Forum protection against spammer

Use this forum to discuss possible implementation of a new feature before opening a ticket.
A developer shall edit the topic title with "[xxx]" where xxx is the id of the accompanying tracker id.
Duplicate posts about the same id. +1 posts are not allowed.

Moderators: leecollings, remb0

Post Reply
User avatar
emme
Posts: 909
Joined: Monday 27 June 2016 11:02
Target OS: Raspberry Pi / ODroid
Domoticz version: latest
Location: Milano, Italy
Contact:

Forum protection against spammer

Post by emme »

The last one is hxw8groax who is spamming a lot the entire forum....

can we add a much more secure authentication against bots and spammer?

something like a CAPTCHA to the unknown users? (less than 100messages or manually flagged by admin as a certified user....)
this could help to avoid spammers and help the admis that would need to clean their mess :P

ciao
M
The most dangerous phrase in any language is:
"We always done this way"
febalci
Posts: 331
Joined: Monday 03 July 2017 19:58
Target OS: NAS (Synology & others)
Domoticz version:
Contact:

Re: Forum protection against spammer

Post by febalci »

I highly support this...
User avatar
EdwinK
Posts: 1820
Joined: Sunday 22 January 2017 21:46
Target OS: Raspberry Pi / ODroid
Domoticz version: BETA
Location: Rhoon
Contact:

Re: Forum protection against spammer

Post by EdwinK »

Did ask about this before, never heard anything about it. Tehre is a simple plugin for PHPbb forum software from stopforumspam.net, which is working great., but ist's for the admins to decide to use it. For now I'm jius reporting posts
Running latest BETA on a Pi-3 | Toon® Thermostat (rooted) | Hue | Tuya | IKEA tradfri | Dashticz V3 on Lenovo Huawei Tablet | Conbee
User avatar
remb0
Posts: 499
Joined: Thursday 11 July 2013 22:21
Target OS: Raspberry Pi / ODroid
Domoticz version: Beta
Location: The Netherlands
Contact:

Re: Forum protection against spammer

Post by remb0 »

thanks all! we will check it for sure.
ben53252642
Posts: 543
Joined: Saturday 02 July 2016 5:17
Target OS: Linux
Domoticz version: Beta
Contact:

Re: Forum protection against spammer

Post by ben53252642 »

Suggestion...

1) A pfSense firewall running Snort with the commercial rules (https://www.snort.org/products) needs to sit in front of the web server. This will stop a HUGE number of malicious IP's from ever reaching the forum and attempting to leave spam. This is probably the number one most effective thing that could be done. The admin will need to monitor the implementation and whitelist certain rules that cause problems as necessary.

2) Apache Mod_Security should be implemented with the OWASP Core Ruleset, again the admin will need to go through the logs and whitelist rules as needed.

I think the above two points should solve > 95% of the issues we are seeing with spam and significantly improve the forum and wiki's security, captcha's are not as effective as they used to be unfortunately.
Unless otherwise stated, all my code is released under GPL 3 license: https://www.gnu.org/licenses/gpl-3.0.en.html
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest