Part of the EllisLab Network
pMachine Pro has been replaced by ExpressionEngine, our full featured web publishing solution. Please consider upgrading.
You can download pMachine Pro here: Download pMachine Pro  |  Download Language Packs
   
2 of 5
2
Spam Registrations
Posted: 31 October 2004 12:53 AM   [ Ignore ]   [ # 19 ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  302
Joined  2003-10-01

Yes, it’s always the same person… their email addres ends in .ru
and their username is a random name.

Profile
 
 
Posted: 31 October 2004 09:36 AM   [ Ignore ]   [ # 20 ]  
Grad Student
Avatar
Rank
Total Posts:  94
Joined  2003-09-24

The email address is randomstuff@mail.ru

Profile
 
 
Posted: 31 October 2004 02:40 PM   [ Ignore ]   [ # 21 ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  302
Joined  2003-10-01

hmmm… i thought there was a way to NOT allow anyone to register unless the adminstrator gives permission. is there such an option?

Profile
 
 
Posted: 31 October 2004 03:47 PM   [ Ignore ]   [ # 22 ]  
Research Scientist
Avatar
RankRankRankRankRankRank
Total Posts:  9868
Joined  2002-06-19

There is a membership approval hack.

 Signature 

Chris Curtis
chriscurtis.org

Profile
 
 
Posted: 01 November 2004 12:28 AM   [ Ignore ]   [ # 23 ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  302
Joined  2003-10-01

re comment spammer:
can this solution be adapted for pMachine?
http://www.7nights.com/asterisk/archive/2004/10/easy-comment-spam-fix

Profile
 
 
Posted: 01 November 2004 07:56 AM   [ Ignore ]   [ # 24 ]  
Lab Technician
Avatar
RankRankRankRank
Total Posts:  2360
Joined  2002-12-06

re:comment spammers…I’d be happy to just disallow any comments with HTML in them.  Or maybe route the ones that do through an approval process. 

 Signature 

Sign up for Southern Fried ExpressionEngine - a 4-day EE class in San Antonio, TX starting on January 20th.

Profile
 
 
Posted: 01 November 2004 12:31 PM   [ Ignore ]   [ # 25 ]  
Research Scientist
Avatar
RankRankRankRankRankRank
Total Posts:  7534
Joined  2002-08-05

That solution is easily circumvented.  A more robust solution is something similar to what we did with ExpressionEngine which creates a unique id for each form that has to be present when the form is submitted.  This allows us to force a page load and that certain information be present like IP and UserAgent. 

I’d just be happy with finding out how they are submitting an apparently blank signature.  That and tracking them down and putting them out of our misery.

 Signature 
Profile
 
 
Posted: 02 November 2004 06:41 AM   [ Ignore ]   [ # 26 ]  
Summer Student
Total Posts:  16
Joined  2003-12-22

Hi,
I think I have the same spammer in my blog.

IP:64.237.57.150

The following person has just registered at: Le Cyber Cactus.com


Name: lptker
Username: jwjyjz
Email: ovvwasd@mail.ru

This account is inactive.
When I’ll have time, I’ll modify the membership file with the membership approval hack.
Thanks Chris . wink

Profile
 
 
Posted: 02 November 2004 07:33 AM   [ Ignore ]   [ # 27 ]  
Grad Student
Rank
Total Posts:  31
Joined  2003-03-04

I have the same registration on mine (ovvwasd@mail.ru) still pending.

I also have pending -
Name: hepcdk
Username: slrdvt
Email: qwe1234qwe1@mail.ru

And this one was activated -
Name: jatnnv
Username: derjek
Email: ueukm06@mail.ru

What is the point? Comments are not a feature of my site and they don’t seem to want to post in the forum. The worst case was the 41 registrations with the dodgy URLs.

Have they perhaps found a way to send out spam that requires a registration? I don’t see anything untoward in my server logs. Just a thought.

Profile
 
 
Posted: 02 November 2004 09:21 AM   [ Ignore ]   [ # 28 ]  
Research Scientist
Avatar
RankRankRankRankRankRank
Total Posts:  7534
Joined  2002-08-05

Hm, I just got a registration from this fellow on my old pMachine Pro based site as well.  However, s/he put in a signature each time, so I wonder if there is something particular about giovanni’s set up that is allowing the spammer to put in nothing.

As for why this spammer is doing this, it just might be a way to get their name out there and to put URLs in member lists.  I think what I can do is actually just block any email addresses with that domain name. 

 Signature 
Profile
 
 
Posted: 02 November 2004 09:52 AM   [ Ignore ]   [ # 29 ]  
Grad Student
Rank
Total Posts:  31
Joined  2003-03-04

Paul,

If and when you do bock email addresses from that domain could you explain how.

Thanks

Profile
 
 
Posted: 02 November 2004 10:15 AM   [ Ignore ]   [ # 30 ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  302
Joined  2003-10-01

Hi paul… as i recall the spammer seems to be in most cases registering twice. once with a format of:
Name: jatnnvetc
Username: dferwetc
Email: ueukm06@mail.ru
and then again with SIGNATURE blank. next time s/he tries it i will forward the info.
so far today…nada.

Profile
 
 
Posted: 02 November 2004 10:27 AM   [ Ignore ]   [ # 31 ]  
Research Scientist
Avatar
RankRankRankRankRankRank
Total Posts:  7534
Joined  2002-08-05

To block that specific email address, all I did is open up member.fns.php and add a conditional during the data check to see if ‘mail.ru’ was part of the email address.  Who wants to test?

 Signature 
Profile
 
 
Posted: 02 November 2004 10:33 AM   [ Ignore ]   [ # 32 ]  
Research Scientist
Avatar
RankRankRankRankRankRank
Total Posts:  9868
Joined  2002-06-19

Just to play devil’s advocate here… there are legitimate people who use that domain, too.  As a good example, the user who created the Russian Language Pack uses that domain.

 Signature 

Chris Curtis
chriscurtis.org

Profile
 
 
Posted: 02 November 2004 10:37 AM   [ Ignore ]   [ # 33 ]  
Research Scientist
Avatar
RankRankRankRankRankRank
Total Posts:  7534
Joined  2002-08-05

He does?  Aw, man…

Using random email address, random IP addresses….I hate spammers.

 Signature 
Profile
 
 
Posted: 02 November 2004 10:38 AM   [ Ignore ]   [ # 34 ]  
Grad Student
Rank
Total Posts:  31
Joined  2003-03-04

Just to play devil’s advocate here… there are legitimate people who use that domain, too. As a good example, the user who created the Russian Language Pack uses that domain.

Bugger. So blocking the domain is out of the question. Better start looking at the membership approval hack then.

Isn’t it time for an update to pM that takes this feature into account?

Profile
 
 
Posted: 03 November 2004 08:56 AM   [ Ignore ]   [ # 35 ]  
Summer Student
Total Posts:  30
Joined  2003-11-07

best way to prevent this kind of thing is to make it harder for spammers by blocking IP addresses

How about this then.  There is already the ability to delete a comment directly from the email that is generated when a new comment is posted.  Is it possible to add another link that reads “Delete comment AND ban IP of user?” which would allow an admin to simply click one link to delete and ban?  As it is, I have to collect all 20 IPs each morning when I ge tup, add them manually to the ban list.  And int he meantime the links remain on my site.

Any thoughts?

Profile
 
 
Posted: 09 November 2004 09:22 AM   [ Ignore ]   [ # 36 ]  
Summer Student
Avatar
Total Posts:  5
Joined  2003-08-18

I just got two “new members” registered in the past two weeks too. Both are from “mail.ru” domains (which are notorious for hackers.. I guess they don’t have very strict rules for what users can do) and both used the same IP addresses listed above in this thread:
- 64.237.57.150
- 66.199.238.21

I’ve blocked both IPs and deleted the users before they were able to do any damage (my settings require new members to be approved). I’d like to block a range of addresses, but it might not really help either.

You can do a WhoIs search on IPs at SamSpade.org but I have no idea what to do with the info from the search. :(  Is it worth reporting them?

Profile
 
 
   
2 of 5
2
 
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 233, on December 18, 2007 12:04 AM
Total Registered Members: 64512 Total Logged-in Users: 0
Total Topics: 81071 Total Anonymous Users: 0
Total Replies: 436301 Total Guests: 21
Total Posts: 517372    
Members ( View Memberlist )
Newest Members:  acidbluejarencyRizqiRustin PharesnaorshushnMasterNielsenTeksxenulirokaKelvin Wong
Active Members: