Skip to:
Content
Pages
Categories
Search
Top
Bottom

Search Results for 'bots'

Viewing 25 results - 126 through 150 (of 415 total)
  • Author
    Search Results
  • Parsnipnose3000
    Participant

    Wordpress 3.8
    BuddyPress 1.9.1

    Hi everyone,

    Virtually our registrations appear to be coming from the IP address of our server, as opposed to the IP address of the registrant’s ISP.

    Is there a setting somewhere we missed, or are the spambots managing to spoof their IP?

    If that’s the case, I’d imagine we’d run into problems if we try to block our own IP address?

    #176615
    Henry Wright
    Moderator

    Also, rename your ‘register’ page to something else. Lots of spam bots look for /register/ so something as simple as /register-page/ will help hide your sign up form from at least a few of the bots.

    #174385

    Topic: A Guild Wars 2 guild

    in forum Showcase
    isopaha
    Participant

    Hey,

    I just finished creating the 2.0 version of my guild’s website. The earlier version was running really old wp+bp+bbp, so I wanted to create everything from the ground up.

    I had a lot of issues importing the forums and users from the old site, since I didn’t want to import thousands of spambots.

    Anyway, you can check out the forum at:
    [Deleted per request] and the whole site at the same place.

    I’m running BuddyPress + BBPress. What do you think? Site is fully responsive but I still have some graphic elements and css to fix on some resolutions. Any feedback is welcome 🙂

    EDIT: One of my biggest issues is that the Search widget is not searching anything from the forums, so I have to use some BBPress search widget, which in other hand doesnt search anything from posts. Any ideas for a fix?

    DennisH
    Participant

    When using the bbPress plugin for forums spam bots can bypass your registration and create accounts using the template files found here: buddypress/bp-forums/bbpress

    Not only can they bypass any anti-spam features (including email conformation), their activity will not show in your normal forums. The spam posts will only show if you follow the default permalink: http://example.com/wp-content/plugins/buddypress/bp-forums/bbpress/ There you will find a vanilla install of bbPress where the spam posts live.

    Buddypress should not be used unless you delete these bbPress files. Spam bots can easily create thousands of posts/accounts per minute with nothing stopping them until your server crashes.

    #172894
    danbp
    Participant

    hi @trinzia,

    don’t ask here about YOUR security settings ! We are not reading in chicken guts or in cristal bowls. 😉

    Also, if you use BP 1.8+, a solution given over a year back cannot work (most of time)

    See here an old discussion with a recent answer (2 mounth) – has patch.

    But before to do something, check your WP settings if comments are allowed and/or if comments are allowed for your test post (sorry for this, but… nobody’s perfect ! 😀 )

    Also, if you cheched site indexing by robots (settings > reading) it may be possible that the comments won’t show up on the activity wall.
    Encountered this a few mounth back with bbPress forum answers on a bp 1.7/bbp 2.3 install

    #170713
    xprt007
    Participant

    Hi

    I have a whole host of different security plugins, including Aksimet (free), bad behavior, IP blacklist cloud & Wordfence security and these at least manage to prevent anonymous topic & unmoderated posts.

    Somehow some bastards, for lack of a better word always manage to create a group with long spam descriptions every 1 – 2 weeks. I do not remember Statcounter registering these visits, including the latest, which makes me think the posts are probably or mostly by bots.
    The problem these created groups are not moderated making worry some very bad stuff could easily get posted.

    How can one effectively prevent this?

    Thank you in advance.

    GalenL
    Participant

    Good Afternoon Ladies and Gentleman,

    I have two questions. How do I add a captcha to my user registration page to prevent bots from spamming my website?
    I currently have the following Plugins installed: Buddypress, Facebook Link.

    Conceivably, I also would like to do is this:
    When someone creates an account, they link it to their facebook. Thereafter, the account details from their facebook is added to current profile
    Its pretty much the same idea as what Tinder does when registering and using
    http://www.gotinder.com/

    Not sure if a plugin exist, if one does, that kicks ass. If not, does anyone know where i can find a good tutorial explaining, step by step, how to do this.

    Thanks,
    GalenL

    #170068
    loki_mdog
    Participant

    So I have looked all over the web and found multiple ways that are supposed to work but I am still having links become automatically linked. I am running BuddyPress Version 1.7.3.

    I have tried:


    function remove_xprofile_links() {
    remove_filter( 'bp_get_the_profile_field_value', 'xprofile_filter_link_profile_data', 9, 2 );
    }
    add_action( 'bp_init', 'remove_xprofile_links' );

    and


    remove_filter( 'bp_get_the_profile_field_value', 'xprofile_filter_link_profile_data', 50 );

    And have tried in plugins/bp-custom.php and in my theme’s functions.php file but no joy.

    Looks like things have changed over the years and that plugins to do this that worked for earlier BuddyPress versions have disappeared also.

    When someone enter something under Activity (under their profile) and post an update, the contents of that update will have URLs links automatically, something we want to do to discourage the actual humans (not bots) who are spamming our site.

    Thanks!

    robsimm
    Participant

    BP Version: 1.8
    WP Version: 3.5.2
    Theme: CStar Design
    Running BuddyPress Template Pack (because of issues here:http://buddypress.org/support/topic/theme-compatibility-issue)

    When AJAX is enabled under the BuddyPress Template Pack – when a user navigates the /groups page and interacts with any components (such as next page or filters) the AJAX requests loads in the homepage of the site. Disabling AJAX appears to resolve the issue – however this renders the site almost useless as functions such as creating a new topic, ordering etc all REQUIRE JS to work (which seems counter-intuitive).

    Network trace of an AJAX request being made, below:

    Request URL:http://www.members.pcosdietsupport.com/wp-admin/admin-ajax.php
    Request Method:POST
    Status Code:302 Moved Temporarily
    Request Headersview source
    Accept:*/*
    Accept-Encoding:gzip,deflate,sdch
    Accept-Language:en-US,en;q=0.8,en-GB;q=0.6
    Connection:keep-alive
    Content-Length:183
    Content-Type:application/x-www-form-urlencoded; charset=UTF-8
    Cookie:__utma=63762478.146401814.1374613173.1374613173.1374613173.1; __utmz=63762478.1374613173.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wordpress_test_cookie=WP+Cookie+check; __utma=7220526.495359790.1374613143.1374613143.1374620066.2; __utmb=7220526.17.10.1374620066; __utmc=7220526; __utmz=7220526.1374613143.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); bp-activity-oldestpage=1; bp-groups-scope=all; bp-groups-filter=active
    DNT:1
    Host:www.members.pcosdietsupport.com
    Origin:http://www.members.pcosdietsupport.com
    Referer:http://www.members.pcosdietsupport.com/groups
    User-Agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1573.2 Safari/537.36
    X-Requested-With:XMLHttpRequest
    Form Dataview sourceview URL encoded
    action:groups_filter
    cookie:bp-activity-oldestpage%3D1%26bp-groups-scope%3Dall%26bp-groups-filter%3Dactive
    object:groups
    filter:active
    search_terms:
    scope:all
    page:1
    extras:

    Response Headers

    Access-Control-Allow-Credentials:true
    Access-Control-Allow-Origin:http://www.members.pcosdietsupport.com
    Cache-Control:no-cache, must-revalidate, max-age=0
    Connection:Keep-Alive
    Content-Type:text/html; charset=UTF-8
    Date:Tue, 23 Jul 2013 23:38:53 GMT
    Expires:Wed, 11 Jan 1984 05:00:00 GMT
    Keep-Alive:timeout=5, max=100
    Location:http://www.members.pcosdietsupport.com
    Pragma:no-cache
    Server:Apache
    Set-Cookie:wordpress_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/wp-content/plugins
    Set-Cookie:wordpresspass_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/
    Set-Cookie:wordpress_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/wp-admin
    Set-Cookie:wordpress_sec_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/wp-admin
    Set-Cookie:wordpressuser_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/
    Set-Cookie:wordpress_sec_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/wp-content/plugins
    Set-Cookie:wordpress_logged_in_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/
    Set-Cookie:wordpresspass_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/
    Set-Cookie:wordpress_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/
    Set-Cookie:wordpress_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/
    Set-Cookie:wordpress_sec_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/
    Set-Cookie:wordpress_sec_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/
    Set-Cookie:wordpressuser_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/
    Set-Cookie:wordpress_logged_in_ddce7cb18cd676f3acecd22812907965=+; expires=Mon, 23-Jul-2012 23:38:53 GMT; path=/
    Transfer-Encoding:chunked
    X-Content-Type-Options:nosniff
    X-Frame-Options:SAMEORIGIN
    X-Powered-By:PHP/5.3.24
    X-Robots-Tag:noindex

    Having looked through the BuddyPress installation I did find handlers for AJAX operations – but there doesn’t appear to be anything out of place with them receiving/correctly interpreting the request.

    Can someone kindly provide insights into this?

    Thanks!

    crm50cc
    Participant

    I’m sure many of user and owner of a site using buddypress, ask himself”do I want my site activity to be indexed by search engine?”. Well I think it would be better for my user to not index the activity,but I have to say that google index most of my activity streams from my site(big exposure) but no privacy for users at all.I would like to know what the buddypress community think about this because it is very interesting to see that there is no privacy for buddypress member(profile show e-mail address,activity show to non member and etc for example).
    To come to my real question I have a hard time to figure how to set my robots.txt file to block activity stream and profile page from been index(/directory path).
    After hours on my webmaster tool(obviously without success) I decide to ask you guys the solution.
    Thank you

    larrymac
    Participant

    I’m creating a new site and to avoid the spambots while I work, I’ve blocked new members from signing up. When I create a new account as Admin, everything seems to work and the image that I’ve assigned for people without avatars shows up if I sign in under that account.

    But…

    If I look at the members page, it shows the member info and “Profile Picture of <user’s name>” where the photo should be. I can then log in with that account and change the avatar normally, but as a result I wind up with multiple uploads of the same photo for each member that I have using the same avatar.

    Any thoughts on what I’m missing? I’ve included the link below and I’ll hold off on correcting the two latest “victims” of this issue.

    Thanks!

    http://www.larrymac.net/dcpress/members/

    #166763

    In reply to: Untraceable spam user

    mareksgregs
    Participant

    @ubernaut I tried that Wangguard plugin (thanks for introducing it to me by the way, it’s awesome) and when I scanned the user, it’s status came back as “Error – 101”

    I don’t see how my site could be hacked though. Perhaps the problem is in one of my plugins. Unlikely though. All of my active plugins are legit and shouldn’t have spam bots in their files…

    #166446
    inge12
    Participant

    Leofitz, WangGuard will check your user base for spammers and delete them.

    See https://wordpress.org/plugins/wangguard/

    The author says that “WangGuard not only protect your site from sploggers, spam users or unwanted users, WangGuard cleans your database from them. No plugin or service does this, only with WangGuard you will get this feature,” and I believe him. His English may not be too good, but the plugin is really outstanding.

    There’s just one consideration for you: In order to have your database cleaned up, you will have to submit far more than 500 queries the first month. Perhaps you can arrange to pay for a month?

    Here’s my suggestion to reduce database queries after that. (It worked for me.) Buddypress allows for the customization of User Profiles. Add a couple of questions that require a certain amount of intelligence to answer and make them required. That means the form will not be submitted either to WordPress or to WangGuard if the required fields are not filled out. It’s not fool-proof, but it decreased queries on my very busy site to just a few a day.

    Incidentally, I added a question, “How do you plan to participate?” Among the choices offered the user are these:
    “I want to increase my online presence.” and
    “I want to sell my stuff.”

    We don’t need anyone not bright enough to figure out that these replies do not make the user desirable. Now all I need is a script to automatically kick out users who choose these replies. 😉 (As it is, they can be manually deleted if other users report them.)

    I don’t know what happens to a group when all the users are unsubscribed, so this may not be precisely what you are looking for. But WangGuard will make your site secure against almost all sploggers. (One registrant passed all tests on our site, and we had to delete manually, but that person must have registered manually too.)

    Good luck!

    Inge (http://ssnet.org)

    #166405
    Ben Hansen
    Participant

    maybe not as long as you think if you use the backend, can’t you mass delete them that way?

    #166380
    Leofitz
    Participant

    Are there any current plugin solutions which can delete accumulated BP spam groups? The BP Group Management plugin did this, from what I’ve read, but it gives error messages with the current versions WP 3.5.1 and BP 1.7.2

    Any suggestions will be appreciated as I have a couple dozen WP-BP sites and some have 1000-5000 groups that are spam generated. Manually deleting these would take me until 2014!

    rcain
    Participant

    ps. we also use (dreaded) captcha fields (plugin) on forms, but have noted of late there are bots out there (eg: XRummer, et al) scraping such captcha images off the web in order to seed simple AI scripts to bypass such protection. pretty clever stuff & born out by what we see in our logs.

    rcain
    Participant

    @bp-help

    good suggestions. thx. 2 of them r new to me, so other people may find them helpful also.

    on our sites we r using::

    Keith Graham’s most excellent ‘stop-spammer-registrations-plugin’ – https://wordpress.org/plugins/stop-spammer-registrations-plugin/

    – has stopped over 53,000 spammers since feb this year! it uses external lookups on StopForumSpam, ProjectHoneyPot, BotScout, (Akismet, which we dont use), others – thus great collective benefit/advance warning of bad traffic. also traps brute force attacks (bad logins/registrations/comment posts, etc), etc. is simple enough to play nice with most plugins.

    to try & keep as much load off the front-end of the server as possible, we also have set up:

    linux iptables ( & ufw add on )- as the basis of all firewall stuff. also has our manually maintained blacklists & whitelists. various custom rule chains setup. takes a while to get your head around, but is essential.

    linux fail2ban – essentially an add on to iptables, puts people in jail for bad behaviour – eg: brute force attacks against ssh, ftp, mail logins. we also have set up custom rules detecting bad activity against wp-login.php itself via fail2ban. am looking to do some more with this.

    linux apache – mod-security2, libapache2-mod-evasive, libapache2-mod-antiloris, libapache2mod-spamhaus – which help protect against general bad behaviour, DDOS, blank header attacks, the infamous ‘Loris’ script (which we’ve experienced!), and bot-nets. still assessing how effective these r.

    we have also had to tune apache on our VPS for resilience in the face of DDOS type attacks and heavy-handed brute force attacks.

    some further good tips here: http://www.dannytsang.co.uk/index.php/apache-2-hardening-tips/ & elsewhere.

    linux logwatch – reports various access stats (the good & the bad & the ugly) via email – very useful indeed for checking whther situation is under control (or not).

    linux rkhunter – scans for rootkits on the server from time to time – just be sure – & particularly useful if u ever do get infected in hunting down the intruder’s code.

    obviously we also have file system bolted down. (there is a good wp plugin to check permissions bolt-down, i forget what its called). we also spend a LONG time analysing logs etc.

    anway, that takes care of many of the bad boys, but we r still left with the following problems to crack:

    1) we have observed that many bad bots/scripts are exhibiting ‘learning behaviour’ (ie. heuristic) and r finding ways around fail2ban rules/jails, etc. in particular:

    a) rotating IP addresses to match ‘ban counts’ – currently we have them wasting an IP address every 3-4 attempts, but they still seem to have an inexhaustable supply, else are spoofing extreamly well.

    b) varying their retry period to match the length of jail sentence. (ie. they are not wasting their mips whilst in jail, just enough to detect when they are released,record it, and tune their future responses).

    2) content scrapers, probes and bad-bots generally – these r wasting enormous resource on our servers. typically i would suggest such ‘bad traffic’ is responsible for over 50% of total server load (ie. not good at peak times on a busy site). additional problems we r facing here:

    a) bad bots often spoof the agent string to pretend to be eg. google, bing, etc. the only way u can tell is by reverse lookup of ip address and try and match to one of well known range of ‘good bot’ addresses. but, despite fact that many ranges are well known, most of them are never actually published or confirmed, many are variable. i am not aware of any definitve list of ip addresses of good bots (though there is http://www.iplists.com/ whichis not bad, & http://www.webmasterworld.com/search_engine_spiders/ which is often helpful – these are very much ‘best efforts/as seen in the wild’ lists.). this problem worsens with the rise of social network agregation services, other (legitimate) content agregators, and personal content aggregating software on mobiles, tablets, etc.

    idea: i am thinking of writing a script/plugin/rule to do smart lookup of ip against good bots list, & to automatically maintain that (collective) list. ideally, this is a service that someone like spamhause, or projecthoneypot should offer, since they already have the infrastructure. but, we’ll see. the script will detect traffic ‘purporting to be a SE bot, of any kind and to ban it via iptables if it isnt in the approved list/doesnt check out. the risk is in false positives and harming ones SEO. anyone any thought in this area?

    b) probes & sniffers hunting out wp/bp forms, ajax ports, plugin files, forms, etc – in advance of main attack by penatration/spamming bots. typically always use swiftly rotated ip’s. many many variants out there. usually they have no luck on our sites, but that does not stop them trying in vast numbers (bot-nets, collectives? hives?) and harming out response times, etc.

    idea: url obfuscation has been brought up on this forum before, particularly for eg: login, registration, admin url’s, etc. i am thinking of creating a plugin to dynamically hash encode links of choice using someething based on wp forms nonce system. not only useful for causing probes & hackers pain, but also to help thwart media thieves. obviously, scripters will soon respond by just snanning for link titles in html, so not bullet proof in any way, but they will at least be on 1-time request code, so causing them page reload every request & less sophisticted scripts will be totally wasting their own time.

    anyway. these have been my thought so far. would love to hear experience/insights of others.

    unfortuntely wordpress & buddypress sites in particular represent the richest of prizes for hackers, content scrapers, spammers, etc – & they r really on our case. furthermore, there is some BIG money involved, from porn to pharma to credit card fraud; that means some very smart programmers being paid excellent rates, to hack our systems, full time. add to that, the 10’s of millions of infected machines out there (often unknowingly) operating as botnet drones, trying to pernetrate our servers 24×7, steal our machine resources and steal our members personal data. it is a war of attrition.

    all further experience, ideas welcome, here.

    bp-help
    Participant

    @dice2dice
    You can change the register page name and slug to sign-up.
    You can also try using Private Community For BP:
    You will also need to change line 27 in private-community-for-bp.php from /register to /sign-up to reflect the change of the register slug.
    If your not using it you can get it here:
    https://github.com/bphelp/private_community_for_bp
    Another thing you can try is this small plugin “Spam Killer” which creates a hidden field humans can’t see, spam-bots will see it and fill it out and get a message indicating spammy behavior and it rejects their registration. Get it here:
    https://github.com/bphelp/bp-spam-killer
    Please read the readme.txt for complete instructions for usage for both plugins.

    #165438
    bp-help
    Participant

    @tux-kapono
    Why would it be confusing unless you have several admins? Subscribers should not have access to how many registered users there are in the dashboard anyway. Unless those users are active participants wouldn’t it kinda mislead new legitimate registered users that there is more active members than what is truly there? Most likely the registered users that never logged in was either spam-bots or human spammers and most people fight that tooth and nail. If you have several admins then I would just communicate that to them.

    #165418

    Topic: SignUp Error

    in group forum Installing BuddyPress
    #165279
    bp-help
    Participant

    @wpbp
    I produced a small plugin that is geared toward automated spam attacks but I haven’t gotten any feedback as far as its effectiveness:
    https://github.com/bphelp/bp-spam-killer
    As far as spam attacks from real users I think there are helpful solutions out there but spammer hacker types will always find way to circumvent any prevention method so the best prevention as an admin is being active on your site.

    #165277
    inge12
    Participant

    One plugin that looks good for preventing registration spam is WangGuard. (Search for it in the WordPress repository.) I’ve just installed it, so can’t tell you if it’s as good as it sounds. (I run a very busy blog and allow commenting by unregistered users. Akismet catches spam and Conditional Captcha deletes it without my seeing it. The latter reduced spam from hundreds of comments a day [marked by Akismet] to near-zero. Only the occasional human spammer gets in.)

    Allowing unmoderated registrations is spammer nirvana. 😉 I allowed posting by unregistered users so I could turn off user registration. Now that I’m wanting to use Buddypress, I had to enable registration but installed WanGuard. Within a few hours, I had one registration attempt — even though Buddypress can’t be seen anywhere on the site yet — but no successful registration, thanks to WangGuard. Tomorrow will tell me more.

    #165246
    @mercime
    Participant

    @wpbp 1. Disable registration in Settings > General.

    2. Disable group creation in Settings > BuddyPress > Settings > Groups.

    3. Disable album creation/uploading of images in the plugin’s settings or are you referring to native WP image galleries?

    You can enable group creation and registration after you’ve done some general housekeeping and adding some spam/spammer prevention.

    #165245

    @wpbp, The problem is that many spam nowadays are not bots but real human spam. I have same problem on one of my installation. all you can do is to ban the domain which has been a source of spam to your site. e.g: spam1@me-now.com. spam22@me-now.com

    when you put “me-now.com” in the following code, it will ban any email from me-now.com, Put it in your functions.php

    http://pastebin.com/a2mTNVZX

    Note: I have 3 sets of this code, I have the one which can ban specific email from gmail, yahooo, hotmail etc without banning other users using gmail, yahooo, hotmail. if you want that aswell i can post it or all the 3 if someone can release it as a free plugin , no problem.

    Naijaping

    #165241
    wpbp
    Participant

    I installed buddypress a few weeks ago now i have so many fake members making groups empty albums and they post for more info about blank go to blank.comand then they vanish.
    *Blank means there website and company PLEASE HELP-WPBP buddypress 1.7.2 wordpress 3.5.1
    http://WWW.Postau.com

Viewing 25 results - 126 through 150 (of 415 total)
Skip to toolbar