I just discovered that there were about 50 users on one of my Nuke sites that had been used to post all sorts of annoying things in the forums. As far as I can tell, either these accounts where created manually, the standard captcha image is being read, or there is some other way to create accounts.
I sincerely doubt that someone took the time to create the accounts manually, although there were only a couple a day for a about a month, so it is certainly possible. However, it makes no sense to me that someone invest the time and effort to create users on this site. Since the standard captcha imagine is fairly straightforward and used by thousands (?) of sites, it would seem logical that someone would likely create a program to scan these images. That leaves some other mechanism, i.e. a backdoor??
Having this on one site made me curious about my other sites. Although I did not find any Forum spam, I did find a similar number of erroneous accounts during basically the same timeframe, although there was a different set of domains for the email address on each site. Most of these are easy enough to figure out as they have "porn" or something similar in their domain name. The problem is Yahoo or Gmail accounts. I would hate to have ban all users with accounts either of those places.
I have been thinking about setting a script that runs once a day to send me a list of all new users and their email addresses so I can relatively quickly see if there is a new domain trying to spam me. I was also thinking of adding a captcha to the post form.
phpNuke and phpBB's CAPTCHAs can be bypassed. There are automated programs to spam forums, even to use free services to autoactivate accounts. If you see anything from
@web.de
@mail.ru
@cashette.com
@gawab.com
They are all services that are being abused by these spammers.
yahoo.com and gmail.com accounts are harder, but they are also used by some spammers.
I'm not sure there's a script that does exactly what you want. For phpNuke, there is the Approve Membership mod that you could use to approve all accounts.
Thanks for those domain names. Unfortunately one of the sites I manage is for a sports club in Germany so there are a lot of legitimate users that have real web.de addresses. In fact, my son's primary address is @web.de.
At this point, I don't want to make it too hard to sign up. However, the Approve Membership module is definitely something to keep in mind.
Joined: Aug 29, 2004 Posts: 9133 Location: Arizona
Posted:
Sun Jan 28, 2007 7:11 pm
And, btw, i am in the testing stages of an Approved Membership Module "Lite" that includes ONLY the approval part and will be based on Ken's 6.1.6 and RavenNuke 2.10. I hope to finish it up about the same time as 2.10 is released... I need it for two personal web sites so had to do it!
View next topic View previous topic
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum