Irish SEO,  Marketing & Webmaster Discussion

 
ThinkGeek - Cool Stuff for Geeks and Technophiles

Form spammers !

This is a discussion on Form spammers ! within the Webmaster Discussion forums, part of the Webmaster Help category; HI All One of my sites carries an online petition - based on a guestbook script which was part of ...


Go Back   Irish SEO, Marketing & Webmaster Discussion > Webmaster Help > Webmaster Discussion

Register Forum Rules FAQDonate Members List Calendar Search Today's Posts Mark Forums Read


Notices

Reply

 

LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 23-09-2008, 09:24 AM
Coder
 
Join Date: Aug 2008
Posts: 44
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
adrian5750 will become famous soon enough
Default Form spammers !

HI All

One of my sites carries an online petition - based on a guestbook script which was part of NetObjectsFusion....

We seem to be getting attacked by spambots - posting links to porno, drug or gambling sites.

I've modified the script so that it detects such posts - and substitutes the spambot's content for a discrete little '-' symbol - which appears on the webpage, to remind me to go into the admin area ad manually delete the offending posts. It works - but it's time-consuming....

Originally, I was wary of 'false positives' from my detection code - but it seems to be pretty good at spotting the spam - so I'm wondering what's the 'best' thing for the script to do when it spots spam...

Should it
a) Appear to accept the entry but quietly 'bin' it ?
b) Refuse to accept the entry, throwing some kind of error code ?
c) Some other response
d) Cause the instigator of the spam to break out in painful boils, their pc to go up in flames and their TV set to be tuned to endless reruns of Wogan

Any (practical!) ideas ??

Thanks
Adrian
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 23-09-2008, 09:35 AM
louie's Avatar
Senior Member
 
Join Date: Jan 2006
Location: Dublin, Ireland
Posts: 2,033
Nominated 5 Times in 3 Posts
Nominated TOTW/F/M Award(s): 1
louie will become famous soon enoughlouie will become famous soon enoughlouie will become famous soon enoughlouie will become famous soon enoughlouie will become famous soon enoughlouie will become famous soon enoughlouie will become famous soon enoughlouie will become famous soon enough
Send a message via Yahoo to louie Send a message via Skype™ to louie
Default

Did you try "CAPTCHA" ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 23-09-2008, 09:37 AM
Forbairt's Avatar
respect my AW-THOR-IT-AYY
Recent Blog: Free CSS book
 
Join Date: Jun 2007
Location: My Office, Dublin
Posts: 2,095
Nominated 2 Times in 1 Post
Nominated TOTW/F/M Award(s): 1
Forbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enough
Send a message via AIM to Forbairt Send a message via MSN to Forbairt Send a message via Yahoo to Forbairt Send a message via Skype™ to Forbairt
Default

as louie said ...

I like this one .. but it can be confusing for your end users.

What is reCAPTCHA?
__________________
Forbairt Media | Web Design & Development Galway / Dublin, Ireland - coming soon ... ( vague but descriptive isn't it )
Recent Work: Safari Club African Safari Holidays - Malawi Safaris
Other Stuff: FluffyLinkulator Rapid Inclusion Service Tools
Jumper Stuff: Task Drop's Official Geansai Gorm Website
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #4 (permalink)  
Old 23-09-2008, 09:51 AM
Coder
 
Join Date: Aug 2008
Posts: 44
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
adrian5750 will become famous soon enough
Default

HI Folks

Yes - we did run CAPTCHA for a while - but it seemed to confuse the h*ll out of people - and I got loads of emails from people asking how to fill the form in....

I'm happy with 'detecting' spam entries (if 'happy' is the right word!) -
but it's what to do with them that's puzzling me.

I'm guessing that the spambots don't care about geting a response from the website - so sending them back a nice error code won't have much effect...

Probably best to simply throw away the spam entries - do you think ??

Regards
Adrian
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 23-09-2008, 09:54 AM
Forbairt's Avatar
respect my AW-THOR-IT-AYY
Recent Blog: Free CSS book
 
Join Date: Jun 2007
Location: My Office, Dublin
Posts: 2,095
Nominated 2 Times in 1 Post
Nominated TOTW/F/M Award(s): 1
Forbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enough
Send a message via AIM to Forbairt Send a message via MSN to Forbairt Send a message via Yahoo to Forbairt Send a message via Skype™ to Forbairt
Default

investigate simple challenges ...

What is 2 + 2?

What is two plus two?

What colour is the sky ?

(I noticed a huge drop in the past using this on one site)


Alternatively have multi page forms ... they usually are more comlicated for spambots to get right .. though obviously not impossible..
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 23-09-2008, 10:01 AM
Coder
 
Join Date: Aug 2008
Posts: 44
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
adrian5750 will become famous soon enough
Default

Quote:
Originally Posted by Forbairt View Post
investigate simple challenges ...

What is 2 + 2?

What is two plus two?

What colour is the sky ?

(I noticed a huge drop in the past using this on one site)


Alternatively have multi page forms ... they usually are more comlicated for spambots to get right .. though obviously not impossible..
<g> - You haven't met some of our users <gg>

Seriously though - I'm not paranoid about the spam thing - just wondering what's the best way to deal with a spam entry - serve up an error code or just 'smile sweetly' and ditch the entry ?

Thanks
Adrian
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #7 (permalink)  
Old 23-09-2008, 10:16 AM
Forbairt's Avatar
respect my AW-THOR-IT-AYY
Recent Blog: Free CSS book
 
Join Date: Jun 2007
Location: My Office, Dublin
Posts: 2,095
Nominated 2 Times in 1 Post
Nominated TOTW/F/M Award(s): 1
Forbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enough
Send a message via AIM to Forbairt Send a message via MSN to Forbairt Send a message via Yahoo to Forbairt Send a message via Skype™ to Forbairt
Default

I assume then you're just doing some form of regexp ? to see if there is mention of hot donkey loving ?

From a data point of view I'd be keeping all entries ... but flagging them as spam. I wouldn't alert the end user that you think its spam.

Its up to you to educate your end users so I'd really be more in favour of adding in some form of blocking though. Challenge / Captcha

You're manually processing these at the moment ... when you have 50 sites doing this will you manually process these every day ... when you've 100 ? ... and so on ? ... going to hire someone to validate entries all day long ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8 (permalink)  
Old 23-09-2008, 11:24 AM
Coder
 
Join Date: Aug 2008
Posts: 44
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
adrian5750 will become famous soon enough
Default

Quote:
Originally Posted by Forbairt View Post
I assume then you're just doing some form of regexp ? to see if there is mention of hot donkey loving ?

From a data point of view I'd be keeping all entries ... but flagging them as spam. I wouldn't alert the end user that you think its spam.

Its up to you to educate your end users so I'd really be more in favour of adding in some form of blocking though. Challenge / Captcha

You're manually processing these at the moment ... when you have 50 sites doing this will you manually process these every day ... when you've 100 ? ... and so on ? ... going to hire someone to validate entries all day long ?
Yes - it seems that simply checking for "http://" in the comments field of our form is sufficient to catch most of the porno / drug spam.

As to 'scaling up' the exercise to 50 - 100 sites - it's not going to happen. Been there, done that (15 years ago!) - this particular site is the campaign site for the restoration of the Swansea-Cork ferry (BringBacktheSwanseaCorkFerry Campaign) - and I'm not about to make a habit out of campaign sites, or any other sites, for that matter...

'Good' entries go straight onto the website - it's only the 'bad' ones that need personal attention <g> - but it's still a pain!

So - rather than throw an error you'd just flag the entries as 'do not display'....? Sounds good...

Thanks
Adrian
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #9 (permalink)  
Old 23-09-2008, 11:31 AM
Forbairt's Avatar
respect my AW-THOR-IT-AYY
Recent Blog: Free CSS book
 
Join Date: Jun 2007
Location: My Office, Dublin
Posts: 2,095
Nominated 2 Times in 1 Post
Nominated TOTW/F/M Award(s): 1
Forbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enoughForbairt will become famous soon enough
Send a message via AIM to Forbairt Send a message via MSN to Forbairt Send a message via Yahoo to Forbairt Send a message via Skype™ to Forbairt
Default

I'd be inclined to use something like Stop Comment Spam and Trackback Spam Akismet it things get flagged by it ... you probably need never worry about looking through them. (At least I don't) The rest you'll have to worry about.

I guess if its just a once off project you're good to go.

But ... you're basically saying I could go to your site and so long as I don't put in http:// ... my comment will be thrown up automagically ? or did I misread ?

so I could go say "The donkey loves the feel of Pantene in its hair" and all will be good in the world of your comment form ?

Last edited by Forbairt; 23-09-2008 at 12:17 PM. Reason: inclined not included ...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #10 (permalink)  
Old 23-09-2008, 12:05 PM
Coder
 
Join Date: Aug 2008
Posts: 44
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
adrian5750 will become famous soon enough
Default

Quote:
Originally Posted by Forbairt View Post
I'd be included to use something like Stop Comment Spam and Trackback Spam Akismet it things get flagged by it ... you probably need never worry about looking through them. (At least I don't) The rest you'll have to worry about.

I guess if its just a once off project you're good to go.

But ... you're basically saying I could go to your site and so long as I don't put in http:// ... my comment will be thrown up automagically ? or did I misread ?

so I could go say "The donkey loves the feel of Pantene in its hair" and all will be good in the world of your comment form ?
Thanks for the Askimet link - filed away just in case.... <g>

Yes - this is one of those exercises where there's no need to make a 'terribly complex - solves everything' sort of solution...

I do actually read all the entries that come in on the e-petition - mostly because some of them are from folks that we can involve in the campaign.... - but also to spot the 'odd' post that passes the filters but shouldn't.... - either because of deviance <g> or general swearing & rudeness or libellous content...

All posts find their way to me by email - so it's fairly easy to control - just when you get a couple of days like we've just had where 95% of the posts are pornospam, you start to think 'Is there a better way'...

I'm hoping that the ferry will be restored in the near future..... and I can relinquish my 'moderator' role.... - got one or two more exciting things to do....

Thanks
Adrian
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Tags
form, spammers

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads

Thread Thread Starter Forum Replies Last Post
Gmail succumbs to the spammers Spiralli General Chat 2 24-04-2008 10:08 PM
Dealing With Spammers blacknight Server / Technical Administration Tips and Queries 15 25-10-2006 10:44 AM


Sponsored links

Paid On Results


All times are GMT +1. The time now is 03:41 PM.


Powered by: vBulletin Version 3.7.3, Copyright ©2000 - 2008, Jelsoft Enterprises Limited.
Hosted in Ireland by Blacknight - Test your ISP |Irish Hosting Directory| Armchair.ie|Logo by Eden Web Design|Avatars by Afterglow |Latest Blog Entries | VPS HostingAd Management by RedTyger

Search Engine Friendly URLs by vBSEO 3.2.0