Problems with SPAM? Read this!

Dr. GBooky is here to help you with your guestbook problems ...
ravetildon1
Posts: 28
Joined: Tue Mar 07, 2006 5:56 am

entries

Post by ravetildon1 »

here's mine if ya want it?

Hey I just noticed that if I pull up this:

[PART REMOVED BY KLEMEN]
ravetildon1
Posts: 28
Joined: Tue Mar 07, 2006 5:56 am

info

Post by ravetildon1 »

It looks as though the same peopel are doing postings but with differnt ip's?
Klemen
Site Admin
Posts: 10116
Joined: Fri Feb 11, 2005 4:04 pm

Post by Klemen »

Hmm, I don't like this. I will do some testing and tracking myself and hopefully can come up with a solution quick.
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
ravetildon1
Posts: 28
Joined: Tue Mar 07, 2006 5:56 am

cool

Post by ravetildon1 »

cool, do you think my permissions are wrong? should peopel be able to view entries file?
Klemen
Site Admin
Posts: 10116
Joined: Fri Feb 11, 2005 4:04 pm

Post by Klemen »

Well since it's a plain text file it can be viewed. You can rename the file to something "asdvfzieafhkj.txt" and set the new name for the file in settings.php under $settings['logfile'] (that's why it's for). But yes, I see the issue and will see if that can be renamed to a PHP file by default in next version (a PHP one couldn't be viewed).
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
Ninja1
Posts: 4
Joined: Sat Jun 17, 2006 10:13 am

Post by Ninja1 »

Couple of familiar names and URLs up there... Nik, Tomas and the Krasaoh link.
Different ip's though.

Few more:
[PART REMOVED BY KLEMEN]

Wasn't aware of the ability to view the entries.txt, have to change that later today :)
Klemen
Site Admin
Posts: 10116
Joined: Fri Feb 11, 2005 4:04 pm

Post by Klemen »

Hi,

I removed the SPAM info from the two posts as I don't want to advertise SPAMvertised websites here :wink: I am now tracking posts at some test GBook I have installed on a website. It was version 1.35 and started getting some SPAM last few days. I updated it to 1.42 with some added tracking info but so far no spam... I have yet to get some of this new spam in the demo GBook as well.

I noticed IPs are from various countries (Japan, Russia, North Korea, Jemen, ...) and with so different IP numbers (and C classes) blocking them isn't a solution. Like said, will see what I can find out and post it here.

As for entries.txt I will have them renamed to entries.txt for next releases.

Regards,
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
ravetildon1
Posts: 28
Joined: Tue Mar 07, 2006 5:56 am

info

Post by ravetildon1 »

You mean entries.php :)

Maybe they are using a rotating proxy application to submit the links, thats why they are differnt each time.
Klemen
Site Admin
Posts: 10116
Joined: Fri Feb 11, 2005 4:04 pm

Post by Klemen »

Yes, I meant entries.php :)

As for the SPAM problem my logs show these new spam posts really do come from anonymous proxies and are actually being sent out by someone located in Russia...

Give this file a try:
Download GBook 1.42 rev2
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
Cheepnis
Posts: 5
Joined: Tue Jul 25, 2006 2:21 pm

Post by Cheepnis »

I don't mean to sound rude, but why re-invent the wheel? Why not use GD-based verification codes like everthing else does (including this forum software)? I have had no spam on either my phpBB or my OSCommerce sites that use GD verification. Are you attempting to use methods that are better (since nothing is perfect, of course)? Just curious...

Cheepnis
Visit www.MST3K.org for the BEST cheesy movies on this planet!
Klemen
Site Admin
Posts: 10116
Joined: Fri Feb 11, 2005 4:04 pm

Post by Klemen »

Hi,

GBook was meant to provide good anti-spam protection to people all over the web and on various (even free) hosts, that's why I didn't use GD (a lot of host don't support it, especially the free ones) and it worked well - until now (although I'm not yet 100% sure it is the number they are reading).

The file in my previous post should fix the latest spamming technique, but yes, a GD version of the security image will be added (soon), probably with the ASCII version being an option for those on hosts that don't support GD.

Note that GBook goes beyond that, it filters out even posts that actually come through the number check, but it can't really tell the difference between a valid post and these casual posts like "Nice website".
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
Cheepnis
Posts: 5
Joined: Tue Jul 25, 2006 2:21 pm

Post by Cheepnis »

Thanks, Klemen. The option for either method is a perfect solution. I really like this script (clean, simple, and easy to maintain/customize). Thanks for your prompt attention to the issue and the continued support for a free product! Do you accept Paypal at the email in your readme file? I'd like to put my wallet where my mouth is :wink:
Visit www.MST3K.org for the BEST cheesy movies on this planet!
Klemen
Site Admin
Posts: 10116
Joined: Fri Feb 11, 2005 4:04 pm

Post by Klemen »

Hi,

The new version with image security number is out, see viewtopic.php?t=959

As for PayPal no I don't accept it at that e-mail. I personally am not able to receive any funds in my PayPal account, but I can accept donations to a friend's account at donations AT phpjunkyard DOT com. But instead of receiving donations I usually prefer to give something in exchange, see
http://www.phpjunkyard.com/help-phpjunkyard.php
:wink:

Regards,
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
ravetildon1
Posts: 28
Joined: Tue Mar 07, 2006 5:56 am

info

Post by ravetildon1 »

Just upgraded to 1.43 from 1.41. So I am anxious to see how my site does. Currently have 14 pages of spam and 139 entries. I am goign to delete them all and see how it goes..

update aug 26, 2006 - So far so good. Only one in a couple weeks. Hope it continues!
suehutton
Posts: 2
Joined: Mon Aug 28, 2006 11:19 am

Post by suehutton »

I think this guestbook script is excellent particularly that it is so well documented and supported in the forum.

I upgraded from 1.41 to 1.43 today, and am pleased that the image captcha component is working.

The guestbook under 1.41 had started to receive spam, apparently from these IP addresses:

210.233.102.66 Tokyo, Japan
125.245.166.2 Seoul, South Korea
61.155.22.117 China
203.149.62.66 Bangkok, Thailand
82.160.156.27 Olawa, Poland
217.65.158.120 Keele, UK, (I shall telephone the Innovation Centre at Keele tomorrow, to tell them that one of their computers may be being used as a spam proxy)
213.35.219.69 Talinn, Estonia

Comments were variously: Hello! or Cool site webmaster.

Maybe this information could be useful in tracing a spam network.

Many thanks for all your hard work.
http://www.suehutton.co.uk
Post Reply