NEWS

Forum Security

  • 31 Replies
  • 9074 Views

Jackal

  • *
  • Newb
  • *
  • Posts: 23
  • JackPoint VPN Admin
« on: <09-03-10/2109:06> »
Nice choice on using SMF for the forum software. I've always liked it better than PHP. That said, with the lack of at least email authentication you can guarantee spam floods. I use the software for pretty much a nothing site, hidden in a sub-directory and I had to resort on using Member Approval (aka, every member had to be manually approved by me) and High Complexity on the visual verification.

Though honestly I don't think the visual verification stops anything other than people with bad eyes because I'm convinced the bots find a loophole around them. At the very least I'd require e-mail activation. But that's just me.

I've ran my own forums on and off over the years and for some reason I can not grasp, spammers still think that flooding forums is a good way to sell their cra....products....
Dumpshock IRC Server

"This Snow Crash thing—is it a virus, a drug, or a religion?"
"What's the difference?"

"Jack the sound barrier. Bring the noise."

Bull

  • *
  • Ace Runner
  • ****
  • Posts: 2427
  • Crotchety Old Ork Decker
« Reply #1 on: <09-03-10/2117:55> »
Email verification doesn't help.  It didn't slow down Spammers on Dumpshock at all.  Dunno how well visual worked. 

Bull

FastJack

  • *
  • Administrator
  • Prime Runner
  • *****
  • Posts: 6184
  • Kids these days...
« Reply #2 on: <09-03-10/2140:21> »
<snip>spammers still think that flooding forums is a good way to sell their cra....products....
Stupid Azzie Corp-hacks. Trust me, if they didn't keep the spam in their UV sector, I'd have killed it by now.

Caine Hazen

  • *
  • Global Moderator
  • Omae
  • *****
  • Posts: 250
  • Dumpshocker Emeritus
    • My lair
« Reply #3 on: <09-03-10/2210:41> »
shit, jackel... they'll let anyone in...

yeah, we'll see how this develops over the next few weeks, and see how security goes
If you try and take a cat apart to see how it works, the first thing you have on your hands is a non-working cat~DNA
SRGC 0.3: SR1 SR2 SR3 SR4++ h b+++ B--- D++ UB++ IE+ RN-- fnord DSF++++ W++++ hk+ ri++ m gm++ M--(+) P FP+

MJBurrage

  • *
  • Newb
  • *
  • Posts: 42
  • Running shadows since 2050
« Reply #4 on: <09-04-10/1453:16> »
I've ran my own forums on and off over the years and for some reason I can not grasp, spammers still think that flooding forums is a good way to sell their cra....products....
The real problem here is the low cost of spamming.  Spam works because it is so easy and cheap that even if less than 1 in 1000 buy something, the spam has made its sender a profit.

The only solution, other than filters, that would work, would be international regulation with international punishment.

Jackal

  • *
  • Newb
  • *
  • Posts: 23
  • JackPoint VPN Admin
« Reply #5 on: <09-04-10/1841:43> »
shit, jackel... they'll let anyone in...

yeah, we'll see how this develops over the next few weeks, and see how security goes

See, proof about the lack of security. ;)
Dumpshock IRC Server

"This Snow Crash thing—is it a virus, a drug, or a religion?"
"What's the difference?"

"Jack the sound barrier. Bring the noise."

Casazil

  • *
  • Omae
  • ***
  • Posts: 602
  • There can be only one!
    • Casazil's Shadowrun
« Reply #6 on: <09-05-10/1943:27> »
Spammers must think that Yahoo Groups (or at least mine) are not spam worthy then.

Granted my group isn't very active though.

But if those groups don't get alot of spam maybe they are doing something that works???
"If at first you don't succeed blame someone else"
Joel "Casazil" Rogers
Catalyst Demo Team Shadowrun Special Agent #251
http://games.groups.yahoo.com/group/CasazilsShadowrun/

Jackal

  • *
  • Newb
  • *
  • Posts: 23
  • JackPoint VPN Admin
« Reply #7 on: <09-10-10/0545:54> »
Well, needless to say, if you check the members roster you'll already see spambot id's showing up. It honestly doesn't rake long for them to find new forums. Wish I knew a truely effective way to get rid of forum spammers for
 good.
Dumpshock IRC Server

"This Snow Crash thing—is it a virus, a drug, or a religion?"
"What's the difference?"

"Jack the sound barrier. Bring the noise."

FastJack

  • *
  • Administrator
  • Prime Runner
  • *****
  • Posts: 6184
  • Kids these days...
« Reply #8 on: <09-10-10/0916:10> »
Well, needless to say, if you check the members roster you'll already see spambot id's showing up. It honestly doesn't rake long for them to find new forums. Wish I knew a truely effective way to get rid of forum spammers for
 good.
Nuclear bombardment from space.

Unfortunately, that would just leave the Corporate Court, Mars Colony and whoever else is up there left...

Jadehellbringer

  • *
  • Global Moderator
  • Chummer
  • *****
  • Posts: 218
  • My crotch! I'm not supposed to... wait, what?
« Reply #9 on: <09-10-10/0943:42> »
Eh, it's why there are moderators here. After years of squirreling out and banning spambots on the Battletech forums, it's nothing new to do the same here. I've gotten pretty good at it- if anyone sees spam posts, keep doing what you've been doing and report them to the mods so we can teach them the error of their ways.
Not to be demanding, but can you please point that Panther Assault Cannon somewhere other than my groin?


Kontact

  • *
  • Prime Runner
  • *****
  • Posts: 3147
  • You called?
« Reply #10 on: <09-19-10/0520:46> »
Though honestly I don't think the visual verification stops anything other than people with bad eyes because I'm convinced the bots find a loophole around them.

You can get the code from GNAA's trollforge backup if you want to try and find a way to beat the old bot algorithm used to read captchas.  I imagine it has been improved since the original project died off a couple years ago.  Just be careful.  Those cats don't play nice.

KarmaInferno

  • *
  • Ace Runner
  • ****
  • Posts: 1874
  • Armor Stacking Cheese Monkey
« Reply #11 on: <10-04-10/2205:06> »
Is there a "moderate first post" option in SMF?

Requiring the first message from a new member be approved before it posts would really cut down on spammers.

It works great on the message boards I've moderated on Yahoogroups, the spammers mostly don't even try if the "moderate first post" option is turned on.




-k

Devil

  • *
  • Omae
  • ***
  • Posts: 747
« Reply #12 on: <10-07-10/2232:48> »
Email conformation is standard for forums these days. Email confirmation doesn't slow people down or piss people off. It's pretty much expected these days to gain access to any good public forum.

I can imagine having to wait for administrator membership approval or confirmation of your first post. Something like that on a public forum would annoy me far more.

How do other gaming co. forums handle these spam issues? Constant moderation? Captchas?
« Last Edit: <10-07-10/2237:35> by Joker »

Jadehellbringer

  • *
  • Global Moderator
  • Chummer
  • *****
  • Posts: 218
  • My crotch! I'm not supposed to... wait, what?
« Reply #13 on: <10-08-10/1608:30> »
Email conformation is standard for forums these days. Email confirmation doesn't slow people down or piss people off. It's pretty much expected these days to gain access to any good public forum.

I can imagine having to wait for administrator membership approval or confirmation of your first post. Something like that on a public forum would annoy me far more.

How do other gaming co. forums handle these spam issues? Constant moderation? Captchas?

Assassins.  ;D
Not to be demanding, but can you please point that Panther Assault Cannon somewhere other than my groin?


hazmat the monstar

  • *
  • Chummer
  • **
  • Posts: 101
  • www.hazmatthemonstar.com
    • www.hazmatthemonstar.com
« Reply #14 on: <10-08-10/1909:39> »
Email conformation is standard for forums these days. Email confirmation doesn't slow people down or piss people off. It's pretty much expected these days to gain access to any good public forum.

I can imagine having to wait for administrator membership approval or confirmation of your first post. Something like that on a public forum would annoy me far more.

How do other gaming co. forums handle these spam issues? Constant moderation? Captchas?

Assassins.  ;D

I am currently out of work if you have a target... - Anonymous runner X45