Mors,
http://www.thenorthfaceguru.com/ubbthreads/ubbthreads.php?Cat=0We're hosted on Dreamhost. The lamest of the lame, but as lame as they are, I'd have to think they have their ports ports secure. Just to be sure, I'll send an email.
THANKS!!!
Harold,
"
They quit getting in once I turned on CAPTCHA."
Would you mind elaborating on this?
What is "
CAPTCHA"?
Gizmo,
It's easy to tell from the link what is going on in the email verification, but I'm confused as to how that could be subverted.
Even if a nefarious user knew the UBB schema, he/she would still have to know the table prefix to do anything?
Ian,
I've added our site to my profile.
Thanks to all for you insights!
An odd extra thing I've noticed is that in some cases, even users that do confirm have the messed up U_SessionId and U_Approved fields. I can't help but wonder if there isn't two seperate issues at work, or if the attempted SPAM BOTs may have damaged an index table.
One thing I did just remember is that we did get ONE spam poster that did successfully get in and post to some porn sites with the ID Anonymous. I had the good fortune of being on the site right when it happened and was able to delete the post. However, before I did, I manually looked Users tble and there was no trace of an Anonymous ID (which is blocked by the system anyway). Now that I've remembered it, I've checked my archived copy of that post and the IP address is the same as two of the recent unconfirmed registrants.
hmmm. I suppose I aught to block that IP address.