Bots Getting Smarter? Re: BorisExpress

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • testbot
    Senior Member
    • Feb 2009
    • 103

    Bots Getting Smarter? Re: BorisExpress

    I'm starting to notice bots getting through captcha especially from .ru.

    One of them started sending PMs to all of our users so we implemented the ol require a few posts before enabling PMs and today BorisExpress posted a thread. It was all gibberish but it still made a post like it knew it had to make posts before it could send PMs.

    Now I'm not even sure if it's a bot or whatever but I search for BorisExpress google style I see that it registered on several boards the same day that it did on my board and several other boards four days before that.

    In theory:
    Bypasses captcha and registers
    Waits a few days
    Try to send PMs
    If can't send PMs because it has to post first it makes garbage posts.

    Anyone else starting to notice this type of activity?

    vb 3.8.2
  • Wayne Luke
    vBulletin Technical Support Lead
    • Aug 2000
    • 74167

    #2
    Build a better mousetrap and you'll attract smarter mice.
    Translations provided by Google.

    Wayne Luke
    The Rabid Badger - a vBulletin Cloud demonstration site.
    vBulletin 5 API

    Comment

    • testbot
      Senior Member
      • Feb 2009
      • 103

      #3
      true

      Comment

      • aussiefooty
        Senior Member
        • Nov 2008
        • 1904
        • 6.0.X

        #4
        Ban their IP address of where they are from. They have a company name such as Googlebot.
        Aussiefootyforums

        New Site New forum
        Come and talk sports all day long


        Comment

        • testbot
          Senior Member
          • Feb 2009
          • 103

          #5
          Originally posted by schwab2clarkson
          Ban their IP address of where they are from. They have a company name such as Googlebot.
          i'm not too concerned about banning their ip addresses because if it's a bot it's prolly spoofed or going through a proxy. if you block a proxy you might block ligament users that enjoy anonymity. if you had to go as far as blocking an ip address then i would do the following instead of using vbulletins features.

          i'm not really looking for a solution to the problem but rather trying to see if other vbulletin users are starting to see the same. i would like to turn theory into fact and then work on a solution.

          Comment

          • Mr Rizla
            New Member
            • Mar 2008
            • 12
            • 3.6.x

            #6
            Im looking at implimenting GeoIP to block ban locations unlikley to use my forum, if interested i have the latest parsed logs and just added another 100+ ip's to my .htaccess file..

            Comment

            • testbot
              Senior Member
              • Feb 2009
              • 103

              #7
              Originally posted by Mr Rizla
              Im looking at implimenting GeoIP to block ban locations unlikley to use my forum, if interested i have the latest parsed logs and just added another 100+ ip's to my .htaccess file..
              that also posses the problem with blocking ligament users that enjoy anonymity.

              i guess implementing methods like that really depends on your final goals. if you have a small site with planned limited growth that that could be a fine solution.

              i use to be a security engineer in a large global corporation and one thing that i always went against was security becoming a road block. there's a fine line when implementing security to block the bad guy and blocking good business.

              our current company is global and can't use tools such as that. if i was looking for a solution for this sort of thing i think *akismet and/or fail2ban would be better options.

              *i haven't used this yet.

              Comment

              • Wayne Luke
                vBulletin Technical Support Lead
                • Aug 2000
                • 74167

                #8
                Originally posted by testbot
                that also posses the problem with blocking ligament users that enjoy anonymity.
                legitimate users?
                Translations provided by Google.

                Wayne Luke
                The Rabid Badger - a vBulletin Cloud demonstration site.
                vBulletin 5 API

                Comment

                • testbot
                  Senior Member
                  • Feb 2009
                  • 103

                  #9
                  Originally posted by Wayne Luke
                  legitimate users?
                  yea haha. not enough coffee in me when i posted that.

                  Comment

                  • hitmancode47
                    Senior Member
                    • Jul 2008
                    • 776
                    • 3.8.x

                    #10
                    if you block a proxy you might block ligament users that enjoy anonymity.
                    You shouldent worry too much about that, as there are hundreds of proxy servers publically avaliable on the web, some even connect from your browser settings (Proxy settings) so a fresh batch of servers are pretty much always avaliable if the person does as you say, like anonymity.
                    Jut a random internet person.

                    A message to all illegal users!

                    Comment

                    • aussiefooty
                      Senior Member
                      • Nov 2008
                      • 1904
                      • 6.0.X

                      #11
                      Try the Question & Answer function in the Human Resources manager. It's probably the best of the lot. You have to get smarter and create the questions that are hard for them to know.
                      Aussiefootyforums

                      New Site New forum
                      Come and talk sports all day long


                      Comment

                      • MRGTB
                        Senior Member
                        • May 2005
                        • 5454

                        #12
                        Originally posted by schwab2clarkson
                        Try the Question & Answer function in the Human Resources manager. It's probably the best of the lot. You have to get smarter and create the questions that are hard for them to know.
                        These days it seems you have to combine a few methods together. Even WordPress users are having to do that these days, as one method is just not good enough alone. I use Akismet on my WP Blog and it's done a really good job of catching all spam so far, which total's about 649 spam comments in only 4 weeks. What a utter joke eh!

                        Already I've chosen to ban a number of IP Address that keep posting the same spam daily that Akismet is catching, as well as enabling admin to authorise all comments before they appear, as well as adding keyword into the spam filter setting. If it wasn't for Akismet doing such a good job, I would have disabled comments all together, or maybe even took the blog down. Seriously, who wants to spend all there time removing spam daily manually. I have Akismet setup to delete all spam itself caught after a certain time frame, which is present in WP.

                        It's a real shame that looking at there site, they don't appear to offer there own vBulletin Akismet official plug-in, because nothing is better than it in my opinion simply because of how it all works.
                        Last edited by MRGTB; Sun 26 Apr '09, 12:36am.

                        Comment

                        • Andreas
                          Senior Member
                          • Feb 2004
                          • 2323

                          #13
                          Erm, vBulletin has built-in Akismet support.

                          Comment

                          • MRGTB
                            Senior Member
                            • May 2005
                            • 5454

                            #14
                            Yes I know, I read somewhere it was released as a hack over at vB.org and vBulletin have added the option in vB to use it of some kind. What I was referring to was the fact if you head over to Akismet own download page they don't appear to be officially supporting it with their own add-on for it. Then again, I'm not sure if the plug-ins listed on that page were created by them looking at were the links lead too.

                            Anyway, I also read that vBulletin won't support Akismet because it makes use of a third party database ie: Akismets database which the Akismet plug-in checks to see if it's reported spam.

                            Link: http://akismet.com/development/
                            Last edited by MRGTB; Sun 26 Apr '09, 1:37am.

                            Comment

                            • Wayne Luke
                              vBulletin Technical Support Lead
                              • Aug 2000
                              • 74167

                              #15
                              Originally posted by MRGTB
                              It's a real shame that looking at there site, they don't appear to offer there own vBulletin Akismet official plug-in, because nothing is better than it in my opinion simply because of how it all works.
                              Why does vBulletin need a plugin when connecting to Akismet is a standard feature on all vBulletin versions since 3.7.0? All you have to do is enter an Akismet API key into the Spam Management Options and turn it on.

                              Originally posted by MRGTB
                              Anyway, I also read that vBulletin won't support Akismet because it makes use of a third party database ie: Akismets database which the Akismet plug-in checks to see if it's reported spam.
                              Where ever you read this is no longer true. We have had Akismet support for a year now. Also offer Typepad Anti-spam support and will probably tie into other Spam Management Services in the future.
                              Translations provided by Google.

                              Wayne Luke
                              The Rabid Badger - a vBulletin Cloud demonstration site.
                              vBulletin 5 API

                              Comment

                              widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                              Working...