OT: Website administration question
#1
Original Poster
FlyerTalk Evangelist
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
OT: Website administration question
This is somewhat off-topic with respect to travel, but I'm hoping some experts can tell me exactly what is happening.
I have a small web forum at www.thinclientforum.com. A requirement for posting is registration, but the BBS software that I use, phpBB, doesn't seem to have an email validation system. Usually, I don't have a problem with rogue users, but lately, I've been running into posters who make nonsense posts that have, in tiny fonts, what appear to be links to porn.
Of course, I delete the posts and ban the users and IP addresses.
What, exactly, do they accomplish by doing this, besides annoying the heck out of me?
I have a small web forum at www.thinclientforum.com. A requirement for posting is registration, but the BBS software that I use, phpBB, doesn't seem to have an email validation system. Usually, I don't have a problem with rogue users, but lately, I've been running into posters who make nonsense posts that have, in tiny fonts, what appear to be links to porn.
Of course, I delete the posts and ban the users and IP addresses.
What, exactly, do they accomplish by doing this, besides annoying the heck out of me?
#2


Join Date: Dec 2004
Location: London
Posts: 6,303
The links are an attempt to increase their ranking in Google.
Basically, Google uses (amongst many other things) the interconnectivity of sites in their ranking routine, so they're hoping that your site will help bump them up in google searches.
A recent bit of information regarding this is here:
http://www.avertlabs.com/research/bl...rch-poisoning/
I thought phpBB has introduced various anti-spam features in later editions. Perhaps worth checking out their webpages - eg perhaps http://www.phpbb.com/community/viewt...f=46&t=1437125
Otherwise there are other forum softwares which often update their forum software to enable better control over rogue posters.
Basically, Google uses (amongst many other things) the interconnectivity of sites in their ranking routine, so they're hoping that your site will help bump them up in google searches.
A recent bit of information regarding this is here:
http://www.avertlabs.com/research/bl...rch-poisoning/
I thought phpBB has introduced various anti-spam features in later editions. Perhaps worth checking out their webpages - eg perhaps http://www.phpbb.com/community/viewt...f=46&t=1437125
Otherwise there are other forum softwares which often update their forum software to enable better control over rogue posters.
#3
Original Poster
FlyerTalk Evangelist
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
The links are an attempt to increase their ranking in Google.
Basically, Google uses (amongst many other things) the interconnectivity of sites in their ranking routine, so they're hoping that your site will help bump them up in google searches.
A recent bit of information regarding this is here:
http://www.avertlabs.com/research/bl...rch-poisoning/
I thought phpBB has introduced various anti-spam features in later editions. Perhaps worth checking out their webpages - eg perhaps http://www.phpbb.com/community/viewt...f=46&t=1437125
Otherwise there are other forum softwares which often update their forum software to enable better control over rogue posters.
Basically, Google uses (amongst many other things) the interconnectivity of sites in their ranking routine, so they're hoping that your site will help bump them up in google searches.
A recent bit of information regarding this is here:
http://www.avertlabs.com/research/bl...rch-poisoning/
I thought phpBB has introduced various anti-spam features in later editions. Perhaps worth checking out their webpages - eg perhaps http://www.phpbb.com/community/viewt...f=46&t=1437125
Otherwise there are other forum softwares which often update their forum software to enable better control over rogue posters.
#4
Join Date: Sep 2007
Location: Purgatory
Programs: Too many to list. Status is a half dozen.
Posts: 9,236
phpBB is modular like most forums, isn't it? Meaning there are add-on options out there - things like spam catchers, or captcha requirements, and perhaps what you want - email / registration validation. Just did a google search and found phbbhacks.com, and the "MODs" forum on the phpBB website at phpbb.com/mods. Check those out if you haven't.
#5
Original Poster
FlyerTalk Evangelist
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
phpBB is modular like most forums, isn't it? Meaning there are add-on options out there - things like spam catchers, or captcha requirements, and perhaps what you want - email / registration validation. Just did a google search and found phbbhacks.com, and the "MODs" forum on the phpBB website at phpbb.com/mods. Check those out if you haven't.
#6
Join Date: Jul 2005
Location: MSP
Programs: SPG Gold;NWA gold;Hyatt Plat
Posts: 1,458
There's something called "contextual verification" which is a module for phpbb. I use it and it cuts down the spam. You put in a question for them to answer. If they can't answer, its a bot. do a search for php and spam and you'll find quite afew resources available.
#7
Original Poster
FlyerTalk Evangelist
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
I'm pretty sure this isn't a bot, though I suppose it might be. The moron returned a couple of nights ago with a slightly altered ID but, since I monitor the board fairly closely, I just banned him again and deleted all of his posts (took 10 seconds or so). I'm busy this week, but when I get some time I'll look into the various additional modules available of phpbb.
#8
Join Date: Sep 2007
Location: Purgatory
Programs: Too many to list. Status is a half dozen.
Posts: 9,236
I'm pretty sure this isn't a bot, though I suppose it might be. The moron returned a couple of nights ago with a slightly altered ID but, since I monitor the board fairly closely, I just banned him again and deleted all of his posts (took 10 seconds or so). I'm busy this week, but when I get some time I'll look into the various additional modules available of phpbb.
Just ask some of the mods how much spam gets through and how much gets caught here on FT. There's plenty, I've happened upon some spam posts before they were dumped here.
#9
Original Poster
FlyerTalk Evangelist
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
Still sounds like a bot. Once a bot finds positive hit, it will keep trying over and over. Usually coming from a range of IP's. Bot programmers have gotten fairly sophisticated and with widely used bulletin board software packages like phpBB, vBulletin and others, bots just crawl the web looking for installed copies. It's always a race between bots and site admins.
Just ask some of the mods how much spam gets through and how much gets caught here on FT. There's plenty, I've happened upon some spam posts before they were dumped here.
Just ask some of the mods how much spam gets through and how much gets caught here on FT. There's plenty, I've happened upon some spam posts before they were dumped here.
#10

