Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> Raven's RavenNuke(tm) v2.00.00 - v2.02.00 Distro
Author Message
jimmo
Worker
Worker



Joined: Dec 08, 2005
Posts: 107

PostPosted: Sun Jan 28, 2007 8:21 am Reply with quote

Hi All!

I just discovered that there were about 50 users on one of my Nuke sites that had been used to post all sorts of annoying things in the forums. As far as I can tell, either these accounts where created manually, the standard captcha image is being read, or there is some other way to create accounts.

I sincerely doubt that someone took the time to create the accounts manually, although there were only a couple a day for a about a month, so it is certainly possible. However, it makes no sense to me that someone invest the time and effort to create users on this site. Since the standard captcha imagine is fairly straightforward and used by thousands (?) of sites, it would seem logical that someone would likely create a program to scan these images. That leaves some other mechanism, i.e. a backdoor??

Having this on one site made me curious about my other sites. Although I did not find any Forum spam, I did find a similar number of erroneous accounts during basically the same timeframe, although there was a different set of domains for the email address on each site. Most of these are easy enough to figure out as they have "porn" or something similar in their domain name. The problem is Yahoo or Gmail accounts. I would hate to have ban all users with accounts either of those places.

I have been thinking about setting a script that runs once a day to send me a list of all new users and their email addresses so I can relatively quickly see if there is a new domain trying to spam me. I was also thinking of adding a captcha to the post form.

Any other ideas would be appreaciated.

Regards,

jimmo
 
View user's profile Send private message
jakec
Site Admin



Joined: Feb 06, 2006
Posts: 3048
Location: United Kingdom

PostPosted: Sun Jan 28, 2007 11:06 am Reply with quote

The standard captcha for Nuke isn't fool proof, which is why I believe that RN 2.10 will have a new one, which will be harder to crack.

Quote:

I was also thinking of adding a captcha to the post form.

Do you have the captcha set for new registrations?

Also are you using email activation, so the user has to verify their email address?
 
View user's profile Send private message
jimmo







PostPosted: Sun Jan 28, 2007 11:48 am Reply with quote

The captcha is activated everywhere I can, and I am using email activation.
 
evaders99
Former Moderator in Good Standing



Joined: Apr 30, 2004
Posts: 3221

PostPosted: Sun Jan 28, 2007 1:11 pm Reply with quote

phpNuke and phpBB's CAPTCHAs can be bypassed. There are automated programs to spam forums, even to use free services to autoactivate accounts. If you see anything from
@web.de
@mail.ru
@cashette.com
@gawab.com
They are all services that are being abused by these spammers.

yahoo.com and gmail.com accounts are harder, but they are also used by some spammers.

I'm not sure there's a script that does exactly what you want. For phpNuke, there is the Approve Membership mod that you could use to approve all accounts.

_________________
- Star Wars Rebellion Network -

Need help? Nuke Patched Core, Coding Services, Webmaster Services 
View user's profile Send private message Visit poster's website
jimmo







PostPosted: Sun Jan 28, 2007 2:09 pm Reply with quote

Thanks for those domain names. Unfortunately one of the sites I manage is for a sports club in Germany so there are a lot of legitimate users that have real web.de addresses. In fact, my son's primary address is @web.de.

At this point, I don't want to make it too hard to sign up. However, the Approve Membership module is definitely something to keep in mind.
 
montego
Site Admin



Joined: Aug 29, 2004
Posts: 9457
Location: Arizona

PostPosted: Sun Jan 28, 2007 7:11 pm Reply with quote

And, btw, i am in the testing stages of an Approved Membership Module "Lite" that includes ONLY the approval part and will be based on Ken's 6.1.6 and RavenNuke 2.10. I hope to finish it up about the same time as 2.10 is released... Wink I need it for two personal web sites so had to do it!

_________________
Where Do YOU Stand?
HTML Newsletter::ShortLinks::Mailer::Downloads and more... 
View user's profile Send private message Visit poster's website
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> Raven's RavenNuke(tm) v2.00.00 - v2.02.00 Distro

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©