Go Back   vb.org Archive > Community Discussions > Forum and Server Management
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 04-18-2009, 05:52 PM
kjkoster kjkoster is offline
 
Join Date: Aug 2008
Posts: 20
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Detecting registration bots

Dear All,

I have noticed recently that the automated spammer registrations use fairly predictable patterns. I am wondering if anyone has used such patterns to kill their tools?

First is that their tools only request the precise pages they need. The style sheets and images are not requested at all.

Second is that one of their tools always use the date jan 1st 1980 as their date of birth.

1) Are there any mods that use this information to poop the spamtools?

2) What would you think of a mod that checks that certain images are actually downloaded before the user can register to the site?

Kees Jan
Reply With Quote
  #2  
Old 04-18-2009, 05:58 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

They are also very quick to register - faster than any human can do so. Is Bot will check how fast they register and if it's faster than xx seconds, they can't register.
Reply With Quote
  #3  
Old 04-18-2009, 06:00 PM
kjkoster kjkoster is offline
 
Join Date: Aug 2008
Posts: 20
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Dear Lynne,

Here is a sample that I lifted from my access log. The times between the first and second request are indeed quite fast, but the third request tool human-like time.

Code:
121.231.14.208 - - [18/Apr/2009:07:45:13 +0200] "GET /forum/register.php?do=signup HTTP/1.1" 200 12749 126819 "http://java-monitor.com/forum" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)"
121.231.14.208 - - [18/Apr/2009:07:45:14 +0200] "POST /forum/register.php?do=register HTTP/1.1" 200 19209 39837 "http://java-monitor.com/forum/register.php?do=signup" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)"
121.231.14.208 - - [18/Apr/2009:07:47:13 +0200] "POST /forum/register.php?do=addmember HTTP/1.1" 200 10887 893786 "http://java-monitor.com/forum/register.php?do=register" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)"
Reply With Quote
  #4  
Old 04-18-2009, 07:49 PM
foroalfaromeo foroalfaromeo is offline
 
Join Date: Feb 2009
Posts: 26
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

These are the IPs and mail domains I blocked in my VB

194.8.75.109
194.8.75.191
194.8.75.192
195.2.240.126
195.2.241.162
200.126.238.235
217.116.138.185
24.12.148.237
62.43.160.66
66.197.231.213
72.232.61.165
87.118.102.57
87.152.131.102
87.152.143.240
87.248.169.14
88.198.157.210
89.105.228.141
89.248.160.195
91.124.60.190
91.124.61.15
91.206.15.66
94.125.179.5
87.118.120.6
194.8.74.37

@getasiansex.com
@islandaccommodation.info
@lovecasino.net
@mail.ru
@mainru.com
@onllinevideo.cn
@yandex.ru
@megapochta.cn

We can build a black list with info..... what do you think?
If everyone cooperates.
Reply With Quote
  #5  
Old 04-18-2009, 08:01 PM
kjkoster kjkoster is offline
 
Join Date: Aug 2008
Posts: 20
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Dear foroalfaromeo,

You are aware of http://www.stopforumspam.com/ and its vb plugin: https://vborg.vbsupport.ru/showthread.php?t=176481 are you?

Let's not duplicate efforts. I was trying to find some *additional* tools to throw at the spammers.
Reply With Quote
  #6  
Old 04-21-2009, 10:52 PM
kermit2 kermit2 is offline
 
Join Date: Jun 2008
Posts: 117
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I use a few lines of code to moderate any first posts which contain a URL. Since the user's post count isn't incremented, if they then make a second post containing a URL, that too is moderated. Sometimes there are false positives, but approving those gives my mods something to do. Obviously the spammers could easily get round it, but the majority just move on to another forum.

Suppose you could do something similar to automatically moderate users with a birth date of 1st Jan 1980, and accept that there are going to be some false positives. Presumably this is only the signature of one particular spammer though.

Or you could just firewall off China
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:31 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03737 seconds
  • Memory Usage 2,205KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_code
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (6)post_thanks_box
  • (6)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (6)post_thanks_postbit_info
  • (6)postbit
  • (6)postbit_onlinestatus
  • (6)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete