Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 07-16-2007, 09:17 PM
lazytown lazytown is offline
 
Join Date: Feb 2004
Posts: 503
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Check Proxy RBL on New User Registration

The following mod was removed due to security concerns (please do not reveal any specific security holes in this thread).

Check Proxy RBL on New User Registration.
https://vborg.vbsupport.ru/showthrea...hreadid=131852

As it had 173 installs and was vital to reduce spam for many forums, I'm sure many of you are wondering what is next. I was surprised a thread about this didn't already exist.

Since the original mod thread was closed (???) I thought this could be the place to discuss alternatives or how/when the mod might be patched.

MANY forums were using this mod to greatly reduce spam and have no viable alternative (captcha/nospam only works for bots -- much spam is now coming from humans in China/etc). Perhaps this could spur development of a new/better mod or someone to offer to patch it. I thought about writing something using a mod alongside project honeypot. Project Honeypot seems to be a lot more accurate for forum type spam -- though it isn't available without registration.

-vissa
Reply With Quote
  #2  
Old 07-17-2007, 04:48 AM
d8tabyte's Avatar
d8tabyte d8tabyte is offline
 
Join Date: Nov 2005
Location: Michigan
Posts: 239
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Why not just use the akismet mod coupled with a promotion strategy.
Reply With Quote
  #3  
Old 07-17-2007, 04:55 AM
lazytown lazytown is offline
 
Join Date: Feb 2004
Posts: 503
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by d8tabyte View Post
Why not just use the akismet mod coupled with a promotion strategy.
Thank you. Very interesting mod I never noticed before (it says its 3.5x, but posts say it works with 3.6x) . I'll have to check it out. What do you mean by "coupled with a promotion strategy?"

This is one reason why I created this thread -- some useful info for those of us looking for spam solutions.

-vissa
Reply With Quote
  #4  
Old 07-17-2007, 11:59 AM
d8tabyte's Avatar
d8tabyte d8tabyte is offline
 
Join Date: Nov 2005
Location: Michigan
Posts: 239
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

you move all existing users with more than 1 post to a usergroup called registered promoted or what ever you want. then set up the registered usergroup with limited permissions and to be monitored by akismet. Make it so they have to make like 5 posts to be promoted to the second usergroup.

This will contain your spam sign ups, monitor them and give them reduced privileges such as not b3eing able to edit their posts, or having reduced number of PM's etc.
Reply With Quote
  #5  
Old 07-17-2007, 03:13 PM
Freezerator Freezerator is offline
 
Join Date: Nov 2001
Location: Den Haag
Posts: 197
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by d8tabyte View Post
you move all existing users with more than 1 post to a usergroup called registered promoted or what ever you want. then set up the registered usergroup with limited permissions and to be monitored by akismet. Make it so they have to make like 5 posts to be promoted to the second usergroup.

This will contain your spam sign ups, monitor them and give them reduced privileges such as not b3eing able to edit their posts, or having reduced number of PM's etc.
I'd rather prevent them registering at all...
Reply With Quote
  #6  
Old 08-03-2007, 04:31 AM
Spinball's Avatar
Spinball Spinball is offline
 
Join Date: Feb 2002
Location: Telford, England
Posts: 705
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Freezerator View Post
I'd rather prevent them registering at all...
Agreed. Just returned from holiday to find one of the most important hacks removed.
It blocked most of our spam - which was several every day. It's so important.
Do the rules prevent someone from fixing it?
Reply With Quote
  #7  
Old 08-13-2007, 05:56 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Spinball View Post
Do the rules prevent someone from fixing it?
People may fix insecure mods (assuming they know what the problem is of course) but they cannot release the fix themselves, it must be posted (by staff, in the main post) as either a find/replace file, or as a fixed full copy - the same as if it had been fixed by staff.
Reply With Quote
  #8  
Old 08-15-2007, 11:36 AM
StevenTN StevenTN is offline
 
Join Date: Mar 2002
Location: Nashville, TN
Posts: 47
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I would like to know why it was specifically removed, so I can make a much more informed decision, rather than question whether or not it's really insecure. Having it removed due to unspecified security concerns, and not even allowing others to post a fix, is extremely bad policy in this day of age.

If we used that general of a reason for everything, I wouldn't be using vBulletin at all. In fact, the saving grace with vBulletin itself is at least they publish their security issues, and either advise on additional action, or issue a patch/new version.

d8tabyte's suggestion wouldn't work for us, given that we can't have someone monitoring registrations 24/7. In fact, the moderators and I we have were getting burnt out on dealing with the advertising that was posted by spambots. That is why we started to employ the blacklist, with great success.
Reply With Quote
  #9  
Old 11-25-2007, 02:00 AM
Seiyaboy Seiyaboy is offline
 
Join Date: May 2006
Posts: 100
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Sorry, but I desperate need that mod. I once installed it but then uninstalled it, but it seems that there are some leftover codes somewhere that has been continuing to place registering members on the moderation list. Unless I get the original code, I won't be able to revert the changes done to my forum.

Anyone who still kept a copy of it, please send me a copy. I'm seriously in need of it.
Reply With Quote
  #10  
Old 11-25-2007, 06:33 AM
chvlad chvlad is offline
 
Join Date: Feb 2007
Posts: 2
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by vissa View Post
The following mod was removed due to security concerns (please do not reveal any specific security holes in this thread).

Check Proxy RBL on New User Registration.
https://vborg.vbsupport.ru/showthrea...hreadid=131852

As it had 173 installs and was vital to reduce spam for many forums, I'm sure many of you are wondering what is next. I was surprised a thread about this didn't already exist.

Since the original mod thread was closed (???)
It's surprise for me two. I'm using this plug-in & I don't download the last 4.0 update.
Where can I download this update? Can anybody help?
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:40 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.07559 seconds
  • Memory Usage 2,263KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (5)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete