Categories: MSDN / DotNet / Java / Scripts / Linux / PHP Ask - La ask - La Answer

Spam

Does anyone know where is the bug that allow auto registrations in vBulltion forums ?
I'm still seraching and testing since yesterday without any results for how we can register in a forum automatically and bypass the captcha check ...

I don't think that there is some ppl who's working only for register in forums to spam !! so if anyone know any informations about this tell me ... of course i want to know for security reasons not for spamming !

And if I get any results I'll share them here ... thanks.
[548 byte] By [Amahdy] at [2007-11-11 11:59:28]
# 1 Re: Spam
It's not a bug, and they don't bypass the CAPTCHA, the new generation of bots knows how to solve CAPTCHA.
JPnyc at 2007-11-12 0:22:57 >
# 2 Re: Spam
And for every one that might make it through, we catch 50 before they ever appear on the site.
Hack at 2007-11-12 0:23:58 >
# 3 Re: Spam
Thanks J for informations, yes we have here a weak captcha and with some image processing and letter recognition we can guess it...
Hack did you mean 50 per day ? this is too much and I would suggest to use a stronger captcha there is too many open source captcha generators all over the internet ...
Amahdy at 2007-11-12 0:25:08 >
# 4 Re: Spam
LOL - no we don't get 50 a day. That was just example numbers to illustrate that we do catch 99% of attempted spam before it ever reaches the forums themselves. :)
Hack at 2007-11-12 0:26:06 >
# 5 Re: Spam
okey; JPnyc actually I don't know it's abbreviation of what ... maybe "Jupiter ... Planet ? ... new york city !!!" anyway I do know that you are the web admin here and I want to take your advice for this :
http://forums.dev-archive.com/showthread.php?t=164789

thanks in advance !
Amahdy at 2007-11-12 0:27:05 >
# 6 Re: Spam
Sorry, security really isn't my area. Oh, and JP are my initials, and yes NYC is New York City.
JPnyc at 2007-11-12 0:28:06 >
# 7 Re: Spam
OK thanks J, but please if you find a suggetion anywhere just give me a buzz there. I have now a very risky server without a firewall !
best regards.
Amahdy at 2007-11-12 0:29:10 >
# 8 Re: Spam
Well, from what I understand you had a firewall, but didn't want to pay for it, right?
Hack at 2007-11-12 0:30:13 >
# 9 Re: Spam
I had a firewall, but I don't use it anymore to not pay those 100$/m anymore ...
I want :
1- strongly recommend to re-use it and why ...
2- alternate cheaper than checkpoint's firewall [but not very bad like **]
3- suggest to buy the software once and install it manually at the server
4- other suggestions ...

**: because sometimes anti-virus and anti-spy become close to virus according to the control and bugs they have, and the low experience of the implementation . checkpoint is PERFECT and i'm plaining to use it again but now what ?
Amahdy at 2007-11-12 0:31:14 >