Skip to:
Content
Pages
Categories
Search
Top
Bottom

Search Results for 'bots'

Viewing 25 results - 376 through 400 (of 415 total)
  • Author
    Search Results
  • #61876
    guristu
    Participant

    I have adjusted the wp-hashcash plugin to work with buddypress signup. Here is what I did: I got the wp-hashcash plugin and I added the following code to the file:

    Code:
    function wphc_check_signup_for_bp(){

    global $bp;

    // get our options
    $options = wphc_option();
    $spam = false;
    //if( !strpos( $_SERVER[ ‘PHP_SELF’ ], ‘wp-signup.php’ ) )
    //return $result;

    // Check the wphc values against the last five keys
    $spam = !in_array($_POST[“wphc_value”], $options[‘key’]);

    if($spam){
    $options[‘signups-spam’] = ((int) $options[‘signups-spam’]) + 1;
    wphc_option($options);
    $bp->signup->errors[‘spam’] = __(‘You did not pass a spam check. Please enable JavaScript in your browser.’);
    } else {
    $options[‘signups-ham’] = ((int) $options[‘signups-ham’]) + 1;
    wphc_option($options);
    }

    }
    add_action( ‘bp_signup_validate’, ‘wphc_check_signup_for_bp’);

    function wphc_error_hook_register_page(){

    do_action(‘bp_spam_errors’);

    }
    add_action(‘bp_before_register_page’, ‘wphc_error_hook_register_page’);

    Then, under the line (line number about 507)

    Code:
    add_action( ‘signup_hidden_fields’, ‘wphc_add_signupform’ );

    I put this line:

    Code:
    add_action(‘bp_after_registration_submit_buttons’, ‘wphc_add_signupform’);

    Then I activate the plugin. It should keep spam bots from being able to create accounts, but humans spammers can still do it. Anyway, if you can’t get it to work, let me know via PM and I will try to send you the file.

    Later

    #61874
    zageek
    Participant

    I am having major problems with spam as well. Ironically it started as soon as I put my link in the showcase thread on this forum. I think the spam bots are looking there for easy targets as well.

    Why do people make spambots that don’t even advertise stuff and just waste everyone’s time filling sites with meaningless crap. Is it like they are trying to sabotage Buddypress?

    How does one submit domains and sites and IP addresses to spam traps.

    #61850
    danbpfr
    Participant

    http://www.bp-tricks.com/tips_and_tricks/stopping-the-sploggers/

    i guess this is one of the best trick against spam blogs and “wild” registrations.

    Step 1 and 2 are a bit obvious, but 3 and 4 are really efficient.

    Keep in mind that on a wpmu site each blog created by a member has his first post and comment appearing on the default template – the good ol’ kakumei… on which is also written “powered by…” ( Step 2 is only for main blog i think) Spam bots eat this with delectation i suppose. :-)

    Spam programs are written to bypass signup. Well. I presume other narrow words like join, fall in, get together are also activ in such programms. But what do these programms if you choose “groink” or “methabolic” ? So follow the explanation and choose a really original word for your signup redirection. This works well for the moment. And don’t forget to put the functions.php file the in mu-plugins folder (to be theme independant).

    To use in addition with some other solutions (wp-ban, invisible defender, …) of course.

    #60339

    In reply to: Removing Activiation

    Jean-Pierre Michaud
    Participant

    i just installed this system, and yes it send the validation email, so the users may be compromised in error…

    on my side i added a TOS plugin *(my own), so people have to check it and the input name have a name the bots are not recognising so they do not check it before registration…

    #8102
    abossola
    Participant

    I shouldn’t joke about spam as it is quite a problem with buddypress. I’ve tried so many things and I am out of ideas. In this Forum there are lots of suggestions but everyone still seems to be SOL or just hanging on.

    Where I have failed:

    BP Registration Options

    This would be great if it worked. But, it still allows users to register. Worse, is that they show up under Site Wide Activity on the home page for everyone to see that you are getting spam. It would be great if there was a fix for that. For anyone with lots of spam, start here, at least you can have some options: http://webdevstudios.com/support/wordpress-plugins/buddypress-registration-options/

    Not to get sidetracked here but this is a cool plugin I found for the Sitewide Activity Widget:http://buddypress.org/forums/topic/advanced-recent-site-wide-posts-widget

    With BP options I get several errors, which I will share since the Forum by the Plugin’s Author seems to not get much response. http://webdevstudios.com/support/forum/buddypress-registration-options/not-working-and-have-errors/ – Maybe we can work some things out here bc I am not the only one with problems with this plugin.

    SI Captcha

    http://wpmu.org/si-captcha-anti-spam-wpmu-and-buddypress-plugin-contest-entry/

    Well it works, or at least shows on the registration page. BUT, the crafty bots or slave laborists just fill in the codes and it’s a waste as well as an extra step for a user that is worthless.

    ReCaptcha

    Here is another great one.

    http://buddypress.org/forums/topic/buddypress-spam-1

    But it only shows on the comments and NOT on the registration page itself. It’s been “modified” to work with BP, but I can’t get it to work. Again, slave labor can overcome this one quite easily. Think I am kidding about the slave labor: http://ha.ckers.org/blog/20080311/human-captcha-breaking/

    Here is an entire group for spam lovers like myself:

    http://buddypress.org/groups/fighting-spam-splogs

    There are some good tips in that link above here are a few swings I took:

    http://wordpress-plugins.feifei.us/hashcash/

    No dice for me. It seems to work for comments but not the registration page.

    http://www.poradnik-webmastera.com/projekty/invisible_defender/

    Same again… No dice for me. It seems to work for comments but not the registration page.

    http://www.svenkubiak.de/nospamnx-en/

    Giving it a whirl now… I’ll keep you posted.

    http://www.hybrid6.com/webgeek/plugins/wp-spamfree

    Same again… No dice for me. It seems to work for comments but not the registration page.

    Here is my favorite and WAS my most hopeful option:

    http://www.bp-tricks.com/tips_and_tricks/stopping-the-sploggers/

    Guess what, still getting spam. Loads of it too. You would think a little core hacking would throw them off. Tsk tsk…. not these bots/humans. A little tip here for the changing of the slug and the code you add to the config files – Don’t forget to put the define statements BEFORE the STOP EDITING HERE LINE in the config.php. That had me and others scratching our heads for a while.

    How about this one:

    http://premium.wpmudev.org/project/signup-code

    Yeah why don’t we just go ahead and give the user a puzzle via snail mail and they can can send smoke signals once they get it. Or better yet just send them a link to Facebook and save everyone some headache. This MAY work but it is too much to ask of a user.

    Maybe a few checkboxes will throw the bots off:

    http://premium.wpmudev.org/project/terms-of-service

    Guess what? No dice.. still getting spam.

    .htaccess solutions:

    http://wpmututorials.com/how-to/spam-blogs-and-buddypress/

    This one seemed hopeful. But no change, still getting spam.

    # BEGIN ANTISPAMBLOG REGISTRATION

    RewriteCond %{REQUEST_METHOD} POST

    RewriteCond %{REQUEST_URI} .yourbpsignupslug*

    RewriteCond %{HTTP_REFERER} !.*yourhomedomain.* [OR]

    RewriteCond %{HTTP_USER_AGENT} ^$

    RewriteRule (.*) http://die-spammers.com/ [R=301,L]

    # END ANTISPAMBLOG REGISTRATION

    You can try banning IPs but an .htaccess tidbit or by using most of the plugins above. But IPs are a dime a dozen to spammers and thats a total waste of time if you ask me.

    In Summary:

    Short of rewriting the registration page and my own plugin for spam I am at a loss. Any tips would be helpful. Hopefully this post will help some others with the same problem. Sorry for the sarcasm but it’s how I survive the insanity. :)

    Site: http://hoopsjones.com

    BP Version 1.1.3

    WP – 2.8.6

    #8092
    zageek
    Participant

    When I try to reactivate BP after automatically upgrading I get the following error:

    Fatal error: Cannot redeclare bp_activity_install() (previously declared in /home/technope/public_html/arduino.za.net/wp-content/plugins/buddypress/bp-activity.php:19) in /home/technope/public_html/arduino.za.net/wp-content/plugins/buddypress/bp-activity.php on line 52

    I don’t know if my other actions would have resulted in this, but before upgrading BP I update WPMU I did the following.

    I deactivated the BP plugin and all other dependant plugins. But before clicking “upgrade automatically” I went to go and mark sum blogs and users as spam, because I had an attack of the spambots again. Then when clicking automatically upgrade it upgraded without any problems but when it was time to activate the plugin then the above fatal error occured.

    My BP site is running with a modified version of the parent theme which has worked fine since before the previous update.

    I am running WPMU 2.8.6 and upgraded BP from 1.1 to 1.1.3 (I might have missed an upgrade because I haven’t had time to work on the site in the last month or two)

    #58786
    Jeff Sayre
    Participant

    @Harry

    Yes, my Privacy Component works just as I described. It is an advanced beta available for testing. See this thread for more details: https://buddypress.org/forums/topic/buddypress-privacy-component-an-update/page/3#post-30574

    @David

    I wouldn’t give users the option to set it to friends only. Or at least… I would like the site admin to have the ability to disable that option.

    In my Privacy Component, the site admin can choose to disable this feature.

    But, to get back on topic, I agree that the best solution is the one that requires the brunt of the filtering to be accomplished through invisible, behind-the-scenes techniques. Requiring users to prove that they are members and not bots should not be the first line of defense. I think it is okay, even necessary for registration purposes. But that is a one time occurrence. After that, the system should do more of the policing.

    Concerning your second link above, perhaps we could create a new CAPTCHA that could harness the collective intelligence of site members to solve the Unified Field theory.

    #58742
    Arx Poetica
    Participant

    Word. Patch it!

    I’ve been having sign up spams (arguably a different issue) on my BP install, and just shut all signups down until I could figure out what to do about it.

    Scouring the WordPress MU forums has made me realize three things:

    1. Spamming is a huge problem for WordPress MU users

    2. I’m betting that BuddyPress will/might have even larger problems due to the very nature of the beast (it’s all about users, right? Which is where the bots/spammers gravitate)

    3. There are no sure-fire methods for preventing spammers

    …well, there’s a fourth, too…

    4. Many of the old hats on the WordPress MU forums are getting tired of explaining how to defend against so-called “splog” signup bots and spammers.

    Just some observations, as BP just received its first official spammer. (Yes, I got the email too, and saw the small twitter firestorm this morning over it.)

    podictionary
    Participant

    I’m running BP 1.1.3 on WPMU 2.8.6 and have two additional domain extension blogs.

    The site-wide activity widget causes Google index problems. Google search results often point to pages where the site-wide activity listing has previously had links to content, but which have since disappeared off the bottom of the list.

    To solve this I added Googleoff and Googleon tags around the site-wide activity listing in the widget. Now Google indexes only the full entries in the extension blogs (and forums) and search results hop the correct pages.

    Has anyone else had this issue? How did they handle it?

    Would it be wise to offer Googleoff/on tags by tickbox in the site-wide activity widget?

    (Googleoff/on tags essentially tell Google not to read this part of the page – <div class=”robots-nocontent”> does it for Yahoo).

    Here’s the code I used in the bp_activity-widgets file:

    Look for

    <ul id="site-wide-stream" class="activity-list">
    <li>

    ….bunch more code in here

    </li>
    </ul>

    And change it to

    <!--googleoff: all--><div class="robots-nocontent">
    <ul id="site-wide-stream" class="activity-list">
    <li>

    ….bunch more code in here

    </li>
    </ul>
    </div><!--googleon: all-->

    #58655
    Mark
    Participant

    I posted this elsewhere but it now belongs as part of this discussion: When using Buddypress, should /wp-signup.php result in an blank page or the registration form (or redirect to /register)? If the issue described here exists, how do you get the proper default buddypress behavior?

    see: http://ttacconnect.org/wp-signup.php

    I could delete /wp-signup to remove the errors but I’d like to understand how bp and wpmu is designed to work (are there any consequences for deleting wp-signup.php?).

    I know BuddyPress is using /register.php and not /wp-signup.php. But when /wp-signup.php is hit (typically by spam bots) a PHP Warning is generated. No white space outside of php closing tags in header.php. I’m not too concerned about that as I figure if it’s working as it should (no registration form), then the php warning will take care of itself (and not be generated). So what needs to change to get /wp-signup.php to result in a blank page?

    PHP Warning: Cannot modify header information – headers already sent by (output started at xxxx/bp-sn-parent/header.php:3) in xxxx/wp-includes/pluggable.php on line 865

    See no Warning and no Registration Form (blank page). Is this the proper default buddypress/wpmu behavior?

    http://nourishnetwork.com/wp-signup.php

    Here /wp-signup.php was deleted and results in a page not found:

    http://memomu.com/wp-signup.php

    wpmu 2.8.6 with active plugins on main bp site:

    bp 1.1.3, bp-groupblog, auto group join, Group Forum Subscripton, bad behavior

    #7924
    #58383
    Mark
    Participant

    I’ve determined that the warning is generated when /wp-signup.php is accessed (mostly by spam bots). Can’t find white spaces anywhere. Is /wp-signup.php supposed to redirect to /register or to a blank page?

    My site and the other listed both display the Registration Form and the PHP Warning: Cannot Modify Headers:

    http://ttacconnect.org/wp-signup.php

    http://memomu.com/wp-signup.php

    These sites result in an blank to semi-blank page:

    http://startupweekend.org/wp-signup.php

    http://nourishnetwork.com/wp-signup.php

    http://morgansjourney.org/wp-signup.php

    http://poetrypress.org/wp-signup.php

    Should /wp-signup.php result in an blank page or the registration form? Will resulting blank page eliminate the ‘Cannot Modify Headers’ Warnings in error_log? What is the fix? Thanks!

    #7881
    KevinHeath
    Participant

    I know this is likely to be a WPMU problem, but I would like to know what BP users have done regarding spam bots.

    I keep getting blogs registered with real names but random letters in the other fields. About 20 per day and it’s getting on my nerves.

    I have just upgraded from RC1 to the latest version of BP and have added SI Captcha. The Captcha is showing on my registration form, but the spam registrations persist.

    Anybody have a good solution to this?

    #57559
    stwc
    Participant

    Glad to hear it, levin! Hopefully that’ll hold the floodwaters back until the next generation of bots finds a way around it.

    #57530
    Catherine
    Participant

    how do i do that? i see privacy options, but it just talks about it being spidered by bots –

    #56562
    danbpfr
    Participant

    @michael -> de nada

    Attempt will continue a few days after you did changes. The time spam robots refresh their attack strategy, heu, their cache…

    I couldn’t say to you “be patient”, i know you are, but…wait a little ? This is not Nescafé, but computing… ;-)

    #56524
    Mariusooms
    Participant

    Same problem,started about a few days ago. Bots are signing up a few times a day, firstnamelastname19xx.

    Interesting is that I notice in my stats some ip found my site by searching for “proudly powered by WordPress MU and BuddyPress”.That could be a reason that this particular bot is finding and attacking bussypress installs.

    If this bot is getting past Captcha, I would recommend applying a reverse Captcha technique. Just do a bit of Googling on this, it uses a hidden field as a honey pot which bots will fill in, but normal users will not. When filled in you can redirect them to a page of your choosing.

    Please report your findings and how you deal with this as it would be very helpful.

    #56522
    stwc
    Participant

    As a first attempt, I’ve tried changing the register slug in wp-config and some of the phrasing used on register.php (after copying it from bp-sn-parent to my child theme) to see what happens… will report back on whether or not it confuses the bots.

