News:

SMF 2.1.6 has been released! Take it for a spin! Read more.

Main Menu

Help!!! Spammers suddenly attacking all my SMF forums!!!!

Started by catfished, November 11, 2008, 12:35:46 AM

Previous topic - Next topic

catfished

All forums have been updated to 1.1.7 and all of a sudden spammers are breaking the CAPTCHA and posting spam all over the place. There are several forums being affected and they are all have a totally different user group, several of them are not mine, they are owned by some of my hosting clients on the same server. I also have one MyBB forum on the server and it's not affected so far so I'm thinking it's a problem with SMF.

Is anyone else experiencing this, especially after upgrading to 1.1.7??
You use and like this forum software? Then show your appreciation and support by becoming a Charter Member.



CatfishEd.com

Deprecated

SMF 1.1.7's anti-bot protection is dismal. I couldn't keep the bots out until I upgraded to SMF 2.0. I suggest you do the same. PM me if you want the URL to my forum with guest posting enabled, and you can try it out yourself.

I couldn't find any mod packages for 1.1.x that worked at all, or at least none solved my problem in my guest posting boards.

catfished

Quote from: Deprecated on November 11, 2008, 12:53:45 AM
SMF 1.1.7's anti-bot protection is dismal. I couldn't keep the bots out until I upgraded to SMF 2.0. I suggest you do the same. PM me if you want the URL to my forum with guest posting enabled, and you can try it out yourself.

I couldn't find any mod packages for 1.1.x that worked at all, or at least none solved my problem in my guest posting boards.

Thanks for your reply Deprecated. Are you saying this is with guests posting? My problem is that spam bots are breaking the CAPTCHA images and registering, then posting spam. I do not have guest posting enabled on any forums. If this is due to the 1.1.7 upgrade, then maybe I should try and downgrade them.

I thank you for the suggestion to upgrade to 2.0 but I'm a bit leary of using beta releases. I hate to say this but if there turns out to be no solution in a day or two, I'll strongly consider changing all my forums to MyBB. :-[
You use and like this forum software? Then show your appreciation and support by becoming a Charter Member.



CatfishEd.com

larryinla

I'm experiencing the same issue. I upgraded to 1.1.7 this afternoon and five hours later I've had 10 spam posts. I haven't had that many since I put up the board! It's just a small board for my old band but we've got kids that use it and these posters are just the worst!

Are the SMF developers going to do something abou this ...?

computel

This is something new it started after I upgraded toi 1.1.7 can I stop this if I uses a mod like are you human?

I don't want to upgrade to 2.0 till it is out of beta.

catfished

Quote from: computel on November 11, 2008, 01:22:13 AM
This is something new it started after I upgraded toi 1.1.7 can I stop this if I uses a mod like are you human?

I don't want to upgrade to 2.0 till it is out of beta.

Quote from: larryinla on November 11, 2008, 01:20:15 AM
I'm experiencing the same issue. I upgraded to 1.1.7 this afternoon and five hours later I've had 10 spam posts. I haven't had that many since I put up the board! It's just a small board for my old band but we've got kids that use it and these posters are just the worst!

Are the SMF developers going to do something abou this ...?

So it seems it's not just me. Thanks for your responses, now I can go to bed knowing it's an SMF problem which I'm sure will be addressed promptly. (crossing my fingers) :-\
You use and like this forum software? Then show your appreciation and support by becoming a Charter Member.



CatfishEd.com

Deprecated

I've had my guest posting enabled since about a day after the SMF 2.0B4 came out. I haven't had more than maybe 1-2 spam posts since then (guessing, another admin or a mod might have deleted 1-2 without telling me).

I haven't had any 'bot registrations since then. The same security protects both guest posting and member registration.

But think about it. I've got guest posting enabled! If the bots can't crack that, how likely are they to actually register accounts?

And think about this: You say you're leery about 2.0 features being flakey, but how flakey is your 1.x that you get all those spammy posts?

I've been running 2.0b3.1 for about 4 months now, combined with 2.0b4 since it got released. The issues have been mainly upgradeing and appearance, and only a very few pesky issues like the totalMembers bug.

Compare the time you spend deleting spam accounts and posts with the time you might spend fixing 2.0 beta problems.

Deprecated

And to add to the two replies while I was composing my post:

This is the first I've heard of any suggestion that 1.1.7 is any different than 1.1.6, and from what I've heard of the few changes to fix 1.1.6 (the "sesc" stuff) I find it hard to believe that 1.1.7 is any more spam-prone than 1.1.6.

You should provide more data than mere anecdotal comments that "there seems to be more spam posts."

We'll help you fix it if there is a real problem though.

computel

I just upgraded and then I started getting these fake accounts bypassing the  visual verification image. I'm lucky I leave all new accounts a not validated till I look at them. I installed are you human mod to see if they can bypass that. I now there is software to by pass  visual verification image.

Never happened on 1.1.6. Strange

Deprecated

I never found any mods to help 1.1.x and I doubt you will either. As far as I can tell the only way to keep out spam posts and spam accounts is to upgrade to 2.0. I never wiped out the spam until I upgraded, and now I don't even get spam on my guest posting areas.

seroxatmad

#10
Hi all

I upgraded to 1.1.7 on Sunday and this morning I have a .ru registered email awaiting approval!

It may just be coincidental but its my first ever attempt to register by a .ru address and its since upgrading

Regards

John

P.S The e-mail to my forum e-mail address was FROM my forum site title!

thenepalgallery

Quote from: seroxatmad on November 11, 2008, 02:50:17 AM
Hi all

I upgraded to 1.1.7 on Sunday and this morning I have a .ru registered email awaiting approval!

It may just be coincidental but its my first ever attempt to register by a .ru address and its since upgrading

Regards

John

P.S The e-mail to my forum e-mail address was FROM my forum site title!

yup same thing is happening to my forum also

never saw any user with .ru email in my forum before

what should we do, should we approve
a site of nepal, its places, religion, fetes, festivals

Lotti


wmcintosh

#13
I have disabled registrations on my forum, had 16 new members (from various countries) right in a row, got tired of it, now when you click registration there is a link on how to become a member, same IP's viewed the forum the link goes to, but no one have asked to become a member in the only forum I allow guests to post in, yet.

I can deal with spam posts, but not members joining just to spam.

Banned are...
*@list.ru
test @ yopmail.com (seems to be everywhere)
*@lullar.com
*@moviedownloadslibrary.com (this is was a big one)

bootnut

had 60 members yesterday, 12 new members over night all of them spammers, i upgraded to 1.1.7 hoping it would fix it but a guy signed up straight after with a funny account name...

I might look at going on to SMF2 like the dude above said, easy to switch over?

wmcintosh

I'm not willing to go 2 till its out of beta, not even RC's when the time comes.

zigzag

Same here, I upgraded from 1.1.6 and bam I am totally inundated with spam users, they seem to be able to get past the captcha and so can login, and it's getting worse I've spent the last hour pressing the ban button as one after another signs up. I really don't want to disable registration but looks like I'm going to have to.

hurtdidit

I've got several forums still running 1.1.6, and one with 1.1.7.   All were hit by this recent surge of spammers.

Would seem someone figured out a way around SMF's CAPTCHA, not even the latest versions though.

phedo

My forum got some spam registrations and post overnight, too. It was a 1.1.6 (now it is running 1.1.7) - so I think it is not a 1.1.6 problem.

I'm thinking about to go to SMF 2.0 but I'm also not sure because of the beta-status. :-/

zigzag

Just after posting here I installed the Are You Human Mod? http://custom.simplemachines.org/mods/index.php?mod=999 and so far (touch wood) they seem to have stopped.

Advertisement: