A couple of weeks ago I upgraded to the new tp 1.0.beta3. ever since. My membership went crazy with spam from FAREAST, RUSSIA, AFRICA, IPs.
I had to turn off member activation, and install member approval. Still I get many spam members each day
any ideas?
H
Please read the Posting Guidelines.html (http://www.tinyportal.net/index.php/topic,581)
Have you tried any of the security mods at SMF? There are a few, number puzzles, question / response, and one I personally use is reCAPTCHA. Although I haven't yet upgraded to TP B3 yet as I need to do it manually and I haven't had the time, I haven't had one single spam bot successfully register and activate an account since installing it. I was getting loads.
We really need more information from you. Any errors in logs, point of entry.. Portal, SMF or server.
Mods.. etc.
TP has nothing to do with the registration process of SMF.
I suggest you do what Zetan said and get one of the security mods at SMF. I use the one named Anti-Spam Verification Questions and it has stopped all spam/bots at the TPM site and a gaming clan site I run, plus others.
Quote from: Renegd98 on March 01, 2009, 04:26:11 PM
TP has nothing to do with the registration process of SMF.
I agree, but we also need to consider Guest shouts, comments in articles.. although I'm not quite sure where we are with guest comments in articles.
True True... but having the Guest be able to shout is a no brainer.. IMHO.
Have guests do anything but read content is a no brainer all together, to much horrid softwares out there that can mess up a lifetime of work in seconds.
Yup.. but it is an option!
I've been to many sites with an open shoutbox. Take the option away and people will ask for it to be put back again.
I doubt this has anything to do with the shoutbox, but we've had no response from hygron...
OK. you asked for more info. I don't know if you want the IP posted or not
If this is against board policy (TPTeam) Please delete the IP immediately.
IP 194.8.75.230 Guest error message
2: strstr() [<a href='function.strstr'>function.strstr</a>]: Empty delimiter
File: /home/hygron/domains/hygronomics.com/public_html/forum1/tp-files/tp-modules/TPAdvShout/Sources/TPAdvShout.php
Line: 3639
So it is a possible IT does have something to do with the advshout. Isn't that what this shows? Or; Does it show that a hack attempt on advshoutbox, failed?
BTW. I don't allow guest shouts. I will have to look and see if I allow guests to view advshoutbox, but I don't think I do.
Thanks for the conversation. Later h
p.s. I reeiterate. I never had an issue until I upgraded to beta3. Which is why I brought this to my friends here @ TP 1st.
Not complaining.
Some of you all know me. I try to help & get help, where I can, and thought this was worthy of The Teams, attention. ;)
Advanced shout isn't supported any more Hygron. Its outdated, and needs a lot of TLC to bring it back up to a working condition. You should use the simple shout instead for now.
Well dadgum... Mine adv shout is working, I just found these errors. I will look into changing over..
Thanks Ich
Just for the record. I turned off the advanced shoutbox module
and, turned on the simple shoutbox, all "shouts" transferred right over, and all the smiley's, and bbc buttons appear to work. Great Job Bloc, and TPteam.
I haven't had the time to read up all the threads in a long time. I had no idea, didn't realize that advanced was outdated.
I like the functioning look of simple shoutbox just fine.
Referring to original spam comments.: I have not had one spambot get through since I went to manual user approval. I will look into recaptcha Mods @ SMF. I never thought they were necessary before, and I just don't particularly want to download every Mod that comes along. Zetan thanks the suggestion, & for posting the link to posting guidelines 8)
Thanks for the help Ichbin, Hey G6. Peace to the rest of you. :)
I will say, I put the recaptcha mod in and all but eliminated the spam on my sites. I had them setup for manual approval anyway, but would still get 5-10 "applications" a day from bots, the recaptcha and stopforumspam mods got ride of most of those. Now I may have 1-2 a month to deal with. Also the stopforumspam.com mode works really well. Hope it helps you... --Mitch
I can't say I've had any since installing reCAPTCHA.. but then I also have member activate by email, which only a few spam bots ever did. new members must post in the welcome board before they can post anywhere else.
Welcome Topic mod sorts that, either they start their own topic from the prompt in a 0 post member targeted banner (say that sober)... or they reply to the Welcome Topic. They have 1 PM limit as a 0 post member, use it wisely.. just in case they need to PM a staff member.
OTT? Yeah, so is spam. I get at least 20 unsuccessful registrations a day.
Thinking about it.. I may remove the option to start a new topic in the Welcome Board and only allow them to reply to topics in that board, their welcome topic. Once they have made their first post there, the restrictions start to lessen.
I did something similar to this. About a month before all those spammers were prevalent back in November, I installed the "Default MemberGroup on Registration" Mod and setup all new members to go into a "Provisional Member" group. I then setup 1 board that this group could post into that was invisible to everybody else on the Forum and setup a top block that is only viewable to that group to instruct them that this was the only board they could post into until approved (see image below).
Since I did that, I have only gotten 1 registration that wasn't legit. It worked pretty well.
ZarPrime
Thats a great idea Zar. I will keep this in mind for possibly other reasons too.
Yeah, I don't know how I had the foresight to actually do this before all the spammers hit but I'm glad I did. It's saved me a lot of headaches. ;)
ZarPrime
I love that idea Zar...I will have to look closer into that. The site I am working on now (which you have been a great help with as well thank you!!!) Is a mostly member only board. Have to be a member of USSMA in order to have full access. I plan on having "guests" allowed to view the gallery and most of the articles and public forums, the next level would be a registered non-ussma member. Will be able to post to a couple of the real public forums, to get info about USSMA and such.. Then, if you are a USSMA member, you have full access....
Have to figure out how I can fit what you did into my scheme...
--Mitch
It's not that difficult to setup and it works very well. I let everybody (guests and provisional members alike) view most of the Forum, except a few boards that are only available to the leaders of their races. Guests can't post anywhere and Provisional Members can only post in that one board. That New Member block is only visible to the "Provisional Members" the new members who were automatically placed into that membergroup upon registration. Once we approve them, I remove them from the provisional member group. This places them in as a regular member (no group) where they can post to the boards that are visible to them. Works good. :up:
ZP
Thanks for all the support on this. Actually, I went into admin, and changed the registration to the hardest captcha, and no bots since.
I love the provisional member group. Great idea.
H
Your being hit from british virgin isle and I had the same a few weeks back.Just add a ban for the Ip range like this 194.8.74-75.* It will kill the entire range the mofo is using and save you having to ban them one by one as they appear.
Best thing you can do IMO is to install a couple of registration mods to keep the bots from registering. This will cut your spam in a major way. The next thing you can do, is install the mod that doesn't allow a user to post links. I've done this on my forum so that you can't post a link until you have 10 posts. This keeps the human spammers from spamming. :)