vBulletin And SpamBots

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Bradley_Wint
    Member
    • Jul 2007
    • 51
    • 3.7.x

    vBulletin And SpamBots

    Hi folks, I was just wondering, how susceptible is vb to spambots? I remember phpbb2 suffered terribly from this, does vb share in the pain or does it keep them out? Cheers.
  • Steve Machol
    Former Customer Support Manager
    • Jul 2000
    • 154488

    #2
    Please see this: How to Reduce Spam and Registration Bots
    Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
    Change CKEditor Colors to Match Style (for 4.1.4 and above)

    Steve Machol Photography


    Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


    Comment

    • Freesteyelz
      Senior Member
      • Jan 2006
      • 530

      #3
      In addition at vB.org there are several mods that target spam.

      Comment

      • Zachery
        Former vBulletin Support
        • Jul 2002
        • 59097

        #4
        None of which are nessary with the proper options set for the vBulletin capcha.

        Comment

        • Dean C
          Senior Member
          • Mar 2002
          • 4571
          • 3.5.x

          #5
          The CAPTCHA is inaccesible. I'd rather use accessible techniques than image verification any day.
          Dean Clatworthy - Web Developer/Designer

          Comment

          • ChrisLM2001
            Senior Member
            • May 2003
            • 1451
            • 3.6.x

            #6
            Just keep in mind that no registration verification can stop a human from filling out the form, then releasing the bots afterwards. Like with any security, if the bad guys want in, they will get in. And that's the limitations of technology and being public with it -- so no matter who or what it is, spam will exist as long as humans want to spam it.
            "Anyone who conducts an argument by appealing to Authority
            is not using his intelligence, he is just using his memory."
            ~~~
            Leonardo da Vinci

            Comment

            • class101
              Senior Member
              • Sep 2007
              • 165
              • 3.6.x

              #7
              I dunno if you can call the phpBB2 a CAPTCHA dude, at least the on in the BB3 stops bot, the one in BB2 stops nothing at all, the one in vB is far much advanced and hardly breakable + NoSpam plugin found on vbulletin.org, it just stops all.
              security community

              Comment

              • Kurisu
                Member
                • Aug 2002
                • 36
                • 3.6.x

                #8
                Originally posted by Zachery
                None of which are nessary with the proper options set for the vBulletin capcha.
                There are already bots which can verify the e-mail adress and bypass CAPTCHA.

                Comment

                • Steve Machol
                  Former Customer Support Manager
                  • Jul 2000
                  • 154488

                  #9
                  Originally posted by Kurisu
                  There are already bots which can verify the e-mail adress and bypass CAPTCHA.
                  I've never seen any proof of that.
                  Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
                  Change CKEditor Colors to Match Style (for 4.1.4 and above)

                  Steve Machol Photography


                  Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


                  Comment

                  • Dean C
                    Senior Member
                    • Mar 2002
                    • 4571
                    • 3.5.x

                    #10
                    Dean Clatworthy - Web Developer/Designer

                    Comment

                    • Wayne Luke
                      vBulletin Technical Support Lead
                      • Aug 2000
                      • 74149

                      #11
                      Originally posted by Dean C
                      That system requires them to download the image and manipulate it to store the result. They are basically building a rainbow table for captcha. If you're site uses a custom font list and custom background images then it would be like salting your MD5 hashes to break rainbow tables. With vBulletin you could easily change the fonts and backgrounds used on a regular basis as well. Just build several sets and switch them out every month or so. The humans won't notice the difference but it would take ages for a machine to get a captcha that has been decoded and recognizes.
                      Translations provided by Google.

                      Wayne Luke
                      The Rabid Badger - a vBulletin Cloud demonstration site.
                      vBulletin 5 API

                      Comment

                      • Freesteyelz
                        Senior Member
                        • Jan 2006
                        • 530

                        #12
                        I've been quite happy with the Prevent Spam Post mod. So far it has captured every spam posting attempt without any false positives.

                        Comment

                        • Lenni
                          Senior Member
                          • Aug 2004
                          • 758
                          • 3.6.x

                          #13
                          I currently run a phpBB with an additional Spam Protection since I was getting flooded with Spam. Now there's a system in place that will ask simple questions. For example: 4 + 3 is? ... Yeah! 7. Since you can add your very own custom questions and answers, this successfully keeps spam bots from registering. I would like to see something like this built into vBulletin.
                          selling kawaiiNation.com

                          Comment

                          • Steve Machol
                            Former Customer Support Manager
                            • Jul 2000
                            • 154488

                            #14
                            This is already built into vB. Just create a new custom Profile Field and make it required. See this thread:

                            Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
                            Change CKEditor Colors to Match Style (for 4.1.4 and above)

                            Steve Machol Photography


                            Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


                            Comment

                            • RedTyger
                              Senior Member
                              • Dec 2006
                              • 335
                              • 3.8.x

                              #15
                              Originally posted by rin
                              I currently run a phpBB with an additional Spam Protection since I was getting flooded with Spam. Now there's a system in place that will ask simple questions. For example: 4 + 3 is? ... Yeah! 7.
                              There are already bots that can read mathematical questions for that kind of registration and personally I think its a very misguided idea. It may be readable across languages, but it is a question that comes easily to computers to say the least. All they'd have to do is learn to look for it the sum, they wouldn't have to work at solving it at all.

                              Not that I have an ingenious alternative, unfortunately.

                              Comment

                              widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                              Working...