Skip to:
Content
Pages
Categories
Search
Top
Bottom

Spambot managed to register passed Human Test plugin

  • How is this possible?

    I have had Human Test installed, and managed to keep spambots out.

    The Mass Delete plugin caused trouble to my bbpress, so I deleted that, but still a spambot managed to register. How can I remove him now?

Viewing 9 replies - 1 through 9 (of 9 total)

  • johnhiler
    Member

    @johnhiler

    Spambots are constantly evolving. Do you have the latest version of Human Test plugin installed?


    kevinjohngallagher
    Member

    @kevinjohngallagher

    Its been a while since i used this plugin, but as i recall it asked an X + Y = question (4+4 = 8).

    Seems to me, as more and more people use this sort of protection, that spambots have become quite intelligent about reading the line before the <input> and seeing if it has a + in it. That seems fairly straightforward to do, i’ve done it myself when accessing a remote site using cURL to grab some data.

    Either way, it’s hardly a “plugin fail”, because the plugin does exactly what its set out to do, not to mention, they could just be simply putting the answer “5″ in every unknown field and eventually it would match.

    You ask how is this possible, is it really beyond our imagination that a computer could answer a question about adding one digit to another? The only way to combat spam is to moderate constantly. Akismet, Human Test, Honey Pot and every other tool out there are just tools, they are not solutions. YOU are the solution.


    Gautam
    Member

    @gautam-gupta

    There are many bots like this (made in VB, etc.) which stops when they see a captcha (or math problem or a clickcha), waits for the user to enter/click that and then it does the rest. A more reliable way to be to install Project Honey Pot for bbPress plugin by Ben (though that also blocks the admin sometimes).


    chrishajer
    Participant

    @chrishajer

    Marius- – to remove him, just delete him in the admin.

    Chrishajer, what you mean just delete him in the admin?

    There is no way to delete users in bbpress.

    Not without mass delete plugin, which i had to delete, because it screwed up my forum.


    johnhiler
    Member

    @johnhiler

    You should be able to block the user without any plugins…


    chrishajer
    Participant

    @chrishajer

    Marius- when I am using 1.0.2, and I view the profile of a user when logged in as keymaster, I have a “Delete User” button on the bottom of their profile page. Do you not have that? That’s how I delete a user if I have to (which almost never happens these days.)

    Screenshot: http://twitpic.com/11zdpu/full

    In addition to deleting them, you could just set their status to “inactive” as well, also on their profile page.


    Gautam
    Member

    @gautam-gupta

    Here is a patch posted by me to mass-delete users, you may use it – http://trac.bbpress.org/ticket/1202

    Chrishajer thank you. I somehow managed to completely ignore that button. Dont know why. I have deleted him now.

Viewing 9 replies - 1 through 9 (of 9 total)

You must be logged in to reply to this topic.