Reply
Thread Tools
Posts: 3,401 | Thanked: 1,255 times | Joined on Nov 2005 @ London, UK
#1
I just tried to see how easy it is to sign up to this forum with a dummy account (promoted by user mutato with 8 spams in a day) and I see that the image designed to prevent automated registrations is broken - it shows a broken image link and of course it's now impossible for legitimate users to sign up to the forum.

Quite how mutato managed to sign up today I've no idea - when was the image verification function added to the registration page? If it was added before 12 Dec 2006 (the date mutato joined) there must be an exploit in the forum software which allows automated registration.

The url for the verification image appears to be:

http://www.internettablettalk.com/fo...97760864cc3a96

which results in the following php error:

Code:
Fatal error: Call to undefined function: imagecreatetruecolor() in /home/tabtalk/public_html/forums/image.php on line 102
 
Reggie's Avatar
Posts: 1,436 | Thanked: 3,144 times | Joined on Jul 2005
#2
We tried recompiling apache last night and missed installing GD. This was done after mutato registered and posted all the spam. FYI, these spammers believe it or not, go through the manual process of registration, with email verification, and have their automated posting app to do the posting. Real crazy.

It should be working now. Thanks for reporting it.
__________________
Reggie Suplido
 
Hedgecore's Avatar
Posts: 1,361 | Thanked: 115 times | Joined on Oct 2005 @ Toronto, Ontario, Canada
#3
What about a captcha for every post? Shouldn't be *too* much of a pain in the ***.
 
aflegg's Avatar
Posts: 1,463 | Thanked: 81 times | Joined on Oct 2005 @ UK
#4
Originally Posted by Hedgecore
What about a captcha for every post? Shouldn't be *too* much of a pain in the ***.
I think it would be. For each new *thread*, however, that seems like a good compromise.

Cheers,

ANdrew
__________________
Andrew Flegg -- mailto:andrew@bleb.org | http://www.bleb.org
Now known as
Jaffa
 
Hedgecore's Avatar
Posts: 1,361 | Thanked: 115 times | Joined on Oct 2005 @ Toronto, Ontario, Canada
#5
That's worth it... though consider the alternative; unable to automatically create new threads legit ones become bombarded by spam.

Is it possible to force captchas for a user's first 20 posts? (Posting 20 legitimate messages before launching a spam barrage seems like a lot of work for a spammer)
 
aflegg's Avatar
Posts: 1,463 | Thanked: 81 times | Joined on Oct 2005 @ UK
#6
Captchas for first 20 posts sounds perfect.
__________________
Andrew Flegg -- mailto:andrew@bleb.org | http://www.bleb.org
Now known as
Jaffa
 
Posts: 3,401 | Thanked: 1,255 times | Joined on Nov 2005 @ London, UK
#7
Originally Posted by aflegg
Captchas for first 20 posts sounds perfect.
Sounds like a reasonable compromise to me.
 
Posts: 3,841 | Thanked: 1,079 times | Joined on Nov 2006
#8
Some other forums I've visited lately use posting captchas, I felt it was no bother at all really. Go for it.
 
Reggie's Avatar
Posts: 1,436 | Thanked: 3,144 times | Joined on Jul 2005
#9
Ok, no spammers lately. I created a new field that a new member should answer during registration:

Enter the first letter of the word "Nokia".

Spammers don't seem to know the answer. lol
__________________
Reggie Suplido
 
Posts: 3,401 | Thanked: 1,255 times | Joined on Nov 2005 @ London, UK
#10
Still getting spam, so they're learning quickly! I guess if the spammers are registering manually but automating the actual posting, there's little you can do to prevent them from signing up in the first place.

Something else to consider - can you prevent the posting of messages that include URLs until the poster has 5 posts under their belt? It will be annoying for legit users, but may confuse the bots.
 
Reply


 
Forum Jump


All times are GMT. The time now is 12:01.