Acabei de ter cerca de 38 contas e posts de bots se inscrevendo e fazendo spam em 30 minutos

Hi, forum is idmforums.com

We have nipped it in the bud quickly, but the numbers were increasing so rapidly that we had to disable new user signups till we can figure out why it’s happening and prevent it. We are running 3.5.0.beta8-dev and about 2 weeks ago enabled OAuth from discord, but that is limited to our guild only. So, I don’t think it’s that as we would have seen the same bot accounts on the Discord server.

We are working on updating some of our post filtering for first time posters right now. Going to use these messages and their content to build up some “words and phrases” to use as auto flagging. Any ideas or tips to filter this type of thing from happening?

2 curtidas

Have you read Tips for Preventing Spam? Maybe the capcha plugin would help in your case?

2 curtidas

Thank you, yes we employ most of these tactics already. Not the captcha plug-in though.

Problem was that the bot accounts were coming from different IP addresses

2 curtidas

Have you checked if they coming from the same region? If so, you might be able to block at least some of them (assuming you don’t have regular users in that part of the world), either using the geo-blocking plugin or directly with something like geoip-shell.

3 curtidas

I’ll have a look, thanks!

1 curtida

It says that hcaptcha is bundled with discourse core. I don’t see it anywhere in our plugin list and I don’t see any git repo to add to the app.yml file. We are self hosted.

Any ideas?

2 curtidas

Try updating your forum, the plugin was included in core a few days ago.

2 curtidas

When did you last update your forum?

1 curtida

28th June. It’s not currently saying an update is available, I might have to do a rebuild.

2 curtidas

Did the rebuild, got the hCaptcha plugin. happy days. Thanks!

7 curtidas

is there a way to check IPs for signups of deleted accounts? The bots are back again even with the HCATPCHA puzzle. I deleted them all and blocked their IPs faster than I could think to get a list of their locations. (didn’t really have time to sit and collect 50 IPs). I have disabled new users registrations once more and am reluctant to open them up again.

1 curtida

Do you use https://meta.discourse.org/t/discourse-ai/259214#p-1260611-ai-spam-detector-5 ?

Stop Forum Spam Plugin is not official but it has been very, very efficient on my forum, including large attacks like the one you’re experiencing.

Also, if the bots post very similar messages, perhaps try to see some expressions or links they post that you can add to watched-words to automatically silence the users? I’ve never used this feature tho.

1 curtida

My biggest problem it’s about IPV6 just god knows how I needs to solve it