רק נרשמו והפיצו ספאם כ-38 חשבונות בוט והודעות בפרק זמן של 30 דקות

Hi, forum is idmforums.com

We have nipped it in the bud quickly, but the numbers were increasing so rapidly that we had to disable new user signups till we can figure out why it’s happening and prevent it. We are running 3.5.0.beta8-dev and about 2 weeks ago enabled OAuth from discord, but that is limited to our guild only. So, I don’t think it’s that as we would have seen the same bot accounts on the Discord server.

We are working on updating some of our post filtering for first time posters right now. Going to use these messages and their content to build up some “words and phrases” to use as auto flagging. Any ideas or tips to filter this type of thing from happening?

2 לייקים

Have you read Tips for Preventing Spam? Maybe the capcha plugin would help in your case?

2 לייקים

Thank you, yes we employ most of these tactics already. Not the captcha plug-in though.

Problem was that the bot accounts were coming from different IP addresses

2 לייקים

Have you checked if they coming from the same region? If so, you might be able to block at least some of them (assuming you don’t have regular users in that part of the world), either using the geo-blocking plugin or directly with something like geoip-shell.

3 לייקים

I’ll have a look, thanks!

לייק 1

It says that hcaptcha is bundled with discourse core. I don’t see it anywhere in our plugin list and I don’t see any git repo to add to the app.yml file. We are self hosted.

Any ideas?

2 לייקים

Try updating your forum, the plugin was included in core a few days ago.

2 לייקים

When did you last update your forum?

לייק 1

28th June. It’s not currently saying an update is available, I might have to do a rebuild.

2 לייקים

Did the rebuild, got the hCaptcha plugin. happy days. Thanks!

7 לייקים

is there a way to check IPs for signups of deleted accounts? The bots are back again even with the HCATPCHA puzzle. I deleted them all and blocked their IPs faster than I could think to get a list of their locations. (didn’t really have time to sit and collect 50 IPs). I have disabled new users registrations once more and am reluctant to open them up again.

לייק 1

Do you use https://meta.discourse.org/t/discourse-ai/259214#p-1260611-ai-spam-detector-5 ?

Stop Forum Spam Plugin is not official but it has been very, very efficient on my forum, including large attacks like the one you’re experiencing.

Also, if the bots post very similar messages, perhaps try to see some expressions or links they post that you can add to watched-words to automatically silence the users? I’ve never used this feature tho.

לייק 1

My biggest problem it’s about IPV6 just god knows how I needs to solve it