Spam botnets
- brokenman
- Site Admin
- Posts: 6104
- Joined: 27 Dec 2010, 03:50
- Distribution: Porteus v4 all desktops
- Location: Brazil
- Contact:
Spam botnets
We are currently being attacked by spambots on a massive scale. Many sites are so this is nothing new. These attacks come from many countries and are getting smarter and smarter as time passes. I'd like to reach out to the community and ask for advice, suggestions and feedback on what you think the best way to prevent/minimize these attacks is.
They are attacking our registration page and occasionally bypassing all layers of security and registering, then posting spam. With a really smart botnet, there could potentially be a lot of spam posted overnight before an admin can get to remove them. Any suggestions on prevention/cure/minimization?
Is anybody dead against using captcha?
They are attacking our registration page and occasionally bypassing all layers of security and registering, then posting spam. With a really smart botnet, there could potentially be a lot of spam posted overnight before an admin can get to remove them. Any suggestions on prevention/cure/minimization?
Is anybody dead against using captcha?
How do i become super user?
Wear your underpants on the outside and put on a cape.
Wear your underpants on the outside and put on a cape.
- francois
- Contributor
- Posts: 6302
- Joined: 28 Dec 2010, 14:25
- Distribution: xfce plank porteus nemesis
- Location: Le printemps, le printemps, le printemps... ... l'hiver s'essoufle.
Re: Spam botnets
I am still alive using captcha. I have survived. This might be a good method for registration of real users. : 8)
Prendre son temps, profiter de celui qui passe.
-
- Contributor
- Posts: 166
- Joined: 08 Jul 2012, 02:30
- Distribution: Porteus v3.0 LXDE i486
- Location: South Central PA, USA
Re: Spam botnets
I'm not opposed to using captcha.
Sean
Sean
Re: Spam botnets
captcha does not prevent intrusion, the spammers for this purpose have a script in php, but if use logical captcha type
"3+6=?" or "or how are is day today ?" is better method.
regards
"3+6=?" or "or how are is day today ?" is better method.
regards
Re: Spam botnets
Please note that the attacks was at a level where the nullroute (drop requests) of whole countries was necessary to stop them. Fortunately, all countries are now able to access porteus.org without restrictions.
Here is a short list of countries used to bounce the attacks:
Here is a short list of countries used to bounce the attacks:
- China
- Ukraine
- United States
- Poland
- France
- Spain
- Canada

NjVFQzY2Rg==
Re: Spam botnets
My proposal add logical captcha in a login area, this method is the best in my opinion.
- francois
- Contributor
- Posts: 6302
- Joined: 28 Dec 2010, 14:25
- Distribution: xfce plank porteus nemesis
- Location: Le printemps, le printemps, le printemps... ... l'hiver s'essoufle.
Re: Spam botnets
The proposition of crashman seems to be the good one. I think that Tomas uses that procedure. There was a lot of spam on the slax site.
Prendre son temps, profiter de celui qui passe.
- brokenman
- Site Admin
- Posts: 6104
- Joined: 27 Dec 2010, 03:50
- Distribution: Porteus v4 all desktops
- Location: Brazil
- Contact:
Re: Spam botnets
I should mention that the present system cross checks IP's signing up against a database of known bots and abusers. If they are on this list they are presented with another layer of security captcha. If not then no captcha is shown. Bots are getting smarter and are now able to bypass or answer many simple captcha techniques.
Personally I'd hate to see the day when the user bears the work of having to prove themselves to be human by answering questions, scanning an eyeball and then dancing the macarena. I've seen captchas that make the user complete a jigsaw puzzle before being able to post a request. I think security should a users experience without hindering it. Having said that i vote for (the expected) captcha for ALL users, with no discrimination. Bot or human, everybody must answer a question. Thoughts?
Personally I'd hate to see the day when the user bears the work of having to prove themselves to be human by answering questions, scanning an eyeball and then dancing the macarena. I've seen captchas that make the user complete a jigsaw puzzle before being able to post a request. I think security should a users experience without hindering it. Having said that i vote for (the expected) captcha for ALL users, with no discrimination. Bot or human, everybody must answer a question. Thoughts?
How do i become super user?
Wear your underpants on the outside and put on a cape.
Wear your underpants on the outside and put on a cape.
- Ahau
- King of Docs
- Posts: 1331
- Joined: 28 Dec 2010, 15:18
- Distribution: LXDE & Xfce 32/64-bit
- Location: USA
Re: Spam botnets
I vote for the Electric Slide rather than the Macarena. There's nothing resembling a latin beat in these hips, I'm afraid.
Please take a look at our online documentation, here. Suggestions are welcome!
- Tonio
- Contributor
- Posts: 276
- Joined: 28 Dec 2010, 16:37
- Distribution: Slackware,porteus,FreeBSD,Slax
- Location: 127.0.0.1
Re: Spam botnets
A captcha may be good, but the spam bots have figured things out?
Some transcendental numbers, i.e, pi, e and the euler macheroni constant or the Golden Ratio to a certain decimal place? at random. So having combinations that are hard for the spambots to defeat is what is needed in my opinion, but random numbers are not so random after a while
Computer algorithms defeat the purpose. Maybe spam removal by regular users to help out? if the spam bots hit the site.
Anyone else propose something else?
Some transcendental numbers, i.e, pi, e and the euler macheroni constant or the Golden Ratio to a certain decimal place? at random. So having combinations that are hard for the spambots to defeat is what is needed in my opinion, but random numbers are not so random after a while

Anyone else propose something else?
- brokenman
- Site Admin
- Posts: 6104
- Joined: 27 Dec 2010, 03:50
- Distribution: Porteus v4 all desktops
- Location: Brazil
- Contact:
Re: Spam botnets
Not such a good idea. Did this once at a party with no authentication at the door ... the house got trashed.open all doors
How do i become super user?
Wear your underpants on the outside and put on a cape.
Wear your underpants on the outside and put on a cape.
- Blaze
- DEV Team
- Posts: 3654
- Joined: 28 Dec 2010, 11:31
- Distribution: ⟰ Porteus current ☯ all DEs ☯
- Location: ☭ Russian Federation, Lipetsk region, Dankov
- Contact:
Re: Spam botnets
Try to block spam bot via IP on phpbb3
Linux 5.15.11-porteus #1 SMP Sat Dec 25 13:08:57 MSK 2021 x86_64 Intel(R) Core(TM) i5-6600K CPU @ up to 4.60GHz GenuineIntel GNU/Linux
MS-7A12 » [AMD/ATI] Navi 23 [Radeon RX 6600] [1002:73ff] (rev c7) » Vengeance LPX 16GB DDR4 K2 3200MHz C16
MS-7A12 » [AMD/ATI] Navi 23 [Radeon RX 6600] [1002:73ff] (rev c7) » Vengeance LPX 16GB DDR4 K2 3200MHz C16
Re: Spam botnets
Why wait until they reach phpBB? I'm looking to blocks them at Ethernet port directly 

NjVFQzY2Rg==