Foiling Spam Bots - Update
Posted: Tue Sep 26, 2006 4:20 am
Just a quick update on my own experience foiling those frickin' spam bots on the OoH phpBB2 forum:
I've installed a mod I found that removes fields that most spam bots like to have during registration: website, signature, etc. - they register to post their crappy sites in their website and/or signature and then post bogus replies, etc., just to get that website/signature in people's faces. You can adjust this mod to allow people to set these values in their profile after X number of posts, or never. It works great BUT this weekend I had three more spam bots register using only their email addresses - which of course are bogus. Grrrrrrrr...
So I decided to look at the registration process myself and why/how the Captcha code (the visual confirmation stuff) could have been broken (which it has been).
After a couple hours adding my own twist (an hour of which was finding where to tweak the php forums code), I may have a solution to the captcha problem and thus a way to stop the frickin' spam bots registering in the first place.
But I need to let it run for awhile (a week or so) to see if it works. If it does, I'll outline how to create your own using the same method. The nice thing is, even if it's cracked somehow you can always re-tweak it every couple of months.
I've installed a mod I found that removes fields that most spam bots like to have during registration: website, signature, etc. - they register to post their crappy sites in their website and/or signature and then post bogus replies, etc., just to get that website/signature in people's faces. You can adjust this mod to allow people to set these values in their profile after X number of posts, or never. It works great BUT this weekend I had three more spam bots register using only their email addresses - which of course are bogus. Grrrrrrrr...
So I decided to look at the registration process myself and why/how the Captcha code (the visual confirmation stuff) could have been broken (which it has been).
After a couple hours adding my own twist (an hour of which was finding where to tweak the php forums code), I may have a solution to the captcha problem and thus a way to stop the frickin' spam bots registering in the first place.
But I need to let it run for awhile (a week or so) to see if it works. If it does, I'll outline how to create your own using the same method. The nice thing is, even if it's cracked somehow you can always re-tweak it every couple of months.