Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 10-25-2012, 09:52 PM
pattycake pattycake is offline
 
Join Date: Jan 2009
Posts: 97
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well,... I just installed a demo version of xRumer and ran it, using my website as a test. The "demo" version of the program uses an email address of:
xrumeremailYOYYY@maildomainJJKUJ.com
Username: XRumerYGQYY

Obvioulsy, this is an invalid email address.

Guess what??? It got signed up.... no validation email, no "vaidation code"... and yet there he was, a new member at my site.
Reply With Quote
  #12  
Old 10-25-2012, 10:30 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Did you have settings in that demo for a delay?

--------------- Added [DATE]1351210745[/DATE] at [TIME]1351210745[/TIME] ---------------

Okay... I did what you did. Got the XRumer demo, and then disabled ALL anti-spam and human verifications on my board, except for the email verification, and let it rip.

Nothing happened. Registration failed, although in the logfile XRumer THINKS it successfully registered.

So, I'm starting now to think your scripts are somehow compromised making it a one-board problem.
Reply With Quote
  #13  
Old 10-26-2012, 12:24 AM
pattycake pattycake is offline
 
Join Date: Jan 2009
Posts: 97
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Nope... no "settings for delay" in demo version. I wonder if it's in the real-mc-coy paid versions?

what version do you have?
Reply With Quote
  #14  
Old 10-26-2012, 12:37 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by pattycake View Post
Nope... no "settings for delay" in demo version. I wonder if it's in the real-mc-coy paid versions?
You asserted it was:
Quote:
Originally Posted by pattycake
the time between registering has long since been defeated by XRumer. They even have a setting of waiting 5, 10, 15, 20, and 30 seconds.
Quote:
Originally Posted by pattycake
ok... whatever, I'm just telling you that the new XRumer has an option to use the delay. YMMV
And my assertion is, the time delay is SO relatively new and SO underused, they likely don't even know about it. Not trying to be snarky, just trying to discover the truth of the matter.

Interestingly, with all of my anti-spam and human verification active, XRumer reported it did successfully register (it did not) and said it was logged in and "probably" posting. BUT - it said there were "extra protections on this forum."
Quote:
what version do you have?
It says "5.0 palladium" and the file version is 5.0.0.747
Reply With Quote
  #15  
Old 10-26-2012, 01:01 AM
pattycake pattycake is offline
 
Join Date: Jan 2009
Posts: 97
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

ditto here... if I activate my spam code, it stops xRumer... I had to disable all of that to run the test above. As yours, the logs shows "extra protections on this forum".

I am going to put a sniffer on the line and watch the process to see what it is sending.

btw: I did install "IsBot" and it's definitely doing a job. I added a few calls to a database so I could keep track of failed (and "allowed in") attempts. I have a several log entries showing a time of: (1350415378 seconds transpired). All are the exact same "1350415378". I wonder if thats their fix? I changed the name of the vars to something else and haven't seen an entry like that since.
Reply With Quote
  #16  
Old 10-26-2012, 01:06 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by pattycake View Post
ditto here... if I activate my spam code, it stops xRumer... I had to disable all of that to run the test above. As yours, the logs shows "extra protections on this forum".

I am going to put a sniffer on the line and watch the process to see what it is sending.

btw: I did install "IsBot" and it's definitely doing a job. I added a few calls to a database so I could keep track of failed (and "allowed in") attempts. I have a several log entries showing a time of: (1350415378 seconds transpired). All are the exact same "1350415378". I wonder if thats their fix?
Wait, perhaps I misunderstand. You were telling us the XRumer registered anyway, bypassing the email validation and indeed, a new account was showing up on your forum. Am I misunderstanding?

Also, IsBot is obsolete as of three days ago - I commissioned a coder here to update it with AdminCP controls and more features, find that here for vB3.x.x:

Bot Blocker 3.x.x

And for v4:

Bot Blocker 4.x.x
Reply With Quote
  #17  
Old 10-26-2012, 01:17 AM
pattycake pattycake is offline
 
Join Date: Jan 2009
Posts: 97
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Correct... isBot and my own custom "spam killers" were already stopping xRumer but I wanted to get to the bottom of this so I disabled isBot and all of my custom scripts... then I ran xrumer and, it did indeed create a new account.

After I confirmed that it created the new account, I re-enabled isBot and my custom scripts.

Tomorrow I will install the sniffer and then we'll see exactly whats going on.

Quote:
Also, IsBot is obsolete as of three days ago - I commissioned a coder here to update it with AdminCP controls and more features, find that here for vB3.x.x:
awesome... I'll give it a try. thanks for the heads up.
Reply With Quote
  #18  
Old 10-26-2012, 01:18 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by pattycake View Post
Correct... isBot and my own custom "spam killers" were already stopping xRumer but I wanted to get to the bottom of this so I disabled isBot and all of my custom scripts... then I ran xrumer and, it did indeed create a new account.

After I confirmed that it created the new account, I re-enabled isBot and my custom scripts.

Tomorrow I will install the sniffer and then we'll see exactly whats going on.
I would be checking my vB folders and files for something amiss...
Reply With Quote
  #19  
Old 10-26-2012, 01:41 AM
pattycake pattycake is offline
 
Join Date: Jan 2009
Posts: 97
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Max Taxable View Post
I would be checking my vB folders and files for something amiss...
the only thing different from the original installation is some coding I did in register.php to disallow certain email hosts. Other than that, all code is the original, all folders are the same, etc. It's a clean install.

No worries, the sniffer will show everything.... everything coming in, and everything going out.
Reply With Quote
Благодарность от:
Max Taxable
  #20  
Old 10-26-2012, 01:44 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well, I'm not really worried, since I verified I don't have this issue. Just trying to be helpful.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:36 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.10411 seconds
  • Memory Usage 2,269KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (8)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (1)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete