheat-master30 is offline
 
Join Date: Mar 2007
Location: Information Classified
Posts: 1,715
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by mikesz View Post
With the captcha AND the SPAM question MOD installed, I was STILL getting 4 to 5 bogus registration EVERY day. I finally added a script to my registration form that traps the bogus submissions and NUKES them before they can submit the junk. I have a record of the IP address and other stuff they used so my "badguy blacklist" is dynamic and pretty much up to date. In addition to the IP address, I wrote some filters that check for known badguy foot prints which enables me to determine a bogus registration by other means as well. I have added a honeypot to mix too (it takes out a fair number of them including badbots that ignore robots.txt). Since last November I have completely eliminated the daily flow of badguys from my site. Zero, not one! I have collected almost 10000 IP addresses of attempts to illicitly access my site. The email addresses they use are almost always forged from the data I have been able to collect over that time period.

Since upgrading to 3.7.0 I have not yet turned of MY system to see if the vB system does what it is suppose to do and am not sure if I will, given that I have some thing that absolutely works and like they say, "if it works, don't fix it" ... I may do some testing at some point to see if 3.7.0 catches the badguys but I don't have a priority for it now.

regards, mikesz
I think you should probably release that system as a modification, since there'd likely be a decent amount of interest in it. So it's basically an auto ban blacklist depending on certain factors of the user registering, like certain info being entered?

Oh, and if you ever use question and answer, I'd say to make the questions more complex than Maths and less general knowledge. Because as said, bots can solve maths. As can normal computers.
Reply With Quote
  #7  
Old 05-18-2008, 06:44 AM
mikesz mikesz is offline
 
Join Date: Jan 2006
Posts: 45
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

cheat-master30, you know that is ABSOLUTELY true. I did use simple math because that is what the so-called "experts" were recommending as well. But the Bots are more sophisticated these days and simple math isn't any problem for them as well as captcha displays that have a following of freaks who want nothing better than to break them publicly which is where the bots retrieve the info to use in the exploits. It is ugly for sure. Yes, indeed I do have an "autoban blacklist" that seems to work. I have not advertised, productized or even packaged it ( I have been monitoring my 3.7.0 system to see if it still works correctly, given the CSRF issues) yet as I don't want to have the badguys make ME their pet project but I would be glad to install it for anyone thinks it will help them get rid of the "mischievous monkeys" LOL

Send me a PM if you are interested in the details about it.

regards, mikesz
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:08 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04567 seconds
  • Memory Usage 2,204KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (7)post_thanks_box
  • (7)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (7)post_thanks_postbit_info
  • (7)postbit
  • (7)postbit_onlinestatus
  • (7)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete