Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Spam Filter: Current Captcha is not 'catching' SPAM sign ups #107

Closed
kathreenriel opened this issue Mar 22, 2017 · 17 comments
Closed

Spam Filter: Current Captcha is not 'catching' SPAM sign ups #107

kathreenriel opened this issue Mar 22, 2017 · 17 comments

Comments

@kathreenriel
Copy link

kathreenriel commented Mar 22, 2017

There are 46 more 'pending' SPAM registrations in the earlyyearsbc.ca today

@alex-418
Copy link
Contributor

Looks like they can beat the image captcha. Only a couple options I can see at this point, we can try the honeypot Brad suggested to trick bots into filling out a hidden field, but I have a feeling if they are sophisticated enough to beat image captcha, then they can also beat that... is enabling re-captcha on the table here?

@bdolor
Copy link
Contributor

bdolor commented Mar 22, 2017

The pattern in the log file isn't consistent enough set up something predictable for fail2ban to kick in. Regardeless, I've dropped a few IP blocks from being able to connect to the server. Working on the honey pot code now. Would like to see if that works.

@alex-418
Copy link
Contributor

@bdolor Ok, leaving this one to you then!

@bdolor
Copy link
Contributor

bdolor commented Mar 22, 2017

resolved via BCcampus/validate-by-domain#5

@bdolor bdolor assigned kathreenriel and unassigned bdolor Mar 22, 2017
@kathreenriel
Copy link
Author

@paulagaube would you post an update in this comment thread to indicate how much spam ( if any ) is still getting through?

@paulagaube
Copy link

As of this afternoon, there are 2 new "Pending" user accounts that are spam. I deleted 2 earlier in the day that Brad said he saw last night. So the honeypot has helped.
FYI, these are the domains on the email addresses in Pending now.
@guild.kellergy.com
@hash.marvsz.com

@paulagaube
Copy link

FYI, today there are 11 new Pending users that all use these three email domains:
big.360ezzz.com
books.ultramoonbear.com
horn.islaby.com

Also, one fake subscriber which I received an email about: marshall@top-toys.info.

@paulagaube
Copy link

Is there any way we could add a column for "account created date" in the WordPress Users page? I'd like to be able to sort users by when they created their account to see who created accounts recently.

@kathreenriel
Copy link
Author

kathreenriel commented Mar 24, 2017

I look under Activity in the Dashboard to see recently created accounts

@bdolor
Copy link
Contributor

bdolor commented Mar 24, 2017

added the spam domains to the 'blacklist' BCcampus/validate-by-domain@046b1b4

@paulagaube
Copy link

FYI, today I marked 10 more accounts as spam from these domains:
cvmania.pl
cheaplondon-escorts.eu

These were created in the last couple days.
Also deleted three other "Pending" spam accounts.
The accounts were "Subscribers" with avatar images uploaded, but in their extended profile were neither "Learner" nor "Organizer".

The other day marked another German user as spam.

@paulagaube
Copy link

paulagaube commented Apr 13, 2017

Since April 8th there have been close to 100 new spam user accounts created on the earlyyearsbc.ca website. What has changed? I thought some of these domains had been previously blocked but they are now showing up again. Is it possible to block users from outside British Columbia or Canada from creating accounts?

These domains the most prevalent in the past two days and would appreciate having these blocked:
@hog.marrived.com
@long.pixymix.com
@hash.marvsz.com
@guild.kellergy.com
@cvmania.pl
@ulgacrbazt.pl
@cbdolejki.pl
@cbdlandia.pl
@wugjeyxwgv.pl

I would like to delete these user accounts rather than mark them as SPAM. Is that a good idea or a bad idea? There is a Bulk Actions feature that would allow me to delete all the users, but it looks like there is no Bulk Action option to change the Role to "No Role for this Site".

@bdolor
Copy link
Contributor

bdolor commented Apr 13, 2017

@paulagaube - I've fixed a flaw in the spam logic that was letting these through and added a top level domain filter, so that we don't have to every variation of @baddomain.pl and @spamdomain.eu BCcampus/validate-by-domain@3c71b10

I've pulled these changes over to both prod and dev.

I see no value in keeping the 100 or so spam user accounts. Delete away!

@paulagaube
Copy link

Thank you, I've been converting all from subscribers to "No role" and it is annoying....I will blast these accounts away and be done with it, thank you!!

@paulagaube
Copy link

More spam accounts created on April 21. I deleted these accounts on April 24th.
(Username - email address)
ewypysyl - maksymilian@ulgacrbazt.pl
afiwyc - agata@cbdlandia.pl
oxikupal - malgorzata@wugjeyxwgv.pl
akycir - zimnoch.rafal@tlen.pl
iduxutur - kamil.chech@prokonto.pl
apaluni - wojtek@cvmania.pl

@paulagaube
Copy link

Another spam ".pl" user created an account at 3:51pm today. I already deleted this user.
Username: yxutamu - Email: kamil.chech@tlen.pl

@bdolor
Copy link
Contributor

bdolor commented Sep 11, 2017

seems to have been resolved

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants