Part of the EllisLab Network
pMachine Pro has been replaced by ExpressionEngine, our full featured web publishing solution. Please consider upgrading.
You can download pMachine Pro here: Download pMachine Pro  |  Download Language Packs
   
 
Comment Spam With Captcha Working
Posted: 18 August 2006 10:50 AM   [ Ignore ]  
Grad Student
Rank
Total Posts:  32
Joined  2004-11-23

Hello.

Last night my site http://www.conservative-truths.com/ was hit with comment spam.  The weird thing is that the captcha process appears to be working correctly, but this was definitely an automated attack.  A different porn-site comment was posted to each of the 80+ entries within the span of one hour (2AM to 3AM) and I just cannot see someone entering a different comment to each posting in that amount of time using the captcha process.

My site is hosted on PowWeb and the server changed on Wednesday.  Is there any way that the server change could have allowed this?

I have deleted all of the spam comments from all of the entries except this one:  http://www.conservative-truths.com/comments.php?id=97_0_1_0_C This is the posting about the server change so I have decided to keep the spam comment on this entry while I look into how this could have happened.

Has this ever happened to anyone else?  Is there any way to make sure that this doesn’t happen again?

Thanks.

-Derek

Profile
 
 
Posted: 24 August 2006 09:59 AM   [ Ignore ]   [ # 1 ]  
Grad Student
Rank
Total Posts:  32
Joined  2004-11-23

This just happened last night on my other pMachine Pro blog.  The entry can be found here: http://www.liberal-truths.com/comments.php?id=92_0_1_2_C

As with the other site, the captcha process is working.  This site’s server change happened on August 10, 2006 so I don’t believe the server change could have allowed this to happen since it happened a few weeks ago, whereas the other site had changed servers within a couple of days of the attack.

Last night’s attack came from the same IP address as the previous attack and that IP address has been banned on both sites, but I would still like to know how this could have even happened in the first place since the captcha process is working.

Does anyone have any ideas?

Profile
 
 
Posted: 30 August 2006 07:45 AM   [ Ignore ]   [ # 2 ]  
Summer Student
Avatar
Total Posts:  20
Joined  2004-10-24

Same happened to me today! In one minute I got 8-10 spams into my comments, totally 100 or so, deleted all by hand. Captcha is on and working. .... so it must be an automated attack.

Still I have version EE 1.2.1.

@ derekcbart - was this attack one-time? Or did the spammer come again?

What can we do? Any Idea?

Profile
 
 
Posted: 30 August 2006 08:52 AM   [ Ignore ]   [ # 3 ]  
Lab Technician
Avatar
RankRankRankRank
Total Posts:  2359
Joined  2002-12-06

FWIW - I had ~85 comment spams added the other day (my site is still on pMPro 2.4, and yes with CAPTCHA enabled).  They all appeared to come from the same IP address, blocked it and so far so good. 

I’m planning a move to EE soon, though, so if it continues I’ll just disable comments altogether until after the move.

 Signature 

Sign up for Southern Fried ExpressionEngine - a 4-day EE class in San Antonio, TX starting on January 20th.

Profile
 
 
Posted: 30 August 2006 09:59 AM   [ Ignore ]   [ # 4 ]  
Grad Student
Rank
Total Posts:  32
Joined  2004-11-23

I have two sites running pMPro 2.4.  Each site was attacked once.  The IP address of the attacker is 62.233.222.146.  It was the same address for both attacks.  Is this the same address for your attacks?

Chacharon, if your site is on EE then this type of attack is not limited to a possible flaw in pMPro.  Someone must have come up with a way to defeat captcha itself.

It would really be nice to hear from an engineer and find out what they think about this.

Profile
 
 
Posted: 30 August 2006 11:19 AM   [ Ignore ]   [ # 5 ]  
Summer Student
Avatar
Total Posts:  20
Joined  2004-10-24

@derekcbart - YES! It is the same IP address! And his E-Mail ‘golik22@op.pl’
I’m flabbergasted.

... to defeat captcha ... how is this possible?

For now I blocked this IP. Hope it works.
But I suppose, it’s only a matter of time before someone else is doing such attacks or another IP is in use.
I think the same like you: It would really be nice to hear from an engineer.

Profile
 
 
Posted: 30 August 2006 04:09 PM   [ Ignore ]   [ # 6 ]  
Summer Student
Avatar
Total Posts:  20
Joined  2004-10-24

So - I searched the IP by the RIPE Database - found this:

netname:      Insite-NET
descr:        Connected through Futuro Poland
country:      PL
admin-c:      SL2058-RIPE
tech-c:      MM6454-RIPE
tech-c:      PF722-RIPE
status:      ASSIGNED PA “status:“ definitions
mnt-by:      FUTURO-MNT
mnt-lower:    FUTURO-MNT
mnt-routes:    FUTURO-MNT
source:      RIPE # Filtered

role:        Futuro - Polish Internet Provider
address:      PRO FUTURO S.A.
address:      ul. Nowogrodzka 47a
address:      00-695 Warszawa
address:      POLAND
phone:        +48 22 338 9999
fax-no:      +48 22 338 9900
admin-c:      PK2632-RIPE
tech-c:      PK2632-RIPE
nic-hdl:      PF722-RIPE
remarks:      trouble:    DNS trouble:    dns@pro-futuro.com
remarks:      trouble:    Abuse trouble:  abuse@pro-futuro.com
remarks:      trouble:    Others:      trouble@pro-futuro.com
remarks:      -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
remarks:      In case of abuse (intrusion attempts, hacking,
remarks:      spamming or other unaccepted behavior) from
remarks:      Futuro addresses space, please contact:
remarks:      abuse@pro-futuro.com.
remarks:      Direct contact in case of abuse: +48 81 7187380
remarks:      -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
abuse-mailbox:  abuse@pro-futuro.com
mnt-by:      FUTURO-OBJ-MNT
source:      RIPE # Filtered

person:      Sebastian Lukaszczyk
address:      Insite
address:      ul. 6-go Sierpnia 1/3
address:      90-606 Lodz
address:      Poland
phone:        +48426300201
fax-no:      +48426300201
nic-hdl:      SL2058-RIPE
mnt-by:      FUTURO-OBJ-MNT
source:      RIPE # Filtered

person:      Mateusz Motlawski
address:      Insite
address:      ul. 6-go Sierpnia 1/3
address:      90-606 Lodz
address:      Poland
phone:        +48426300201
fax-no:      +48426300201
nic-hdl:      MM6454-RIPE
mnt-by:      FUTURO-OBJ-MNT
source:      RIPE # Filtered

% Information related to ‘62.233.128.0/17AS15833’

route:        62.233.128.0/17
descr:        Futuro Route
origin:      AS15833
remarks:      removed cross-nfy:  GM2964-RIPE
remarks:      removed cross-mnt:  FUTURO-MNT
mnt-by:      FUTURO-MNT
mnt-lower:    FUTURO-MNT
mnt-routes:    FUTURO-MNT
source:      RIPE # Filtered

Can we do something? I mean something efficient?

Profile
 
 
Posted: 02 December 2006 12:48 PM   [ Ignore ]   [ # 7 ]  
Grad Student
Rank
Total Posts:  70
Joined  2006-11-04

Same thing happened to me. IP 219.238.134.69.

 Signature 

maurymccown.commy photos

Profile
 
 
Posted: 02 December 2006 02:56 PM   [ Ignore ]   [ # 8 ]  
Lab Technician
Avatar
RankRankRankRank
Total Posts:  1399
Joined  2003-08-28

Do you folks user the Throttling Configuration in Preferences? That can be set to slow down the automated entries, and you can set the lockout time, too.

UPDATE: There’s also the Comment Re-Submission Time Interval in Weblog Management. Set that to the number of seconds before the same user can submit another comment.

 Signature 

RonnieMc

Honolulu, HI USA

HomeMac360

Profile
 
 
Posted: 02 December 2006 04:17 PM   [ Ignore ]   [ # 9 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  12231
Joined  2002-04-29

Ronnie and RailHead - this thread is for pMachine PRO 2.4, not EE. smile

 Signature 

Quick Reference - EE Trial Options - EE Wiki - Docs for updating a build

Profile
 
 
Posted: 28 March 2007 02:11 PM   [ Ignore ]   [ # 10 ]  
Grad Student
Rank
Total Posts:  32
Joined  2004-11-23

Hi there.

This just started happening again on my sites.  There is no ability to limit the number of replies to posts in pMachinePro as far as I can tell.  I did limit the number of days that replies can be made to a posting.  It was set to 0 and now it is set to 60.  I only publish once per week, so 60 days would basically be two months which should be enough time for anyone to make a legitimate post.

I still find it disconcerting that the protection that CAPTCHA is supposed to be providing isn’t working.

-Derek

Profile
 
 
Posted: 28 March 2007 03:07 PM   [ Ignore ]   [ # 11 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  12231
Joined  2002-04-29

pMachine PRO is no longer a supported product. It hasn’t been for a few years now. As far as CAPTCHA problems go, I wouldn’t know where to start troubleshooting. Boyink a year or more ago didn’t have an answer either. He’s moved his site over to EE.

There are certainly better options for comments in EE, if at all possible I suggest you upgrade.

 Signature 

Quick Reference - EE Trial Options - EE Wiki - Docs for updating a build

Profile
 
 
Posted: 28 March 2007 05:14 PM   [ Ignore ]   [ # 12 ]  
Grad Student
Rank
Total Posts:  32
Joined  2004-11-23
Sue Crocker - 28 March 2007 03:07 PM

pMachine PRO is no longer a supported product. It hasn’t been for a few years now. As far as CAPTCHA problems go, I wouldn’t know where to start troubleshooting. Boyink a year or more ago didn’t have an answer either. He’s moved his site over to EE.

There are certainly better options for comments in EE, if at all possible I suggest you upgrade.

Hello Sue.

Actually, EE was not a viable choice for my blogs.  I don’t know if it is better now, but other than this occassional comment spam my sites do all that I want them to.  Also, even if I did convert to EE is there any guarantee that CAPTCHA would work there since it isn’t working with pMPro?

Profile
 
 
Posted: 28 March 2007 05:16 PM   [ Ignore ]   [ # 13 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  12231
Joined  2002-04-29

No, there isn’t any guarantee. But you could still download the EECore free version and see how it works for CAPTCHAs. That’s what I suggest trying.

 Signature 

Quick Reference - EE Trial Options - EE Wiki - Docs for updating a build

Profile
 
 
   
 
 
‹‹ PHP 4.4.3      Bookmarklet failing ››
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 233, on December 18, 2007 12:04 AM
Total Registered Members: 64433 Total Logged-in Users: 0
Total Topics: 80878 Total Anonymous Users: 0
Total Replies: 435358 Total Guests: 20
Total Posts: 516236    
Members ( View Memberlist )
Active Members: