Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
  #1  
Old 12-10-2011, 04:33 PM
lrdvdr lrdvdr is offline
 
Join Date: May 2009
Location: Seguin, Texas
Posts: 5
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Problems with bogus users

I recently started having a problem with what I believe are bogus registrations. All of these have unusual email addresses such as deemdod@f4hrs9.com. I have the usual human verification hack but apparently it is not helping in this case. Anyone have any suggestions?
Reply With Quote
  #2  
Old 12-10-2011, 11:12 PM
Big Al Big Al is offline
 
Join Date: Nov 2011
Posts: 54
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Sounds like spammers. You may find it helpful to block the individual IP's

If they are all from the same IP block then you can block that IP range.
But this may stop any genuine potential members from joining if they are using that IP range.
Reply With Quote
  #3  
Old 12-10-2011, 11:28 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

This puts an end to that stuff permanently, without blocking any IPs..

https://vborg.vbsupport.ru/showthread.php?t=135094
Reply With Quote
  #4  
Old 12-11-2011, 01:04 AM
lrdvdr lrdvdr is offline
 
Join Date: May 2009
Location: Seguin, Texas
Posts: 5
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I will try it out. Most of the ip address are from China, a few from Russia and Nigeria. Thanks for the help.

--------------- Added [DATE]1323639985[/DATE] at [TIME]1323639985[/TIME] ---------------

Quote:
Originally Posted by Max Taxable View Post
This puts an end to that stuff permanently, without blocking any IPs..

https://vborg.vbsupport.ru/showthread.php?t=135094
I installed it but I'm still getting quite a few registrations coming through. I've been banning IP addresses also. Maybe I might not have installed it correctly perhaps?
Reply With Quote
  #5  
Old 12-13-2011, 05:41 AM
Big Al Big Al is offline
 
Join Date: Nov 2011
Posts: 54
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Not all spamming posts are from bots. So blocking IP's can be of use.

Some spammers will post ten times and then post a link. They can usually be spotted as they post inconsequential things like , "good post, I have been looking for posts like this" and "Nice post I will add to my blog" ETC.

On some sites a noob has to post five or ten posts before they can post a link, so some spammers will post ten times and then hit you with a link.

Rapid deletion of their posts is somewhat of a deterrent to them, as their sole reason for existence is to promote their site's, hence the links, so that they can get income from people clicking them.

If you take this away from them their work has been in vain.
Reply With Quote
  #6  
Old 12-13-2011, 09:45 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

There are human spammers but it's a tiny percentage of the spam problem. Most spam is coming from big botnets. Stop the bots, stop most of the spam.
Reply With Quote
  #7  
Old 12-13-2011, 11:51 AM
Digital Jedi's Avatar
Digital Jedi Digital Jedi is offline
 
Join Date: Oct 2006
Location: PopCulturalReferenceLand
Posts: 5,171
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I have NoSpam! installed on a couple of sites and I think it's perfect at preventing bot registration....if you know how to use it. Far to often I see people coming up with verification questions that actually are too easy. Examples would be simple math questions or "type the word "blubber" in this box."

One of the reasons I like NoSpam! over the one built into vB is the ease at adding multiple questions quickly, but also the ease of adding HTML images. I add dozens of images, make sure the answer isn't in the file name, and have the user identify something basic about the image. Like, how many "cubes are in this picture?" [photo of a bunch of shapes], "This is a picture of a what?" [photo of a cat], "Type the last four letters in the word in this picture" [Star Wars logo] and then I put in the multiple correct answers that NoSpam! allows me to add. I stay away from making people identify colors and try to use the same question for multiple pictures, such as the "this is a picture of what?" question. Depending on the niche of your site, you can even get more specific with the questions (there's no reason someone going to my gaming website shouldn't know who Batman is), but if I do those, I do a lot of them and I add more any time I think of them.

On another site I'm using SolveMedia's CAPTCHA (which may not be making me a ton of money, but I do like how you have to play a video to see the verification string) along with requiring the user to enter in a YouTube URL. (I provide a few right there for them to right click and paste) I've only tested this for a couple of days, but I noticed the garbage registrations have come to a stand still where I was using SolveMedia and a not-recently-updated set of NoSpam! questions alone. Will wait to see how this plays out. I do like this Is Bot thing now that I've looked at it more closely, and may add that in as just another layer of defense and a way to see if I can get some reporting on if my registration protection is working.
Reply With Quote
  #8  
Old 12-13-2011, 02:16 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Digital Jedi View Post
I do like how you have to play a video to see the verification string) along with requiring the user to enter in a YouTube URL. (I provide a few right there for them to right click and paste)
I use this cut/paste problem with the standard Q&A. The answer is identical to the question, which is a long, convoluted instruction to copy and paste the question into the answer box. Nobody's going to take the time to type it, and there are subtle built-in typing errors that probably wouldn't be noticed if they did. Bots cannot copy/paste, human spammers usually skip out and find a easier target.
Quote:
I do like this Is Bot thing now that I've looked at it more closely, and may add that in as just another layer of defense and a way to see if I can get some reporting on if my registration protection is working.
I get about 80 spambot signup attempts daily, none ever succeed. Very rarely, the occasional human spammer does get through but finds the account created so limiting that it's essentially worthless, since new users cannot even send visitor messages, PMs except to Admins, cannot post images or links in posts, and cannot even use signatures or have access to the "home page" field on the profile. Most just hang it up and leave without even posting.

Many layers of spam protection is best, as you say. But I have found the IsBot mod to be by far the best bot catcher and reporter. I get their email address, IP address, what username they tried to use and I send all of the information to Project Honey Pot, and the IsBot works even if they don't fill out the Q&A field. There's also instructions in the Mod thread, on how to make it automatically ban these IPs and email addresses, for those so inclined. The other nice thing about IsBot, it doesn't give itself away with any kind of "gotcha" message, it just uses the default vBulletin "The Administrator has disabled registration" message. So the botnet administrators don't get the clue what is causing the problems getting their bots registered.

Currently I am also experimenting with hidden fields in the register.php script. These are fields the bots can see and will attempt to fill out, triggering the IsBot script regardless of time, if they do so. Humans won't see these hidden fields and therefore could never attempt to enter any data in them.

As you can see, I hate spam.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 05:49 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.07649 seconds
  • Memory Usage 2,231KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (8)post_thanks_box
  • (8)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (8)post_thanks_postbit_info
  • (8)postbit
  • (8)postbit_onlinestatus
  • (8)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete