Previous Thread
Next Thread
Print Thread
Hop To
#254357 12/14/2013 5:58 PM
Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
I'm used to the occasional spam registration attempts, but it seems in the last two weeks I've been getting a ton. Anyone else?

Here's what my queue currently looks like:

[Linked Image from ctfisherman.com]

Joined: Jun 2006
Posts: 869
old hand
old hand
Joined: Jun 2006
Posts: 869
I have blocked anything form 163.com chinese spammers often...


http://clubadventist.com/forums

No longer following the carrot
Joined: Jun 2006
Posts: 16,292
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,292
Likes: 116
Yeah, times like this one needs to utilize the EMail/IP ban types (which now adays isn't much of an issue). I have a mod at UBBDev that changes the 7.5.7 StopForumSpam modification (and v7.5.8 has this stock) that make it so that ip's are looked up on signup.


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Oct 2008
Posts: 104
Member
Member
Joined: Oct 2008
Posts: 104
We've been getting a ton of them too.
But the ones we get are multiple IP addresses and domains.

I could add each IP to the ban list, but I'm always a little concerned I might end
up shutting out someone legit.



Founder/Host
Piano World
https://PianoWorld.com
Home of the world famous Piano Forums.
http://forum.PianoWorld.com
88,000+ registered members
Over 2.5 million posts, and growing...
Joined: Jun 2006
Posts: 16,292
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,292
Likes: 116
Well, the copy of the Stop Forum Spam modification in v7.5.8 Refresh (the current codebase) tests IP's on registration as well which in your example shows the users listed so it should trigger them as well on registration. There are also modifications at UBBDev for Stop Forum Spam for both your version and the latest version to extend where it tests for users (in fact the change in 7.5.7 is also at UBBDev that was added to 7.5.8 to detect registration ip's).


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
At 1:00 a.m., I cleaned out a bunch of different registration attempts. By 8:00 a.m., I had 24 sitting in my queue.

I don't get it. Is getting a spam message across to a few people on a forum, or gaining control of your board, that profitable? Seems likes a lot more trouble than it's worth. How exactly do these guys make a profit? Clearly when they do get through on a forum, their message is some nonsensical garbage that is immediately recognized as spam.

Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
On a side note, I've already blocked "@163.com" but those registration attempts still get through. What's up with that?

Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
I think I see why. You need "%@163.com" to block all from that email domain, correct?

Joined: Jun 2006
Posts: 16,292
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,292
Likes: 116
Originally Posted by Mitch P.
I don't get it. Is getting a spam message across to a few people on a forum, or gaining control of your board, that profitable? Seems likes a lot more trouble than it's worth. How exactly do these guys make a profit? Clearly when they do get through on a forum, their message is some nonsensical garbage that is immediately recognized as spam.
Just advertising really; there are groujps you can pay to have whatever you want plastered literally everywhere for pennies on the dollar, it's insane. The sad part is that a lot of these "bots' are actual humans.

Originally Posted by Mitch P.
I think I see why. You need "%@163.com" to block all from that email domain, correct?
Correct


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Apr 2004
Posts: 1,945
Likes: 145
UBB.threads Developer
UBB.threads Developer
Joined: Apr 2004
Posts: 1,945
Likes: 145
Originally Posted by PianoWorld
I could add each IP to the ban list, but I'm always a little concerned I might end
up shutting out someone legit.

To expand on what you've brought up...

This could also block out many people with shared IPs or Proxy servers. Think; Internet cafés, schools, hotel chains, corporate buildings, ... AOL subscribers (is that still a thing?)...etc

And what happens when the coworker/sibling/partner of a positive contributor to your site, decides that it would be funny to create another account and spam your site with gibberish and troll-bait... "just because."

If you block an address/range of addresses, you're blocking everyone from that IP, not just the "jokester."


Current developer of UBB.threads PHP Forum Software
Current Release: UBBT 7.7.5 // Preview: UBBT 8.0.0
isaac @ id242.com // my forum @ CelicaHobby.com
Joined: Apr 2004
Posts: 1,945
Likes: 145
UBB.threads Developer
UBB.threads Developer
Joined: Apr 2004
Posts: 1,945
Likes: 145
To add, it would great to replace the built-in ubbt crapcha with an alternative, such as one of these...
http://econsultancy.com/us/blog/63144-six-alternatives-to-using-the-dreaded-captcha-images


Current developer of UBB.threads PHP Forum Software
Current Release: UBBT 7.7.5 // Preview: UBBT 8.0.0
isaac @ id242.com // my forum @ CelicaHobby.com
Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
Thanks Gizmo.

I run a mainly paid board (with subscriptions) so I already have a pretty stringent screening process in place (I manually check everyone's IP at sign-up).

But really, is there anyone here who has members from China posting on your board? I'd like to be able to block the entire country as a whole.

Joined: Mar 2007
Posts: 522
Addict
Addict
Joined: Mar 2007
Posts: 522
There have been legitimate Chinese members on my board, but they are few and far between.


Steve

UBB.classic from 2000-2003
UBB.threads from 2003-present!
Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
I'm getting about 30 spam registration attempts per day now. Anyone else getting that volume?

What the hell, am I on some kind of spammer hot list?

Joined: Apr 2007
Posts: 3,940
Likes: 1
SD Offline
Former Developer
Former Developer
Joined: Apr 2007
Posts: 3,940
Likes: 1
nope... i support a lot of boards and it's just a wave of scripts that are being run with spammer regs.

weather the storm and be vigilant wink

set captcha + stopforumspam to fail silently at register, if you want to be proactive.

for the SMALL number of peeps who might have issues signing up, you can then 'Add User' to get them registered.

Joined: Apr 2004
Posts: 1,945
Likes: 145
UBB.threads Developer
UBB.threads Developer
Joined: Apr 2004
Posts: 1,945
Likes: 145
To combat spam sign-ups, would it be worthwhile to implement a delay (60 seconds?) between executing the mailer scripts for new registrations?

I've been running the "StopForumSpam" mod on a few sites since October 2011 (now built in to UBBT v7.5.8). I haven't seen much/any spammers since then.

EDIT: I'm also set to "fail silently at register", as SD mentioned above.

Last edited by id242; 12/18/2013 3:15 PM.

Current developer of UBB.threads PHP Forum Software
Current Release: UBBT 7.7.5 // Preview: UBBT 8.0.0
isaac @ id242.com // my forum @ CelicaHobby.com
Joined: Jun 2006
Posts: 16,292
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,292
Likes: 116
I highly advise anyone running Stop Forum spam who is having issues with people still getting in to apply the modification for stop forum spam at ubbdev (7.5.8) as it integrates into the login center and when they start appearing after they've registered they'll be no longer able to login...


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Jul 2006
Posts: 4,057
Joined: Jul 2006
Posts: 4,057
I find the same spam Ads on this forum as my own on the same days so there must be a list.


BOOM !! Version v7.6.1.1
People who inspire me Isaac ME Gizmo
Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
I've got 18 sitting in my registration queue right now that I have to clean out. Annoying.

Remember way back in the day before spam, when you could just leave your registration open? Yeah, you'd have a crazy person or two get through, but not like now. Your board could be infested and overtaken in mere minutes if these accounts went through.

Last edited by Mitch P.; 12/19/2013 9:45 AM.
Joined: Jul 2006
Posts: 4,057
Joined: Jul 2006
Posts: 4,057
Users with Multiple accounts more of a problem than the spammers.

There IP changes every time they reboot there rooter making defences useless.
Would be handy to gleem the computer name as well as IP's.

My members are pretty good with the spam they notify me pretty quickly.


BOOM !! Version v7.6.1.1
People who inspire me Isaac ME Gizmo
Joined: Feb 2007
Posts: 1,294
Likes: 2
Veteran
Veteran
Joined: Feb 2007
Posts: 1,294
Likes: 2
Ban the entire China netblocks in .htaccess

order allow,deny
deny from ###.###.###.###

allow from all

You can find the China IP Blocks at http://www.nirsoft.net/countryip/cn.html

So to get you started typing:

Code
order allow,deny
deny from 1.0.32
deny from 1.0.33
deny from 1.0.34
deny from 1.0.35
deny from 1.0.36
deny from 1.0.37
deny from 1.0.38
deny from 1.0.39
deny from 1.0.40
deny from 1.0.41
deny from 1.0.42

allow from all

Keep going through all their netblocks.

Last edited by JAISP; 01/13/2014 3:40 PM.
Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
These darn things are relentless. I turned off registration a few days ago. I turned it back on tonight and in about 3-1/2 hours I already have four bogus registration attempts.

Joined: Apr 2004
Posts: 1,945
Likes: 145
UBB.threads Developer
UBB.threads Developer
Joined: Apr 2004
Posts: 1,945
Likes: 145
Is the "Stop Forum Spam" option in UBBT v7.5.8 not working for you guys?

Since enabling it, I haven't seen a single spam bot pass new user validation to post. I do see a few bots sit in the registration queue with either their email or ip address marked as "SPAM" for the duration of UBBT's 24hr account validation window.
Control Panel > Primary Settings > Stop Forum Spam

[Linked Image from id242.com]


Also turn on CAPTCHA Image Verification at:
Control Panel > Registration Settings > Basic Options > select either "Use ImageMagick" or "Use GD2"
ImageMagick generally produces a considerably sharper/higher-quality image. On the other hand, ImageMagick is not supported as well as GD2 by some hosting providers. If in doubt, Try ImageMagick first, then fall back to GD2 if IM is not working (displays no image) for you.

A few of my forums are hosted through BlueHost Pro, so no matter if I use ImageMagick or GD2, my Captchas always fail to load until first clicked, regardless of what browser is used (latest version of Chrome, FireFox or InternetExplorer) or what version of PHP I use (PHP 5.1 or 5.2 or 5.4)... So, I don't use Captchas at all on those sites.

[Linked Image from id242.com]

On all other servers which I admin UBBT on, Captchas display exactly as intended.


And finally, YMMV for the following two "these are probably just snake-oil, but cant hurt if you try them" suggestions...

Confirm that the following registration text input field is restored to the default of "Show & Require"
Control Panel > Registration Settings > Registration Screen
Tick "Location" to "Show & Require"

In addition, you could also change your new user submit button language from "Submit" to "Create Account" for the screen reader bots.
Control Panel > Languages > Language Editor > newuser.php > BUTT_SUBMIT
Replace "Submit" with "Create Account"


Current developer of UBB.threads PHP Forum Software
Current Release: UBBT 7.7.5 // Preview: UBBT 8.0.0
isaac @ id242.com // my forum @ CelicaHobby.com
Joined: Oct 2006
Posts: 358
enthusiast
enthusiast
Joined: Oct 2006
Posts: 358
Just for a different perspective, the "Stop Forum Spam" works fantastically for me.

I have tried CAPTCHA Image Verification twice in the past 3 or 4 years and both times had to remove it. Too many new users ended up in a "cycle" and couldn't get accepted.

And I gave up on "queueing up" new members for approval first. So, my process now is very simple and it works very well. KISS.




--BIll B
Joined: Dec 2003
Posts: 6,560
Likes: 78
Joined: Dec 2003
Posts: 6,560
Likes: 78
I do know at one time when SD was posting about ubb 7.6.
He stated that the captcha was to be loosened up a bit to make it easier to read.


Blue Man Group
There is no such thing as stupid questions. Just stupid answers
Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
Thanks all.

I'm unclear on a few things.

Where is the setting in CP that controls how long a new person has to verify his email before the account gets deleted?

Also, I'm not really sure I understand the difference between the different Spam Protection Level settings.

Currently I have mine set to:
Semi-Auto with Member management checks before display

Ideally, I'd like my board to function like this:
1. Accounts that are flagged by Stop Forum Spam get deleted within a certain period of time (without me having to manually do it)
2. Still be able to manually approve all new legit registrations

Joined: Jun 2006
Posts: 16,292
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,292
Likes: 116
Mitch, you'd be looking at the "Semi Auto with Message" setting. As for how long a user has to validate, I don't think there is a setting that one can edit, and I'm not entirely sure what the timeframe is on email validation.


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Dec 2003
Posts: 6,560
Likes: 78
Joined: Dec 2003
Posts: 6,560
Likes: 78
The time setting is hard coded for validation.
I looked it up a few years ago.
I don't recall the timeframe But I recall there has to be an additional registration attempt after the timeframe has passed to delete the registrant if they have not validated.
I recall it was short though like 24 -48 hours.

Of course that is from memory.


Blue Man Group
There is no such thing as stupid questions. Just stupid answers
Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
Thanks Gizmo. Just to be clear, which setting do you recommend?

Manual with 1-click check
Semi-Auto with Member management checks before display (I'm currently using this one)
Auto with Message
Auto with Silent Fail

Joined: Jun 2006
Posts: 16,292
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,292
Likes: 116
The closest setting to the initial modification (which is how I prefer it to work) is "Auto with Message".


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
The spam bots are brutal. I turned registration off for my board for a few days. The minute I turned registration back on, I'm averaging three garbage registrations per hour. Ugh.

Joined: Jan 2004
Posts: 2,474
Likes: 3
D
Pooh-Bah
Pooh-Bah
D Offline
Joined: Jan 2004
Posts: 2,474
Likes: 3
Does anyone else get the basketball playing Chinese doctor?
That one tries to get in a few times every day at my forum.

Joined: Nov 2006
Posts: 191
Likes: 1
T
Member
Member
T Offline
Joined: Nov 2006
Posts: 191
Likes: 1
Is there a way I can deny all the spam registrations in once account by having them change to deny then hitting submit OR running a command?

Joined: Dec 2003
Posts: 6,560
Likes: 78
Joined: Dec 2003
Posts: 6,560
Likes: 78
Originally Posted by ThreadsUser
Is there a way I can deny all the spam registrations in once account by having them change to deny then hitting submit OR running a command?
Double post???
Answered in your other post.


Blue Man Group
There is no such thing as stupid questions. Just stupid answers
Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
A "select all" option would be nice to have.

I currently have 86 spam accounts sitting in my queue that I have to manually go through and select for deletion.

Joined: Jun 2006
Posts: 811
old hand
old hand
Joined: Jun 2006
Posts: 811
These spammers are brutal. I turned registration off for a few days.

The second I turned it back on, the attempts started up.

From 4:09 to 4:26 a.m., I had 11 spam registrations show up.


Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
spam issues
by ECNet - 03/19/2024 11:45 PM
Looking for a forum
by azr - 03/15/2024 11:26 PM
Editing Links in Post
by Outdoorking - 03/15/2024 9:31 AM
Question on barkrowler and the like
by Mors - 02/29/2024 6:51 PM
Member Permissions Help
by domspeak - 02/27/2024 6:31 PM
Who's Online Now
1 members (Ruben), 476 guests, and 111 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Stones
Stones
by isaac, August 19
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20230217)