WXforum.net
May 24, 2013, 10:50:38 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
Members: 6620  •  Posts: 178767  •  Topics: 18138
Please welcome moranbahweather, our newest member.
Welcome to the the new hosting for WXforum.net.
 
   Home   Help Search Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Whew, lots of drive-by spammer registration attempts...  (Read 3939 times)
0 Members and 1 Guest are viewing this topic.
saratogaWX
Administrator
Forecaster
*****
Offline Offline

Posts: 3741


Saratoga, CA, USA Weather - free PHP scripts


WWW
« on: July 28, 2011, 09:11:37 PM »

It's been busy the last week with over 100 spammer (caught by stopforumspam ) registration attempts which were deleted before registration was completed.  Looks like the spambot registrations have upped their kung-fu and are getting past the latest picture-rotation human test we have installed.

Now off to look for yet another 'human' test to make sure the bots are thwarted.  Course, if the spammers are outsourcing to humans for registrations, then another 'human' test won't make it go away soon.

Yours for a clean and spam-free forum Smile

Ken
Logged

Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis Vantage Pro Plus - FARS, Boltek-PCI/NexStorm, GRLevel3, WD, WL, VWS, Cumulus, Meteohub
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP
DanS
Chiang Mai weather
Forecaster
*****
Offline Offline

Posts: 4305



WWW
« Reply #1 on: July 28, 2011, 09:24:28 PM »

It's amazing to me that people put in so much effort with writing scripts and trying different techniques to get spam through.

Thanks for all your combat work, Ken!
Logged

Dan ThaiWx website
WS-2310/2810 WUHU WinXP 24/7
WeatherBeacon
Chief
Forecaster
*****
Offline Offline

Posts: 1353



WWW
« Reply #2 on: July 28, 2011, 09:29:49 PM »


Thanks for all your combat work, Ken!

Ditto that. I'm sure you do much more behind the scenes for us than we can even begin to imagine. Thanks much, Ken!
Logged

Mae govannen!
Kevin  (Member AMS) http://www.wxbeacon.com               Genesee County, Michigan
Hardware:  Davis Vantage Pro Wireless, Midland WR-300
Software: VWS 14.01p43, WeatherFlash, & GRLevel3
CNYWeather
Forecaster
*****
Offline Offline

Posts: 1386



WWW
« Reply #3 on: July 28, 2011, 09:43:40 PM »

Seems to come in waves. I've got a forum that will get 10-20 in a day.
How do they get past the captcha to register in the 1st place beats me
Logged

Downlinerz2
Forecaster
*****
Offline Offline

Posts: 2929



« Reply #4 on: July 28, 2011, 10:59:11 PM »

   Thanks for the good work!!!  I hope things don't get too much harder with the picture ID tests and such.  I have enough trouble with those already!  Some times I have to move to a second cause I cannot read what is there! Embarassed
Logged
saratogaWX
Administrator
Forecaster
*****
Offline Offline

Posts: 3741


Saratoga, CA, USA Weather - free PHP scripts


WWW
« Reply #5 on: August 01, 2011, 02:15:49 AM »

Well, I've dealt with over 100 blocked spammer registration requests in the last 2 days.. had 31 to 'approve' yesterday morning.  Ha.. approved them to oblivion instead.

Ended up blocking some new IPs for hosters in China, Ukraine and Russia.. now down to a dull roar again (I hope).

Ken
Logged

Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis Vantage Pro Plus - FARS, Boltek-PCI/NexStorm, GRLevel3, WD, WL, VWS, Cumulus, Meteohub
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP
sacreyweather
John Sacrey - VP2 Pro
Forecaster
*****
Offline Offline

Posts: 407


Saline Weather


WWW
« Reply #6 on: August 04, 2011, 07:16:24 AM »

Ken,

I wish to thank you for all of the work you do here, behind the scenes, and the work you have done on the scripts.

John Sacrey
Logged

CWOP: D2073, GR2AE, GR3, WD, PWS/weatherforyou.com, WxWeb,
CoCoRaHS: AR-SL-16, Weatherbug Station No. 25826
Saline Weather
Saline Weather on Twitter
Arthurhh
Senior Contributor
****
Offline Offline

Posts: 251


IT Fixer


WWW
« Reply #7 on: August 04, 2011, 07:42:59 AM »

Forum and forms spammers are a fact of life on the internet today.

It costs 0.000025c cents to have a slave labour nation employee pass the tests of catchpa and attempt to spam.

I get it a lot on my contact forms, my filters deal to it. I have about 3000 rules in my filters on these acconts most are word/phrase based very few are IP based.
Ideal a lot with the China/Russia and ickistan countries so canot just block /24 IP ranges.

