Just wondering if anyone has been seeing this lately, i have had several over the last couple weeks.
New members have joined using a uk.yahoo.com email address. I found this strange because my board wouldnt be something the someone in the UK would know or care about.
So i google the member name, and low and behold there a pages of profiles for the same member each form a different board...ALL with NO activity( zero posts). MANY of them , if not MOST of them ( the accounts)created in the last couple days.
I have just deleted these members, and the idea to check here came after i killed the accounts so i dont remember the names to recheck anything...
I don't recall if all the hits were SMF only boards and very few had and external linking( like profile websites).
Just wondering what this could be about, seems fishy, perhaps an exploit in SMF they can or are going to take advantage of?
I've noticed a few, but I don't think its an exploit. Its just they are registering through some automated process.
What are your Visual Verification settings?
I'd recommend at least medium.
Maybe even try my 'Are You Human Mod'
http://custom.simplemachines.org/mods/index.php?mod=999
My visual verification is actually on "high". Wonder if there is indeed an automated process that can get through THAT now.
Not a big deal yet, haven't seen enough to be bothersome, just wondering what they are up to really.
May use that mod if it gets more prevalent.
I haven't seen any automated bots capable of getting passed high.
However there are some semi-automated bots which can
(basically either through a trick website, they get a real human to complete your captcha, and then the script does the rest)
And I've heard about teams of people for hire in china who manually complete thousands of them.
There isnt much you can do about either of them.
Lainaus käyttäjältä: karlbenson - joulukuu 21, 2007, 05:17:19 AP
Maybe even try my 'Are You Human Mod'
http://custom.simplemachines.org/mods/index.php?mod=999
Thank you KarlBenson for that very helpful suggestion. For what it is worth, I saw new accounts created today on 2 different domains running SMF with the same user name in each case, using an email address at yahoo.co.uk. In each case the new "user" came from an IP address for a server in Israel that is running wi-fi hotspot software. I have firewalled that IP address from my server, but of course it is just a drop in the bucket.
Per your suggestion I installed the Are You Human mod, but if it is humans creating these accounts, well, oops.
I also routinely block entire Chinese ISP netblocks to defend against various types of attacks against my server.
It certainly is a constant battle between the good and the spammers.
This is exactly the same sort of thing that I was "discussing" (complaining) about in another part of the board.
I get 20- 30 spambot applications a DAY- all testing to determine the level of email/ member verification on the site. 90 % will always be inactive as are using fake email addresses. I've seen one site with 6000, yes 6000 inactive members.
2-3 spambots a DAY will post an actual message whereupon I ban their email addresses.
The problem is, and IMHO both SMF and phpBB are derelict in this respect, is that both products :
a) lack the ability to block non successful applicants from placing their names as members
b) lack the ability to mass delete member name- it is actually a five- step process to delete any member on phpBB
AND ITS BLOODY UNFAIR for the board designers to place their heads in the sand and pretend the problem isnt there.
BTW Merry Christmas and a Happy New Year from Australia
regards
On my forum I rarely got spam applications, maybe 1 or 2 a month.
Even then its extremely rare for them to post. (maybe 1 every quarter).
As suggested above, those people who have installed my 'Are You Human Mod'
http://custom.simplemachines.org/mods/index.php?mod=999
Are getting almost no spambot registrations whatsoever
I have this problem too. A person signs up and put lots of URLs at his signature. I googled his username and found him signing up to lots of forum at the same time with the same sig. Maybe for putting his link to increase his site's PR?
Indeed, trying to obtain backlinks to count towards PR.
There isnt much you can do, a determined spammer will always get through.
But you can cut out 99.99% of spammers/bots by fine tuning smf settings (visual verification to at least medium) and other mods which are available.
The funny thing he activated his membership, does it means he's a human?
BTW, through the IP, he is from Israel.
Luckily my forum rules limit the number of links in signatures. ;)
Lainaus käyttäjältä: karlbenson - joulukuu 25, 2007, 01:17:31 IP
Indeed, trying to obtain backlinks to count towards PR.
Maybe someone needs to create a mod that will, at admins discretion, diasble links and or images in signature. hint :D
-shacon ;)
Like my Prevent Signature Images and/or Links mod
http://custom.simplemachines.org/mods/index.php?mod=921
;)
(set a min post count before they can use them)
Exactly
-shacon ;)
Lainaus käyttäjältä: karlbenson - joulukuu 25, 2007, 02:07:37 IP
Like my Prevent Signature Images and/or Links mod
http://custom.simplemachines.org/mods/index.php?mod=921 (http://custom.simplemachines.org/mods/index.php?mod=921)

(set a min post count before they can use them)
Wow.. that look nice.. will try it out soon. ;)
thanks.