Customizing SMF > Portals, Bridges, and Integrations
Anyone here working with CloudFlare/HoneyPot antibot software?
prince_bear:
I have Bad Behaviour, and http:BL running currently on a SMF 2.0 RC3 Forum. I am currently running into problems with legitimate users from sometimes questionable IPs hitting the http:BL captcha multiple times, over the course of several days. Would Cloudflare offer a solution by analyzing their usage to determine that they are just normal users, or because they are coming from questionable IP's just dead-end them faster?
butchs:
No. CloudFlare is written by the guys who made ProjectHoneypot so if your members are getting flagged with httpBL they will get flagged with CloudFlare. Both offer human confirmation questions with set time limits.
prince_bear:
Thank you, I was kinda suspecting that. I will keep searching and learning about forum security in the rougher parts of cyberspace.
spamtrawler:
Hey Prince_Bear,
ProjectHoneypot have 2 values which may be interesting in your case:
Last Seen
and
ThreatLevel
When developing our software, we learned that these 2 values can make a huge difference in regards to "false positives"
Fighting spam can be a tough nut to crack :)
For any questions, please feel free to ask.
Cheers
SpamTrawler
prince_bear:
Thanks for that note spamtrawler
My question would be how do those values help me, if I have legitimate users coming from questionable IPs? They are getting flagged at a certain threat level based on the spam usage of those IPs, but those IPs are shared by hundreds if not thousands of clients. Most of those clients are not the problem, but the bad apples are ruining the batch for everyone else.
Only thing I can think of would be to place a "trusted cookie" on the user's machines after they have gotten through the captcha so that even if they are coming from a questionable IP they would be flagged as safe. Then you only have to worry about the public computers, which are accessing the forum.
Navigation
[0] Message Index
[#] Next page
[*] Previous page
Go to full version