Page 4 of 7

Posted: Mon Mar 18, 2013 9:48 am
by bb1boy
This is one of the best 'Lude forum's on the net - friendliest, most knowledgeable, helpful bunch of car nuts around - I sincerely hope it doesn't follow the downfall of PUK.

Great job keeping the site tidy, Admin's - muchas gracias! :D

Posted: Mon Mar 18, 2013 9:51 am
by Merlin
Dont worry the mods and admins see this stuff, probably before the majority of memebers do, it gets deleted and measures put in place to try and stop it.

Some clever spam bot is managing to get past the confirmation code needed for the regsistration issues section, that is all. That is where all of the spam post have been, it is not forum wide.

There seems to be a lot of spam attacks going on. A few forums I have been on this weekend have the same.

Posted: Mon Mar 18, 2013 4:18 pm
by Confused
Re-Captcha's are stupidly simple to bypass - the whole point behind the Re-Captcha project is that one word is able to be read by a computer, and the other can't be read by a computer and requires a human to decipher it, so the only check is on the word that is already able to be read by a computer...


The best anti-spam countermeasure I've found for forums is the the Q&A one - you (as the site admin) specify a question, and the allowed answer.

You make this something relevant to the site, or easy for a human to answer, but something that's not easily Googleable.

A great one is something like this:

Please enter the fifth word of this sentence: "The 4th generation Honda Prelude is better than the 5th generation"

An automated spam-bot is usually unable to get round these, but a human easily can.

Add in half a dozen questions, and change them every few months, and I can almost guarantee you'll eliminate successful spam account registrations (negating the need for Admin approval) and still allows the open posting in the Registration Issues forum.

Posted: Mon Mar 18, 2013 4:25 pm
by rob quilter
Confused wrote:Re-Captcha's are stupidly simple to bypass - the whole point behind the Re-Captcha project is that one word is able to be read by a computer, and the other can't be read by a computer and requires a human to decipher it, so the only check is on the word that is already able to be read by a computer...


The best anti-spam countermeasure I've found for forums is the the Q&A one - you (as the site admin) specify a question, and the allowed answer.

You make this something relevant to the site, or easy for a human to answer, but something that's not easily Googleable.

A great one is something like this:

Please enter the fifth word of this sentence: "The 4th generation Honda Prelude is better than the 5th generation"

An automated spam-bot is usually unable to get round these, but a human easily can.

Add in half a dozen questions, and change them every few months, and I can almost guarantee you'll eliminate successful spam account registrations (negating the need for Admin approval) and still allows the open posting in the Registration Issues forum.
This!

Or something like 5+5=?

Posted: Mon Mar 18, 2013 4:46 pm
by indigolemon
Just upped security settings across the board. Logins now checked against blacklists of known spam merchants, and the captcha has been changed to an in house generated one.

We'll see how this goes, @Confused - the Q&A Captcha is available to us. I'll need to think up some decent questions ;-)

Posted: Mon Mar 18, 2013 5:54 pm
by Donald
I don't get it though, the latest one is selling Parkinson's disease treatments? Not even boner pills!

Posted: Mon Mar 18, 2013 5:56 pm
by wurlycorner
The spambot's read some of the posts on here and concluded that can be the only reason for the inanity?!

(EDIT: Or should that be insanity?!)

Posted: Mon Mar 18, 2013 5:59 pm
by Donald
Unless.....

It's picked up that most of us are wankers and could benefit from muscle relaxants?

Posted: Mon Mar 18, 2013 6:13 pm
by indigolemon
Killed it - seriously doubting these are bots given the current captcha settings!

Posted: Mon Mar 18, 2013 6:31 pm
by jjmartin349571
indigolemon wrote:Killed it - seriously doubting these are bots given the current captcha settings!
It's probably SH Driver, pissed off that we banned him :lol: