09-23-2009, 12:32 PM
OK I'm at my wits end with this one spammer issue.
I originally posted in the hacking sticky about this but since yesterday I've got 4 now overnight. I'm averaging 2 spam registrations per night now and I want to stop it right the first time.
I fixed the problem where they were actually posting so I KNOW these are not bots but real people taking time to join and actually come back on the activation email instructions. (again, see the original post link for those details)
http://community.mybboard.net/thread-524...#pid404518 <--- original post
My registration is by email activation.
You MUST post an intro to be able to post to any topic.
Forum is open to read all topics but you cannot post or download until you Intro.
CAPTCHA on registration is enabled.
putting CAPTCHA on every post, topic, reply etc is out of the question. That is a board killer.
I've tracked the degenerate to San Juan, Philippines. Same person, same location.
They use a variety of IP addresses but basically the same one.
120.28.86.96
120.28.82.203
120.28.86.247
120.28.86.247
120.28.83.226
They're using a new Google or Yahoo email address for every name they register with.
Can I ban a range of IP addresses without affecting legitimate members?
HOW can I do that? I don't know how to do this safely.
Here is some more info on this person - just click the link:
http://whatismyipaddress.com/staticpages...up-results
It's the same result for each IP address.
I've had one spammer from the USA but I am not having a problem with that one. It's this one in the Philippines that is a problem.
I got more info from SiteMeter too:
Apparently the common denominator for this is the search because all of them are basically the same with similar search criteria:
"powered by mybb sports"
"powered by mybb nurse"
"powered by mybb home"
"powered by mybb home entertainment"
One has this link as the referring URL:
http://us.mg4.mail.yahoo.com/dc/blank.ht...lang=en-US
You click it and it's a dead page now.
Apparently they're burning bridges behind them and building new ones along the way.
Sometimes they hit all my sites, most of them are on just one.
Someone help me please! I don't want to become a babysitter for my site.
I am running the lateste version of mybb too 1.4.9
I originally posted in the hacking sticky about this but since yesterday I've got 4 now overnight. I'm averaging 2 spam registrations per night now and I want to stop it right the first time.
I fixed the problem where they were actually posting so I KNOW these are not bots but real people taking time to join and actually come back on the activation email instructions. (again, see the original post link for those details)
http://community.mybboard.net/thread-524...#pid404518 <--- original post
My registration is by email activation.
You MUST post an intro to be able to post to any topic.
Forum is open to read all topics but you cannot post or download until you Intro.
CAPTCHA on registration is enabled.
putting CAPTCHA on every post, topic, reply etc is out of the question. That is a board killer.
I've tracked the degenerate to San Juan, Philippines. Same person, same location.
They use a variety of IP addresses but basically the same one.
120.28.86.96
120.28.82.203
120.28.86.247
120.28.86.247
120.28.83.226
They're using a new Google or Yahoo email address for every name they register with.
Can I ban a range of IP addresses without affecting legitimate members?
HOW can I do that? I don't know how to do this safely.
Here is some more info on this person - just click the link:
http://whatismyipaddress.com/staticpages...up-results
It's the same result for each IP address.
I've had one spammer from the USA but I am not having a problem with that one. It's this one in the Philippines that is a problem.
I got more info from SiteMeter too:
Quote:Domain Name (Unknown)
IP Address 120.28.82.# (Unknown Organization)
ISP Unknown ISP
Location Continent : Unknown
Country : Unknown
Lat/Long : unknown
Language English (U.S.)
en-us
Operating System Microsoft WinXP
Browser Firefox
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.13) Gecko/2009073022 YFF3 Firefox/3.0.13
Javascript version 1.5
Monitor Resolution : 1024 x 768
Color Depth : 32 bits
Time of Visit Sep 23 2009 2:27:50 am
Last Page View Sep 23 2009 2:31:41 am
Visit Length 3 minutes 51 seconds
Page Views 4
Referring URL http://www.google.co...Y0s999LlrlHFu-Sv4pnw
Search Engine google.com.ph
Search Words powered by mybb sports
Visit Entry Page http://www.twitchink...umdisplay.php?fid=10
Visit Exit Page http://www.twitchinkitten.com/member.php
Out Click
Time Zone UTC-8:00
Visitor's Time Sep 22 2009 11:27:50 pm
Visit Number 361
Apparently the common denominator for this is the search because all of them are basically the same with similar search criteria:
"powered by mybb sports"
"powered by mybb nurse"
"powered by mybb home"
"powered by mybb home entertainment"
One has this link as the referring URL:
http://us.mg4.mail.yahoo.com/dc/blank.ht...lang=en-US
You click it and it's a dead page now.
Apparently they're burning bridges behind them and building new ones along the way.
Sometimes they hit all my sites, most of them are on just one.
Someone help me please! I don't want to become a babysitter for my site.
I am running the lateste version of mybb too 1.4.9