This spam bot is out of hand....can't we do a screening of some sort......
Announcement
Collapse
No announcement yet.
We need to let admins and mods screen new members
Collapse
X
-
heres the problem with screening....
the admin doesnt know if its a fake or not.
he just sees a user, with no location, or anything.. so he only has a name to go by.
tjstoner -- could be a bot. could be a pothead... could just be the guys initals and name. who knows?!
Kilter-- sounds like it could be a bot name to me.
Doc -- yea, ive had a bot called this try to register before....
so... as we can see, the admin would not want to lock people out.. so he oks the person.
nothign happens.
the a couple hours later..... the bot spams the whole board. (or the person posts)
heres a better idea.
dont let bots register.
the concept is rather simple.
a computer program, a dumb computer program... can only figure out so much.
its not filling in the fields of the page and clicking buttons... no, its actually just posting the data directly to the webserver...
normally when you fill out a form online and hit the submit button, the browser takes all that form data and sends it to the server.
this data is formatted something like this:
[ Field Name | Data ]
ok, so lets think about this.
the BOT never looks at the page.. he just submits the data directly to the server.
1 method:
so if we CHANGED the field name in the program and on the page... the user would never see the diff.. but when the bot submitted the info... it wouldnt work.
another method:
if we changed the URL... the location the data is sent to.... the user would never see the diff... but the bot wouldnt even know where to send it to.. it wouldnt work for them.
yet another method:
if we add a field thats required... say, the make/model of your bike...
some bots would be blocked. some bot would figure out this field is required, but they wouldnt know to put in "Honda Hawk" or whatever..
the admin could then see that someone put in "Fishing" or somethign else stupid there, and not allow them.
once more, another method:
this one is called instaban.
some bots are smart enough to figure out these hacks after trying them once.
instaban instantly bans that IP the first time they try it... so that they dont get that second chance.
for example, if we changed the register tag from "agreed = true" to "IamInAgreEmeNt = true"..... then we can instaban anyone who trys "agreed = true".... a person using a browser is never going to do that because they're clicking the "IamInAgreEmeNt" link.... but the bot never uses the links.
see, theres TONS of things you can do.
Comment
-
Originally Posted by tjstonerhow bout those things where they have a .jpeg with some letter number combos and you have to enter them to get through...?
the people that run these have only one goal.. money (or malicious intent).
just getting you suckered onto the site is only half of it.. the other half is installing (without your knowledge) adware... or spyware for your info.. or sometimes just to screw with your computer, but thats a small percentage.
just clicking it once, supports the bastards... nevermind the computer problems you'll get.
Comment
-
Originally Posted by kiwiuntil you get this bot how about enabling "report post function" so that the mods dont have search out the spam threads users can use the report post to help you guys
Comment
Comment