Re: topicless posting continues

Dayo Akanji <[email protected]>
Newsgroups gmane.comp.web.gallery.devel
Message-ID <[email protected]>
Impressive and incredible spike as from May this year.

I don't know what the details of the measures in place are but there  
needs to be "defense in depth" so to speak.

While Mollom might be catching a high percentage as shown, the very  
fact that there is such a high number of attempts points to a weakness.

That is, how some so many spammers are able to register in the first  
place?

Are there any measures to filter out automated registrations?

I just took a look at the registration page and it seems to be totally  
open (email validation is not a significant barrier and can easily be  
automated).

One thing I found on a site I run is to create a hidden token on the  
registration form (this can be done with JS) which is then checked  
server side to make sure the user actually used the registration form.

A simple algo can generate unique daily token.

That will not stop humans but using humans for spamming is a lot less  
efficient than scripting.

It may be possible to extend this to the forum posts as well.

I also use a variant of the httpBL http://drupal.org/project/httpBL to  
simply block unwanted visitors.

Basically, the point is that there needs to be a look into  
supplementing Mollom if this is not yet in place.



On Aug 3, 2012, at 7:48 PM, Bharat Mediratta wrote:

>
> PS, here's our Mollom activity graph:
> http://mollom.com/statistics.swf?key=54f4552a707b235473c27af4bc42b6e2
>
>
> On Fri, Aug 3, 2012 at 9:46 AM, Bharat Mediratta  
> <[email protected]> wrote:
>
> I was frustrated with Mollom - until I looked at its stats.  On 8/1  
> we sent 1303 messages to Mollom and it blocked 1272 (97.6%) of  
> them.  So it's definitely doing a good job - just not quite good  
> enough.  I'm guessing that the work you're doing reporting these to  
> Mollom is really helping - thanks a ton, Wayne.
>
> I've been looking through the code to see if it's easy to reject or  
> take appropriate action on these posts, but I'm not enough of a  
> Drupal expert here.  Chad can you help?
>
> It looks like node_form_submit is calling node_submit which is  
> invoking hook_submit which winds up in forum.module's forum_submit.   
> That's not getting the tid on node properly, not sure why - but I  
> think really what we want at that point is to just fail the node  
> insert entirely.  What's the best way to do that?  I an hack it by  
> throwing an exception and catching it in node_form_submit and  
> silently fail, but is there some Drupal way to do it?
>
>
> On Fri, Aug 3, 2012 at 5:11 AM, Wayne Patterson <[email protected] 
> > wrote:
> This guy is apparently posting by skipping the form as the form  
> would force him to choose a topic.
> He is getting 3 or 4 of these through a day.
> examples
> http://gallery.menalto.com/node/107804
> http://gallery.menalto.com/node/107803
> I have reported to molem literally hundreds of louis vuitton posts  
> and yet they still get through - very frustrating.
> And the pure Asian or Cerilic posts
> http://gallery.menalto.com/node/107798
> or just plain garbage
> http://gallery.menalto.com/node/107801
>
> I don't think forcing him into a topic is the answer.
>
> -Wayne
>
>
> On Thu, Aug 2, 2012 at 9:26 PM, Bharat Mediratta  
> <[email protected]> wrote:
>
> I still don't fully understand what's going on here so I don't want  
> to take any strong action.  Ie, I'd hate to find out that there's  
> some bug in the UI which some browser allows these through and we  
> wind up banning a long time user and deleting all their posts :-/
>
> How much of these posts are we getting?
>
>
> On Wed, Aug 1, 2012 at 4:00 AM, Wayne Patterson <[email protected] 
> > wrote:
> On Thu, Jul 26, 2012 at 12:00 PM, Bharat Mediratta  
> <[email protected]> wrote:
>
> Ok - I tried adding in a hack to force those posts into the "General  
> chit-chat" forum.  Let me know if you see any weird side-effects.
>
>  Ok, yes this does force the spammer into the "General chit-chat"  
> forum.
> But that means we still have a hacker posting spam. Can he simply be  
> banned then and there instead?
>
>
>
>
> ------------------------------------------------------------------------------
> Live Security Virtual Conference
> Exclusive live event will cover all the ways today's security and
> threat landscape has changed and how IT managers can respond.  
> Discussions
> will include endpoint security, mobile security and the latest in  
> malware
> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ 
> __[ g a l l e r y - d e v e l ]_________________________
>
> [ list info/archive --> http://gallery.sf.net/lists.php ]
> [ gallery info/FAQ/download --> http://gallery.sf.net ]

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/

__[ g a l l e r y - d e v e l ]_________________________

[ list info/archive --> http://gallery.sf.net/lists.php ]
[ gallery info/FAQ/download --> http://gallery.sf.net ]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.