Go Back   Pligg CMS Forum > Pligg Help > General Help

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-10-2008, 05:38 AM
New Pligger
 
Join Date: Apr 2007
Posts: 22
Thanks: 0
Thanked 0 Times in 0 Posts
SOLUTION for "site was hacked" !!!

In the last few days, I had a lot of attacks on my website.
The single step registration works perfect, but the attacker are still there. Thatīs a lot of traffic and my cpu load get up to 90-100%.....:devil:

The solution is:

Put this code in your .htaccess!
Works perfect!


#Block pycurl bot
RewriteEngine on
RewriteCond %{HTTP_USER_AGENT} ^pycurl/ [NC]
RewriteRule .* - [F]
Reply With Quote
  #2 (permalink)  
Old 01-10-2008, 07:46 AM
Divisive Cotton's Avatar
Pligg Donor
 
Join Date: Sep 2007
Posts: 219
Thanks: 2
Thanked 12 Times in 7 Posts
But what does this code do?!
Reply With Quote
  #3 (permalink)  
Old 01-10-2008, 07:57 AM
graphicsguru's Avatar
Pligg Donor
Pligg Version: 9.9.5
 
Join Date: Aug 2006
Location: USA
Posts: 416
Thanks: 75
Thanked 48 Times in 36 Posts
that only helps it will not stop them 100%

its from Hackers using PyCurl to bypass registration

you can see some on the morons on Pligg Beta 9 / Upcoming

add them to your ban urls
Reply With Quote
  #4 (permalink)  
Old 01-10-2008, 08:12 AM
Constant Pligger
 
Join Date: Oct 2006
Posts: 125
Thanks: 3
Thanked 1 Time in 1 Post
Quote:
Originally Posted by graphicsguru View Post
that only helps it will not stop them 100%

its from Hackers using PyCurl to bypass registration

you can see some on the morons on Pligg Beta 9 / Upcoming

add them to your ban urls
Thats scary, if pligg demo in developers site is like that, its a thing to get worried about.

Anyways, its seems as pligg is dieing, maybe its time to hire a programer, who knows.

Or developers are still here ?

Because it seems all questions are just get ingnored, no matter about what.
Reply With Quote
  #5 (permalink)  
Old 01-10-2008, 08:37 AM
graphicsguru's Avatar
Pligg Donor
Pligg Version: 9.9.5
 
Join Date: Aug 2006
Location: USA
Posts: 416
Thanks: 75
Thanked 48 Times in 36 Posts
NOT sure how the plidd demo members are submitting the stories simple sign up and post is my guess

NOT sure if the pligg demo has and mods my guess is NOT


I am using all the pro and member developed mods to help fight spam and splog

I am use the code above its not going to stop a retard from joining and making a post
Dream Day First Home Game Download At Palygame made one post today on my site its gone now banned

what I get is 2 to 5 signing ups that don't read my terms not pligg fault at all "we banned them all"

no way is anyone going to keep a successful pligg site bug free spam free by themselves

if you find them on the pligg demo its a 99.9% chance your going to see the same post on digg are you saying digg needs to hire new developers
Reply With Quote
  #6 (permalink)  
Old 01-10-2008, 09:50 AM
Casual Pligger
 
Join Date: Jan 2007
Posts: 47
Thanks: 4
Thanked 7 Times in 5 Posts
Hi all,

I am quite confident that Bad Behavior, and standard, heavily used plugin in the Wordpress community, is an excellent solution to this problem. Bad Behavior is designed to stop all types of bots. Combined with Akismet, which is designed to stop manually entered spam, Pligg would have excellent protection. It is beyond me why the Pligg developers have never incorporated these simple protection mechanisms into the base product (at least the option to turn them on). It is impossible to have maintain a clean, heavily used site without these protections.

In addition, I would like to have the Google Safe Browsing API incorporated into the base application, in order to minimize Google blacklisted pages suspected of phishing and malware.

I would like to build a Pligg site on Links.com that will be designed to highlight new sites on the web, but I need to incorporate these APIs as well as a new skin before I can do it. If there is a developer who can take on this assignment, please contact me.

Rich
Reply With Quote
  #7 (permalink)  
Old 01-10-2008, 10:06 AM
Casual Pligger
Pligg Version: 9.8.2
Pligg Template: Vera
 
Join Date: Dec 2007
Posts: 64
Thanks: 6
Thanked 1 Time in 1 Post
Quote:
Bad Behavior is designed to stop all types of bots. Combined with Akismet, which is designed to stop manually entered spam, Pligg would have excellent protection.
Co-sign, don't know if it's something easy to do fro pligg (I guees it's not), but co-sign :)
__________________
Esto Se Sale 2.0
Reply With Quote
  #8 (permalink)  
Old 01-10-2008, 10:14 AM
Casual Pligger
 
Join Date: Jan 2007
Posts: 47
Thanks: 4
Thanked 7 Times in 5 Posts
Hi,

I briefly read the spec on Bad Behavior. I think it is straightforward enough that even I could do it, and I know practically nothing about Php programming. However, since I need to do a few things, I thought I would seek out an experienced Pligg developer and pay for it. I have a local guy, who is really sharp, and I will contact him. If I come up with a solution, I will share it with the group.

Rich
Reply With Quote
  #9 (permalink)  
Old 01-10-2008, 12:30 PM
Divisive Cotton's Avatar
Pligg Donor
 
Join Date: Sep 2007
Posts: 219
Thanks: 2
Thanked 12 Times in 7 Posts
Bad Behaviour is too strong a solution Rich - it can interfere with legit traffic
Reply With Quote
  #10 (permalink)  
Old 01-10-2008, 12:36 PM
Casual Pligger
 
Join Date: Jan 2007
Posts: 47
Thanks: 4
Thanked 7 Times in 5 Posts
Hi,

Yes, it is true that Bad Behavior can stop some legit traffic - but very rarely. It is a compromise that needs to be made, for without it, the whole site goes down. I get about 2000 visits per day. I can't afford to have rubbish all over the place, so if a legit user is stopped every once in a while (it may happen once a month or so), it is the compromise I have to make. Without it, for me, Pligg is totally useless. Every blogger makes their own decisions, since the Wordpress Bad Behavior is a plugin. Most successful blogs, with high traffic, need to use Bad Behavior or an equivalent. It is unfortunate that the Pligg development team does not understand yet, that no Pligg site can be highly successful without top of the line spam protection. It is like building an expensive mansion without a lock on the front door.

I have a developer working on the problem right now. If it works, will share it with other users.
Reply With Quote
Reply

Thread Tools
Display Modes
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Similar Threads
Thread Thread Starter Forum Replies Last Post
Poll: A Solution For Speed Problem xenfra General Help 10 07-14-2008 12:57 AM
Parse error, parse error, Parse error: A 'concrete' solution available? nothingman General Help 6 06-06-2008 01:28 AM
Stop Pligg blank@blank.com Spammers. A possible solution. oriolhernan General Help 2 05-22-2008 12:25 AM
Register Error (Solution) - Post Issues Here skins4webs Bug Report 46 04-04-2008 05:08 AM
Easier solution for adding MANY categories? blaze General Help 6 01-21-2008 04:48 AM


Search Engine Friendly URLs by vBSEO 3.2.0