Hi all,
To date the forum has seen 126 spammers who had managed to slip through the cracks of the Anti-Spam features and had successfully registered. When they were found to be spammers, they were banned from the forum and will not be able to register again (the forum software allows for their usernames, IP addresses and email addresses to be recorded to prevent them from returning). Then the module that links to the Stop Forum Spam database and the Akismet database was installed, and this has also helped to block registration attempts by spammers recorded in both these databases.
Adding to the measures to prevent spammers from joining and to prevent hackers from destroying the forum, ZB Block has been installed to help protect the forum. ZB Block is a PHP application that prevents hackers from exploiting the vulnerabilities of a PHP based forum application (like phpBB3 and many PHP based forums), by preventing code injection attempts, recursive directory traversal attempts and also links to Stop Forum Spam to prevent spammer registration. With ZB Block installed, the forum has been protected from 461 attempts ranging from registration spoofing to downright attacks on the forum, resulting in the attacker being banned from access to the forum. If an attacker returns after the 3rd attempt, he/she is faced with an error message that says the service is unavailable. Here is an example of a spammer who didn't even make it to the front door to register:-
Code: Select all
#: 446 @: Wed, 03 Jul 2013 08:16:46 +0200 Running: 0.4.10a3 / 74a
Host: 91.236.74.173
IP: 91.236.74.173
Score: 1
Violation count: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on Stop Forum Spam (http://www.stopforumspam.com/removal) (local block).
Query: mode=register&sid=77600163d251e1dc2ba99301e216f19d
Referer: http://www.gps-users-forum.co.za/ucp.php?mode=register&sid=77600163d251e1dc2ba99301e216f19d
User Agent: Mozilla/5.0 (Windows NT 5.1; rv:15.0) Gecko/20100101 Firefox/15.0.1
Reconstructed URL: http:// www.gps-users-forum.co.za /ucp.php?mode=register&sid=77600163d251e1dc2ba99301e216f19d
The firewall has recently also undergone some serious scrutiny and now has Snort installed. Snort does intrusion detection/prevention on the internet side of the firewall. Snort watches for attacks against the firewall, web server and the network here as a whole. Anything outside of accessing the forum will raise alerts that are logged to a database. Just like an antivirus program, there are updates to the rules which Snort works with and these are updated daily.
Hope this helps
Darryl