Go Back   Pligg CMS Forum > Pligg Help > General Help

Reply
 
LinkBack Thread Tools Display Modes
  #51 (permalink)  
Old 12-11-2007, 09:01 PM
davemackey's Avatar
Pligg Donor
Pligg Version: 9.9.
Pligg Template: siChunkBlue
 
Join Date: Aug 2007
Location: Langhorne, PA
Posts: 286
Thanks: 33
Thanked 18 Times in 14 Posts
edpudol is absolutely correct. It would appear they are using PyCurl or some other method to entirely bypass CAPTCHA.
Reply With Quote
  #52 (permalink)  
Old 12-11-2007, 09:07 PM
New Pligger
 
Join Date: May 2007
Posts: 21
Thanks: 0
Thanked 1 Time in 1 Post
If they are using legitimate bot and behave like robot then we can stop them by disallowing them from robots.txt
Reply With Quote
The Following User Says Thank You to edpudol For This Useful Post:
  #53 (permalink)  
Old 12-11-2007, 09:12 PM
davemackey's Avatar
Pligg Donor
Pligg Version: 9.9.
Pligg Template: siChunkBlue
 
Join Date: Aug 2007
Location: Langhorne, PA
Posts: 286
Thanks: 33
Thanked 18 Times in 14 Posts
Correct, unfortunately, it is unlikely that a spammer will act like a legitimate robot. Additionally, while it may quash this particular spammer there is the larger issue of the ability of a spammer/hacker to insert unwanted data into our db through the user.php page. I am sure the Pligg developers will be able to quickly implement a method that disallows outside sources to simply add materials.
David.
Reply With Quote
  #54 (permalink)  
Old 12-11-2007, 09:16 PM
not2serious's Avatar
Pligg Donor
Pligg Version: v0.96 w/modifications
Pligg Template: Yget w/modifications
 
Join Date: Apr 2007
Location: East Coast, USA
Posts: 226
Thanks: 16
Thanked 16 Times in 15 Posts
It appears to have only hit the top 40 posts on the published page and 10 posts on the upcoming page. I have the gravity mod installed, so each change on a post put the story back on the top. It used several different of the several hundred accounts that the spammer created.
__________________
My Pligg Site: Critique My Art
My Arts Directory: Links 2 Arts

Last edited by not2serious; 12-12-2007 at 09:29 AM..
Reply With Quote
  #55 (permalink)  
Old 12-11-2007, 10:31 PM
New Pligger
 
Join Date: Sep 2007
Posts: 28
Thanks: 0
Thanked 7 Times in 4 Posts
That little math quiz I added seems to have worked. No new spammer registrations since the change. If they get they can't solve 8 + 1, they're not registering on luxa.org. Deleting the spammers was a breeze in phpmyadmin. I may change up the quiz once in a while, along with the form field name. On a side note, I don't use CAPTCHA, and my registration process is only one step.

Hit 300 legitimate members today. :)
Reply With Quote
The Following 2 Users Say Thank You to katlis For This Useful Post:
  #56 (permalink)  
Old 12-12-2007, 01:13 AM
skarld's Avatar
New Pligger
Pligg Version: 9.8.2
Pligg Template: GarrX
 
Join Date: Jul 2007
Location: Las Vegas
Posts: 25
Thanks: 11
Thanked 1 Time in 1 Post
I got whacked today while I was at work. I was able to delete the comments but not the users from the admin panel. I am using katlis' math hack right now until a better fix gets posted. I have saved all the deleted data if anyone is interested in comparing.
Reply With Quote
  #57 (permalink)  
Old 12-12-2007, 01:53 AM
New Pligger
 
Join Date: Sep 2007
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Had the same problem yesterday. I deployed the setup email registration confirmation, which has been recommended by others.

http://forums.pligg.com/pligg-mods/4...il-v0-1-a.html

Funny thing now that I think about it though, the moment I deployed this, the new accounts and spams stopped completely, which was great. It makes sense to me that this stopped the problem. But shouldn't this only prevent the spambot from using the accounts it created, shouldn't the accounts the bot is trying to create still appear in the user management area of admin? Maybe I am having a "duh" moment and overlooking something obvious. I tried creating a new account though and not confirming it, and it does appear there.

I don't know, but I do know the bot is still hitting the site repeatedly, I am logging tons of unique hits due to this even though the spam problem has stopped. I guess we have to all try and work on how to stop this bot, because it is going to throw everyone's traffic and bandwidth records way off. It won't be as simple as an IP block though since this bot uses a different IP with each hit it appears...
Reply With Quote
  #58 (permalink)  
Old 12-12-2007, 06:11 AM
New Pligger
 
Join Date: Aug 2007
Posts: 13
Thanks: 1
Thanked 3 Times in 3 Posts
It seems - although I wasn't paying a great deal of attention - as if each account only posted 1-2 comments and then got discarded... presumably in case there is some kind of flood protection... so, once you change your register page - problem solved.

It IS disconcerting though and I certainly hope that anti-spam, verification becomes part of core Pligg functionality because it seems to be in the firing line now... which isn't to say that the mods aren't appreciated and useful, it simply seems Pligg is of the age when these type of precautions aren't optional anymore.

Again thanks to people for the advice - I just finished clearing out the 300+ spammers from the database... I'm really glad that I was around when this happened or there'd likely have been thousands of them. Definitely good to see people banding together against adversity. I just hope that Pligg doesn't becoming a punching bag for the Eastern Bloc hacking community.
Reply With Quote
  #59 (permalink)  
Old 12-12-2007, 09:13 AM
TobiParrot's Avatar
Casual Pligger
Pligg Version: Pligg beta 9.8.2
Pligg Template: Default
 
Join Date: Dec 2007
Location: UK
Posts: 45
Thanks: 5
Thanked 8 Times in 6 Posts
The new captcha options module is a good idea, but as davemackey says, assuming the article about pyCurl is correct, none of the captchas will prevent pyCurl being used to hack user.php directly. Wiil there be a security patch released for user.php?
Reply With Quote
  #60 (permalink)  
Old 12-12-2007, 05:48 PM
Banned
Pligg Version: 9.9.5
 
Join Date: Oct 2007
Location: Canada
Posts: 914
Thanks: 169
Thanked 17 Times in 17 Posts
ok this is crazy. The bot has managed to disable my option to delete the comments.

both albumotes.com and flickvotes.com do not have the check box to delete the comment. I have tried with all three themes including yget

Ash, Chuck is this possible because the admin options are simply gone blogengage.com was safe because I edited and added the mods you suggested immediately.

Last edited by bbrian017; 12-12-2007 at 06:08 PM..
Reply With Quote
Reply

Thread Tools
Display Modes
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Similar Threads
Thread Thread Starter Forum Replies Last Post
Looks like our Curl User is back REF Help I am being Spammed rmorrill General Help 1 01-09-2008 11:00 PM
Wiki has been spammed... jrothra Suggestions 5 07-14-2007 04:20 PM


Search Engine Friendly URLs by vBSEO 3.2.0