I work for one of the largest compnies in my country (New Zealand we see the world before you do) Our mail servers dealt with 2.7 million emails last month we rejected nearly 90% as spam. Failure rate on rejection by our filters was under 1% But the cost to us of running a system like this is huge.


Logged

saratogaWX
Administrator
Forecaster
*****
Offline Offline

Posts: 3741


Saratoga, CA, USA Weather - free PHP scripts


WWW
« Reply #8 on: August 04, 2011, 02:52:17 PM »

Think I've found the root cause for the spambot invasion over the last few days.. appears a Russian spambot called Xrumer (wikipedia entry here has likely done an automated decode of the stock image sets included with the notCaptcha mod ... so, I've crafted a new set of images to use.. let them decode that Smile

Arthur is right.. spam is cheap.  Hosting is cheap.  Spambots are improved by Russian/Chinese/Roumanian/Ukrainian folks all the time, so it's a arms-race to keep them out.

I'll keep you posted...

Best regards,
Ken
Logged

Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis Vantage Pro Plus - FARS, Boltek-PCI/NexStorm, GRLevel3, WD, WL, VWS, Cumulus, Meteohub
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP
TNETWeather
Kevin Reed (KrelvinAZ)
Senior Contributor
****
Offline Offline

Posts: 193


Davis Vantage Pro2+ with full FARS


WWW
« Reply #9 on: August 04, 2011, 03:25:32 PM »

Funny but the number 1 spam I get on my contact forms is an India SEO company looking for business.  I rarely get any other spam.   I use a system that uses StopForumSpam with a rDNS system which then if it gets a hit actually checks the SFS database to get the details.  Been pretty good.

Most of my forums are private, meaning you have to be a member to get an account so there is no big issue there.  New accounts are created when they sign up for a membership at a meeting.  No online signups, just renewals.
Logged


All you need is Time, Aptitude and Desire ... and you can build just about anything...
saratogaWX
Administrator
Forecaster
*****
Offline Offline

Posts: 3741


Saratoga, CA, USA Weather - free PHP scripts


WWW
« Reply #10 on: August 04, 2011, 03:40:02 PM »

We use stopforumspam, httpBL, reCaptcha, and notCaptcha to help keep this forum free of spambot registrations .. the notCaptcha was defeating them fine until the XRumer spambot was 'updated' to decode the default set of icons.  Now with custom icons, I'm hoping they will be defeated again (as they were until the XRumer update).

I too get the SEO spams on various contact forms .. all from .in addresses.  I just route 'em to the junk and they are no longer a bother either Smile

Best regards,
Ken
Logged

Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis Vantage Pro Plus - FARS, Boltek-PCI/NexStorm, GRLevel3, WD, WL, VWS, Cumulus, Meteohub
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP
mackbig
Forecaster
*****
Offline Offline

Posts: 4076



WWW
« Reply #11 on: August 04, 2011, 03:51:32 PM »

"We are a leading India based SEO company providing the best search
engine optimization services........................................ "

I think I got my first one of these a week after putting my contact-us on my site.  d'oh!  After the 20th I think I blocked most of India in my htaccess

Andrew
Logged


Andrew - Davis VP2+ 6163, serial weatherlink, wireless anemometer, running Weather Display.  Boltek PCI Stormtracker, Astrogenic Nexstorm, Strikestar - UNI, CWOP CW8618, GrLevel3, (Station 2 OS WMR968, VWS 13.01p09), Windows 7-64
saratogaWX
Administrator
Forecaster
*****
Offline Offline

Posts: 3741


Saratoga, CA, USA Weather - free PHP scripts


WWW
« Reply #12 on: August 05, 2011, 10:58:52 AM »

Spambot registrations thwarted with a new set of images for the notCaptcha.  Only 4 manual spammer registrations overnight (instead of the usual 30 or more).

So.. shields are now up again.

Please let me know via a 'report to moderator' if one manages to make it through the gauntlet and post a spam.

Best regards,
Ken
Logged

Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis Vantage Pro Plus - FARS, Boltek-PCI/NexStorm, GRLevel3, WD, WL, VWS, Cumulus, Meteohub
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP
WeatherBeacon
Chief
Forecaster
*****
Offline Offline

Posts: 1353



WWW
« Reply #13 on: August 05, 2011, 04:17:05 PM »


Thanks a lot, Ken!
Logged

Mae govannen!
Kevin  (Member AMS) http://www.wxbeacon.com               Genesee County, Michigan
Hardware:  Davis Vantage Pro Wireless, Midland WR-300
Software: VWS 14.01p43, WeatherFlash, & GRLevel3
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!
Page created in 0.087 seconds with 19 queries.