    #56450
    Jeff Sayre
    Participant

    Data on who viewed a given user’s profile is not stored in the database. To accomplish this task, you would have to write your own plugin and add at least one new table to the DB.

    However, depending on how the plugin was coded, on even a moderately active site, this/these new table(s) could grow to a very large size. For instance, if a given site was not set up to disallow viewing of users’ profiles unless the viewer was logged in, all sorts of useless visitor hits would be encountered–unknown actual people viewing a profile, search engine bots visiting a profile for purposes of indexing, etcetera.

    Of course, the solution would be to code the plugin to ignore those type of hits and only log actual logged in member views. But then the number of true views would be greatly undercounted.

    gazouteast
    Participant

    Hi Jeff – key comment in this reply is the last line ;-)

    So, if your source image is smaller than 150 on at least one of its dimensions, you could have issues with creating the large avatar. If it is smaller than 50 on at least one of its dimensions, you could have issues with creating the small and large avatar

    So what happened to css basics?

    e.g.

    maximum-width; 150px

    note the use of maximum-width as opposed to width – or is that not available in javascript ? (genuine query as I don’t know js coding at all) – also, note the dimensions I gave in reply to Xevo way back up the thread.

    it may be that your server is running too old of a version of the GD image library

    possible, though highly unlikely with this particular host – I’ll check with them though.

    never use the auto-upgrade feature when upgrading WPMU or BuddyPress. It is simple and quick enough to manually upgrade them and it gives you more control and assurance that it is done right.

    Side topic response, but – I’m 2,000 miles from the closest of my servers (Singapore) and 8,000 from the main one where the install is running a deadline, and 12,000 from the US hosts that I also use heavily. It is NEVER quick to manually download the package, extract it and upload it from here – assuming the locals can keep the electric on for more than an hour at a time, and the internet connected for two consecutive minutes – that’s why the auto-upgrader was such a godsend when it arrived in 2.5 Having said that, I’ve noticed some very consistent differences on it with UK and US hosts – both the auto upgrader and the plugins/theme direct download to site and upgrades, work flawlessly on US hosts and never ask for FTP login. On UK hosts, they all always ask for FTP user login from wp-admin, and greater than 50% of the time they fail to complete all expected on-screen steps. I’ve also noticed that UK hosts tend to override the timeout preventions built into WP, which US hosts do not do. ….. don’t get me started on the pricing differences either – LOL

    Are you on a shared or dedicated server? Talk with your hosting firm to see if there is some javascript-based application that the hosting firm has running on your server that could be interfering with the basic JS operations in WPMU

    It’s a shared server, but a reseller account – half way step between shared and VPS as in limited main accounts per server but with dedicated RAM per reseller account and so on.

    The background js / mootools question is a good one that I’ll fire at them.

    On the UK install, I’ve tried every possible config right down to the barest of bones – even to the point of deleting (not just deactivating) all plugins and themes and dropping all tables created by any plugins – still problems persisted.

    It got to the point a couple of hours ago that I finally had enough and made liberal use of the Ctrl+A and Del keys

    Pffzzzzzt – zap – gone – empty domain space. I’ll be nuking the database in a minute or two as well, then uploading from scratch and starting again in the morning (1:00am+ here now) after letting the dust in my head settle after spending the whole weekend scouring the WPMU and BP forums trying to resolve this.

    I’ll also be starting with a WPMU install that has no periods in its directory and folder names – i.e. NO ” blogs.dir ” style of names – I am convinced that is a major source of some problems related to images, just as I am convinced that the user blog folder tree goes way to deep for Google search bots to follow it all the way to the bottom – and that’s gonna hurt SEO.

    As I said up a bit, I’ve nuked the install (and the test installs) and will make a fresh start tomorrow … to mis-quote a famous movie line –

    “I love the sight of deletion in the evenings” ~ Major Lee Pistoff, in aPressolypse Now

    LOL

    Gaz

    #7256
    Mascix
    Participant

    hello all

    I understand that there is no way to stop spam our wpmu installations. capatcha or asking questions maybe stop bots but normal living spammers will go on. here is my suggestion to solve this issue.

    can we disable wordpress mu and buddypress signup and open openID/facebook connect/google friend connect stuff ?

    #53116

    In reply to: BuddyPress Spam

    wordpressfan
    Participant

    I read your example. I need something with a wider net. First off, the robot registration never leave an e-mail address. Unlike WP comment spam, WPMU registration robots appear able to bypass required fields, including e-mail address.

    I receive e-mails announcing new registrations that contain only IP addresses. Meaning I would need to include hundreds of IP addresses in your code.

    The real solution is somehow create a bullet-proof required registration field or move the registration page behind a firewall. I’ve seen single-user WordPress installations that move the wp-admin or wp-signup pages to avoid robot attacks using the default name and location of these pages.

    #6706
    Mike Challis
    Participant

    Please help me beta test the next version of SI CAPTCHA

    I have tested it in WP – WPMU – BuddyPress and it works for me.

    Your testing can help me to be sure..

    Here are the changes in this BETA release:

    = 1.9 BETA =

    – (24 Sep 2009) – Added full WPMU and BuddyPress compatibility. WPMU and BuddyPress users can now protect comment form, registration, and login from spam.

    – Added login form CAPTCHA. The Login form captcha is not enabled by default because it might be annoying to users. Only enable it if you are having spam problems related to bots automatically logging in.

    – New feature: An “advanced options” section to the options page. Some people wanted to change the text labels for the CAPTCHA and code input field.

    These advanced options fields can be filled in to override the standard included text labels.

    – Added new advanced options for editing inline CSS style of captcha image, audio image, and reload image.

    – Minor code cleanup.

    Download the beta here:

    http://www.642weather.com/weather/scripts/si-captcha-for-wordpress1.9-beta.zip

    SI CAPTCHA plugin site:

    http://wordpress.org/extend/plugins/si-captcha-for-wordpress/

    Thanks for your help, Mike Challis

    #52299

    In reply to: Fighting Splogs

    danbpfr
    Participant

    i don’t know if robots go directly into db, or use the wp code…

    but one thing you can try is to hack a little the register_new_user function in wp-login.php

    to ban some email domains like “XXXX@myspacee.info” witch massevely occurs in the past last weeks….

    function begins at line 228 (v. 2.8.4a)

    add this on line 233

    $email_check = explode(“@”, $user_email);

    insert also this at line 248

    } elseif($email_check[1] == ‘myspacee.info’) {

    $errors->add(‘invalid_email’, __(‘ERROR: The email address isn’t correct.’));

    insert the same code and change the mail domain name if you need to ban more domains

    In use with invisible-defender, wp-ban and wp-spamfree i think you would be quiet for a moment with unwanted registering of blogs or users.

    3448011
    Inactive

    I don’t know if this has been mentioned, but when permalinks are enabled for WordPress, the bbpress folder can’t be seen be scanned and shows a 404 not found. I thought it was just my install, but when I tried validating the Buddypress Forum it shows the same result: “Sorry! This document can not be checked,” resulting with a 404. I also tried an online sitemap generator which couldn’t see it either.

    When I disable the permalinks in WordPress, then everything was fine and it could be seen. I also have the same issue with enabling pretty permalinks in bbpress. The Pretty Permalinks work just fine in BBPress when the permalinks are not enabled in WP; but when permalinks are enabled in WP, about 90% of the time it will result in a 404 in IE (if I refresh the page, it will find it – works fine in FF ).

    Also on a bit of a different subject, but since I’m here :), I was curious if there is a way to have search engines blocked from the BP group forums in the bbpress forum. I want to be able to use the forum for more than just the BP groups, but don’t want it to reflect as duplicate content (I want the content for indexing to remain with the groups, not the forum).

    I changed the main topic that BP uses to a category and then was thinking of just using a robots.txt file to disallow that category. Would you recommend me doing it this way or should I do something else?

    I appreciate you help!

Viewing 25 results - 376 through 400 (of 415 total)
Skip to toolbar