Go Back   vb.org Archive > Community Discussions > Modification Requests/Questions (Unpaid)
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #21  
Old 12-05-2014, 12:34 AM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Just pointing this out ozzy, once your current "stop spam" methods get popular enough, xrummer, and other bots will build defenses around them, and then they'll be useless too.
Reply With Quote
  #22  
Old 12-05-2014, 12:38 AM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Not if you stay on top of it, and update it as things are defeated. Once they defeat one layer, change it and add a different layer.
Reply With Quote
  #23  
Old 12-05-2014, 12:41 AM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ozzy47 View Post
Not if you stay on top of it, and update it as things are defeated. Once they defeat one layer, change it and add a different layer.
So, you mean the same arms race that recapcha/etc is all under?
Reply With Quote
  #24  
Old 12-05-2014, 12:46 AM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Nope, there in no captcha In anything I use, as it has been defeated for years.
Reply With Quote
  #25  
Old 12-05-2014, 12:54 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zachery View Post
Just pointing this out ozzy, once your current "stop spam" methods get popular enough, xrummer, and other bots will build defenses around them, and then they'll be useless too.
Actually there is no way a defense against the registration timer will ever be done. Because first, you can't guess the timer setting, so you make the delay 60 seconds at least for your botnet. This greatly cuts into the production. Secondly, false fields exist in the timer mod. Bots always put gibberish in odd fields. Third, there's also a maximum time setting you gotta figure on.

XRumer currently has nothing in it that even allows for time delays. I'm a paid license holder and get all the updates.

And this is just the timer mod. The other mods we recommend involve targeted blocking of known spammer hostnames, user agent strings, and spammy emails that use dots and other punctuation in the username of the email addresses.

And none of them give any hint whatsoever that any human verification is being used, and don't give "gotcha" messages when a spammer fails the checks. And as a package, they provide alot of bullets in the anti-spam gun.
Reply With Quote
  #26  
Old 12-05-2014, 01:50 AM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Keywords "currently".

Bots never had the ability to defeat recapcha, then it got popular, then it got defeated.

Honeypots are stupidly old, and became unpopular, because bots were programmed to defeat them.

Timers are also old, and once again they can be user annoyers. Because I don't know anyone who can't fill out a registration in less than 60 seconds. Chrome auto fills these for me, I can register in under 5 seconds. If the minimum is 60, guess I can never register another account again.

Your silver bullets will eventually corrode and be useless.

Edit: Hostnames, and user agents can easily be countered to be valid user agents too. These people have more incentive to break down your walls than you currently have to build them. Your walls take months/weeks to build, and they can break them down in hours.
Reply With Quote
  #27  
Old 12-05-2014, 02:00 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zachery View Post
Your silver bullets will eventually corrode and be useless.
Defeatism.

Tell me how they're going to defeat all the checks.

Botnets rely on speed and high volume. Programming even a short delay means potentially a million fewer stabs a week. Delay can't really be programmed, because you have to make it long enough to defeat minimum time, short enough to pass the check for maximum time. No way to know the settings site to site.

False fields - botnets are programmed to put SOMETHING here. And they do.

Dots, dashes and other punctuation in email usernames - this mod has settings too. How many dots are allowed? Commas? Semicolons, underscores? There is no way to know these settings.

The targeted lists - these are not honeypots. These are lists of guaranteed known bad user agent strings and hostnames. Not IP addresses.

This "new" reCaptcha - the "new" thing about it is a checkbox. Defeated years ago, the bots check the "I have read the rules" box already. They will quickly adapt to this "new" one that is at least 5 years behind the times.

These games, puzzles, captchas, Q&A and such, are just GADGETS that annoy legitimate people and have been long defeated.

We believe we are smarter, more creative, better looking, and just overall superior to any botnet admin, spammer supervisor, or spammer alive. This is why they are bottom feeders to start with. The era of Big Spam is over.
Reply With Quote
  #28  
Old 12-05-2014, 02:01 AM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I said back on the first page, you should use the tools that do the job today. You just can't claim they'll always work.

Once they're popular, they're targeted. Once they're targeted they can be defeated.

Edit:I've got a lot more to write i'm just in the middle of something else atm.
Reply With Quote
  #29  
Old 12-05-2014, 02:03 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zachery View Post
Timers are also old, and once again they can be user annoyers. Because I don't know anyone who can't fill out a registration in less than 60 seconds. Chrome auto fills these for me, I can register in under 5 seconds. If the minimum is 60, guess I can never register another account again.
Haven't seen these problems yet. Have you personally? Or is this just a theory?

Quote:
Edit: Hostnames, and user agents can easily be countered to be valid user agents too. These people have more incentive to break down your walls than you currently have to build them. Your walls take months/weeks to build, and they can break them down in hours.
The hostnames and UA strings CAN be spoofed. Question is, will they ever be in wide use basis.
Reply With Quote
  #30  
Old 12-05-2014, 02:04 AM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I'll tell you what Zachary, if this new capcha is the way to go, as everything else is defeated as you say, code up the mod, and make it so it can only run if the re is no other form of spam protection on the sites. Not any other mod, Q&A or anything.

Then we will see if sites stop getting spam.
Reply With Quote
Благодарность от:
Max Taxable
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:42 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04280 seconds
  • Memory Usage 2,283KB
  • Queries Executed 12 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (5)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (10)post_thanks_box
  • (1)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete