MyBB Community Forums

Full Version: [TIP] Security Questions
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
I've had a long trip of converting my PHP-Fusion 7 forum over to MyBB 1.6, but that's not the idea of this topic.

However, once I did convert back to MyBB, I was receiving COUNTLESS amounts of bot registrations and spam. I didn't understand. Turned on e-mail verification, switched to recaptcha, had the security questions on, nothing worked.

But then it hit me.. why not make it possible, yet nearly IMPOSSIBLE to solve these questions?

So, I whipped these up in the list. I have not had a single, not ONE, bot register on my forums since these changes.

Now, a couple of these are completely relevant to my forum, which I'm not going to advertise here, but you can click the banner in my sig and it will take you to my site (we're renovating, sorry). Our name plays a part in 1 or 2 questions.
  • If something isn't negative, it's.. pos_t_ve? This should be obvious.
  • What fruit is also the name of a company/computer? And no, Windows are not fruits.
  • Type the world "e.v.o.l.u.t.i.o.n" in the box without the dots. This may be the easiest one here.
  • What is the opposite of left? Well, unless you're crosseyed..
  • Type a number from 300-310. The answer for this has all the possible numbers in this range.

I haven't seen any bots at all register with these security questions in place. I don't have any "regular" users registering right now because we're still renovating our website and servers, so promotion is a bit tedious.

Originally, I was looking at this many within only 2 days of converting back. I know it's going to happen no matter what, that's a given. But when it comes down to that, it's just insane.

Quote:Whitey 18th Jan 2013, 21:15 Deleted 3 user(s)
Whitey 18th Jan 2013, 21:13 Deleted 5 user(s)
Whitey 18th Jan 2013, 13:47 Deleted 21 user(s)
Whitey 18th Jan 2013, 4:18 Deleted 14 user(s)
Whitey 18th Jan 2013, 4:14 Deleted 13 user(s)
Whitey 18th Jan 2013, 4:13 Deleted 13 user(s)
Whitey 17th Jan 2013, 8:22 Deleted 6 user(s)

Do you have similar questions as well? Even something that may make sense, unlike my "Fruit" one.

Share! Smile
I've done something similar with the questions, I also think this helps:
http://mods.mybb.com/view/limiturlposting

I take this as an extra precaution, even though a spambot getting through is like once in a blue moon for me. Because the spammers spam links, and if they're not able to post links, that's another road bump for them. Unless of course, they're an actual person, but even then the links aren't clickable (that's the only way they'll be able to post them), and I believe it helps prevent users from accidentally clicking.

I of course use the stopforumspam plugin.

And I always check the IP address that the spambot is coming from. If it's an obvious data center address, I try to source out all the IP ranges belonging to those data centers, and I put them in my .htaccess block list.
(2013-01-22, 07:19 PM)weBex Wrote: [ -> ]and I put them in my .htaccess block list.

how would i do this?
Edit .htaccess, add:

Order deny,allow
deny from [IP]
allow from all