Major spam
Moderator: John Smith
- Andrew MacLean
- Moderator
- Posts: 7703
- Joined: Thu 15 Jan 2004 8:01 pm
- Keratoconus: Yes, I have KC
- Vision: Other
- Location: Scotland
- John Smith
- Moderator
- Posts: 1941
- Joined: Thu 08 Jan 2004 12:48 am
- Keratoconus: Yes, I have KC
- Vision: Graft(s) and spectacles
- Location: Sidcup, Kent
Oh well, it's come to this.
Doing some analysis of where the spam comes from, there is an incredibly high correlation.
Almost all of the spam comes from outside Europe. Almost all the spam comes from countries where English is not widely spoken.
The sheer volume of "attacks" on the web server has grown to unacceptible levels. Something has got to be done, or the Group will be facing large bills for excess bandwidth usage. Drastic action is called for.
Drastic action: at a web-server level, deny access to those countries where most of the attacks and spam originate. This of course will mean that any legitimate visitor from the affected countries will also lose their access.
But something just HAD to be done.
So we can bid farewell to the Ukraine, Russia, Peru and China. Although kudos to the chinese who managed to get out of their country in the first place!
Doing some analysis of where the spam comes from, there is an incredibly high correlation.
Almost all of the spam comes from outside Europe. Almost all the spam comes from countries where English is not widely spoken.
The sheer volume of "attacks" on the web server has grown to unacceptible levels. Something has got to be done, or the Group will be facing large bills for excess bandwidth usage. Drastic action is called for.
Drastic action: at a web-server level, deny access to those countries where most of the attacks and spam originate. This of course will mean that any legitimate visitor from the affected countries will also lose their access.
But something just HAD to be done.
So we can bid farewell to the Ukraine, Russia, Peru and China. Although kudos to the chinese who managed to get out of their country in the first place!
John
- Paul Osborne
- Chatterbox
- Posts: 254
- Joined: Tue 11 Oct 2005 9:54 am
- Keratoconus: Yes, I have KC
- Vision: Graft(s) and spectacles
- Location: Canterbury, Kent
John,
If you do decide to investigate the authentication route again, there are certainly other plugins available for say WordPress (so again php so code porting should be minimal effort) that instead of doing the unreadable letters ask the user to input the sum of two small numbers which are randomly generated (ie add 6 + 7).
I can send you details if you like.
Regards
Paul
If you do decide to investigate the authentication route again, there are certainly other plugins available for say WordPress (so again php so code porting should be minimal effort) that instead of doing the unreadable letters ask the user to input the sum of two small numbers which are randomly generated (ie add 6 + 7).
I can send you details if you like.
Regards
Paul
- John Smith
- Moderator
- Posts: 1941
- Joined: Thu 08 Jan 2004 12:48 am
- Keratoconus: Yes, I have KC
- Vision: Graft(s) and spectacles
- Location: Sidcup, Kent
Thanks Paul, that does sound interesting...
The blocking by source country for those wayward parts of the world seems to be working quite well already. I only deleted 1 spam user today, and I've not been running the system a week yet!
I've also found a phpbb mod that won't accept registrations from IP addresses that are in DNSBL-type blacklists. That sounds good too.
The blocking by source country for those wayward parts of the world seems to be working quite well already. I only deleted 1 spam user today, and I've not been running the system a week yet!
I've also found a phpbb mod that won't accept registrations from IP addresses that are in DNSBL-type blacklists. That sounds good too.
John
- Alison Fisher
- Forum Stalwart
- Posts: 334
- Joined: Sat 18 Mar 2006 12:56 pm
- Keratoconus: Yes, I have KC
- Vision: Graft(s) and spectacles
- Location: Leicester
Hi John
I was telling my friends about your efforts to curb spammers and they would like to know how you block entire countries like that. Is it easy to do?
I like the sound of the IP banning thing too. Can you point me in the right direction on how to do that as well?
TIA, Ali

I was telling my friends about your efforts to curb spammers and they would like to know how you block entire countries like that. Is it easy to do?
I like the sound of the IP banning thing too. Can you point me in the right direction on how to do that as well?
TIA, Ali

grafts in 1992 and 1996
- John Smith
- Moderator
- Posts: 1941
- Joined: Thu 08 Jan 2004 12:48 am
- Keratoconus: Yes, I have KC
- Vision: Graft(s) and spectacles
- Location: Sidcup, Kent
Hi Alison,
This is what I've placed in my "httpd.conf" for the KC group virtual server...
As you can see, it's easy to block a particular range of IP addresses (you can get the range/netmask from a WHOIS lookup on the IP address), or a single country. Note that the ".ar" etc bits rely on reverse-DNS being setup. That's why I'm looking into the DNSBL mod. One such mod is at http://web-professor.net/wp/category/misc/phpbb/, but I've not installed any of these yet.
This is what I've placed in my "httpd.conf" for the KC group virtual server...
Code: Select all
<location />
Deny from 195.225.176.0/255.255.251.0
Deny from 195.225.176.0/24
Deny from 218.98.32.0/18
Deny from .ar .br .co .kr .ua
Deny from .sa
Deny from .cn
Deny from .pe .ru .sk .th
# Oh dear, it's in spain, just block the single ISP...
Deny from .rima-tde.net
</location>
As you can see, it's easy to block a particular range of IP addresses (you can get the range/netmask from a WHOIS lookup on the IP address), or a single country. Note that the ".ar" etc bits rely on reverse-DNS being setup. That's why I'm looking into the DNSBL mod. One such mod is at http://web-professor.net/wp/category/misc/phpbb/, but I've not installed any of these yet.
John
- Alison Fisher
- Forum Stalwart
- Posts: 334
- Joined: Sat 18 Mar 2006 12:56 pm
- Keratoconus: Yes, I have KC
- Vision: Graft(s) and spectacles
- Location: Leicester
- Paul Osborne
- Chatterbox
- Posts: 254
- Joined: Tue 11 Oct 2005 9:54 am
- Keratoconus: Yes, I have KC
- Vision: Graft(s) and spectacles
- Location: Canterbury, Kent
John Smith wrote:Thanks Paul, that does sound interesting...
OK here is the link for the maths test:
http://www.herod.net/dypm/
Paul
Who is online
Users browsing this forum: No registered users and 10 guests