• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
  • Search
  • Member List
  • Calendar
  • Help

Current time: 07-24-2008, 06:23 AM Hello There, Guest! (Login — Register)


Warp2Search - Your Daily Tech News Service / Warp2Search Internal / Feedback / Spam and what to do against it

Post Reply  Post Thread 
Threaded Mode | Linear Mode
Spam and what to do against it
Author Message
Hancoque
Member
***


Posts: 86
Group: Registered
Joined: Dec 2003
Status: Offline
Reputation: 0
Post: #1
Spam and what to do against it

There seem to be spam threads on a daily basis now. And all the moderation does, is to delete those (still unapproved) threads. But isn't that getting a bit tedious, having to delete all that stuff manually?

I wonder how the spammers manage to do it anyway. They post with registered accounts, so either they aren't bots but humans or they have found a way to crack the phpBB CAPTCHA protection used in the registration form. If they are really human, there seems to be no way to effectively block them. But I think it's the latter case. The CAPTCHA doesn't look very difficult to crack and due to the popularity of the phpBB forum software, spammers surely have focused on cracking it.

So, these are the solutions I see:

1.) Customize the board's registration and post interface in a way that bots cannot recognize it anymore. This can be done by changing parameter and file names.

2.) Modify the CAPTCHA protection, so that phpBB-trained bots cannot overcome it any longer.

3.) Change the forum software to a more secure one. But that would involve paying for a commercial software. I personally recommend the Invision Power Board. But I guess, you don't want to pay for it, so the above solutions should be the favored ones.


05-11-2006 08:49 AM
Find all posts by this user Quote this message in a reply
Dark Biene
Super Moderator
******


Posts: 1,649
Group: Super Moderators
Joined: Feb 2004
Status: Offline
Reputation: 0
Post: #2
 

so....Degger is on the way to try what he can do (and with your tipps)

and we mods can only delete them but we can´t ban IP´s...
like i said a week before

don´t watch them, ignore them as good as possible and we try to delete them afap


let´s hope we really can ban them all! Smile


Intel Q6600 @3,6Ghz@FSB400 - Watercooled
8800GTX - Watercooled
Gigabyte X38 DQ6 - Watercooled
2x2GB OCZ Platinum 800 @1066Mhz@5-5-5-15
2x320GB Seagate RAID0 @ TX2300 - Watercooled
Audigy 2 ZS @ Creative 5400 5.1
05-11-2006 10:04 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Hancoque
Member
***


Posts: 86
Group: Registered
Joined: Dec 2003
Status: Offline
Reputation: 0
Post: #3
 

I think banning IP addresses doesn't help because they change so often. There is also a chance to ban addresses from legit users who coincidently use an address that a spammer used before. Only few people have static IP addresses and they would surely not use them for criminal activities. Wink

If they really are bots (which is what I believe) the best way is to use a stronger CAPTCHA protection that the bots can't break.

The CAPTCHA code of phpBB is in the file includes/usercp_confirm.php.

Look at the following page, to see what CAPTCHAs are better than others: http://sam.zoy.org/pwntcha/. According to them, the phpBB CAPTCHA has these weaknesses: "Constant font, no rotation, no deformation, constant colours, weak perturbation". You might also consider reading this thread: http://www.phpbb.com/phpBB/viewtopic.php?t=338401.


05-11-2006 10:23 AM
Find all posts by this user Quote this message in a reply
Mertsch
Super Moderator
******


Posts: 3,001
Group: Super Moderators
Joined: Aug 2002
Status: Offline
Reputation: 1
Post: #4
 

I totally agree with you. But the only one who can change anything is degger.

Its not only the problem of changing some settings and so on ... its also a problem of phpBB upgrades
a new version can cause everything you have done to stop working if its not default ...

There are some IPs that came up very often and they disappeared after ban

lets hope degger will change something



Avatar and signature by Eckpert @ Kackebeus.de
05-11-2006 09:27 PM
Find all posts by this user Quote this message in a reply
Hancoque
Member
***


Posts: 86
Group: Registered
Joined: Dec 2003
Status: Offline
Reputation: 0
Post: #5
 

Mertsch Wrote:
Its not only the problem of changing some settings and so on ... its also a problem of phpBB upgrades
a new version can cause everything you have done to stop working if its not default ...

Yes, that's why I personally want to use as little modifications as possible on my board. But on the other hand it's maybe the only way to be completely protected against spam if you use a hand-tailored protection scheme, because no spammer would try to break it. He could rather register and spam by hand. Default CAPTCHAs of widespread software will always be in danger of being cracked by someone. That's not the case with a unique protection.


05-11-2006 11:43 PM
Find all posts by this user Quote this message in a reply
Guest
Unregistered


Post: #6
 

Or: "In your face!" :knife:

07-13-2007 01:31 PM
Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply  Post Thread 

View a Printable Version
Send this Thread to a Friend
Subscribe to this Thread | Add Thread to Favorites

Forum Jump:

Contact Us | Warp2Search.Net | Return to Top | Return to Content | RSS Syndication

Powered By MyBB
Copyright © 2002-2008 MyBB Group