Join Date: Aug 2007
Location: SAT
Programs: WN RR
Posts: 171
The other issue with phpBB is its susceptibility to hacking. It's long been one of the most vulnerable scripts out there and the hackers can use its vulnerability to get root access on your server! Supposedly it has gotten better, but I've seen hackers get root through phpBB at two former employers, and it isn't pretty.
If you're serious about running a message board, spring for serious message board software, like vBulletin or Invision Power Board. You'll get much better tools to deal with the spam.
#11

Join Date: Jun 2004
Location: The People's Republik of MSN
Programs: Hilton Diamond. Anti-Apostheid Platinum, PWP CentCom
Posts: 4,768
You just need to find the right tools and let them do their job, just like e-mail filtering, only more so.
#12
Original Poster
FlyerTalk Evangelist
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
I used to administer a couple of phpBB forums for my employer. One of them drew 40-50 spam messages a day, about 10x as many spam messages as customer messages! Eventually the company shut the spammy board down, because the spam was relentless.
The other issue with phpBB is its susceptibility to hacking. It's long been one of the most vulnerable scripts out there and the hackers can use its vulnerability to get root access on your server! Supposedly it has gotten better, but I've seen hackers get root through phpBB at two former employers, and it isn't pretty.
If you're serious about running a message board, spring for serious message board software, like vBulletin or Invision Power Board. You'll get much better tools to deal with the spam.
The other issue with phpBB is its susceptibility to hacking. It's long been one of the most vulnerable scripts out there and the hackers can use its vulnerability to get root access on your server! Supposedly it has gotten better, but I've seen hackers get root through phpBB at two former employers, and it isn't pretty.
If you're serious about running a message board, spring for serious message board software, like vBulletin or Invision Power Board. You'll get much better tools to deal with the spam.

