It is currently Fri May 17, 2024 12:18 am


The forum is READ ONLY. Please direct any future discussions to our Facebook page


 Page 1 of 1 [ 1 post ] 
Author Message
 Post subject: Automatic Spam Ban
PostPosted: Tue May 22, 2007 1:57 am 
Developer
Developer
User avatar

Joined: Wed Feb 19, 2003 6:07 pm
Posts: 2930
We have added to the next release automatic IP banning for spammers who use the ADMIN contact button on the login page of the game.

The current 0.30.3 version of the game filters the spam so you never see it and notifies the admin via email that a spam contact was filtered and from what IP address. The problem is that some spammers use scripts so you end up seeing constant daily streams of spam filter notification emails. The people using these scripts never check to see that the site has issued a message saying the contact form was never delivered because it contained spam. So they keep hitting the site every day. I don't know what they think they can get out of it but they do it anyway.

The game currently has an IP BAN table where the admin can ban players by IP Address or Email address. I have modified the contact programs so they will use this IP BAN table. When a spam contact is detected the IP Address is stored in the table along with a count for how many times that IP Address has sent a spam contact form. Each time an IP Address sends a spam contact form the number is incremented by 1. When the count hits 3 the IP Address is permanently banned from sending any contact emails and the notification the spammer can see is changed to indicate the IP address has been banned from doing anything on the site. The admin will no longer be notified that the IP address has been filtered because of spam.

The filter checks for MIME injections of different types as well as too many URL's in the text. If any of the filter checks come back positive in the contact email address or text body the IP Address is added to the ban table. If the IP belongs to a player that IP is also banned from playing the game. This is why there is a "3 Strikes Your Out" rule. If a player has triggered the automatic ban by accident they can still contact the Admin of the game to get the issue resolved. It is pretty hard to trigger it by accident. :)

We have seen spammers start sending mass URLs through web site contact forms. It's kind of useless since they are usually only seen by one or two people. I guess they figure someone will eventually click on one of the URLs. Anyone that does is usually in for a big surprise if they are using IE. Many of the URLs automatically download and install all kinds of junk as the web site is loading. Most admins will probably never experience this problem but we thought it was better safe than sorry.

We are also changing the ADMIN graphic button on the login page to CONTACT. We found too many people thought that was a special login for admins only instead of a way to contact the admin of the game.



_________________
PJ's Annoyingly Useless Blog
ADOdb Lite
Template Lite
Offline
 Profile  
 
Display posts from previous:  Sort by  
 Page 1 of 1 [ 1 post ] 


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

cron