Closed
Bug 444826
Opened 17 years ago
Closed 16 years ago
spam found on labs forum
Categories
(Websites :: mozillalabs.com, defect)
Websites
mozillalabs.com
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: chofmann, Assigned: morgamic)
References
()
Details
Attachments
(2 files)
|
5.08 KB,
patch
|
Details | Diff | Splinter Review | |
|
11.93 KB,
text/plain
|
Details |
reported to webmaster@mozilla.com. we should get this cleaned off, and figure out captcha or bot protection mechanism. maybe something along the lines that morgamic is thinking about for addons.mozilla.org
You have a spam profile on your forum at
https://labs.mozilla.com/forum/index.php?action=profile;u=4105
We are receiving form spam (see below) linking to this page.
-----Original Message-----
From: Website [mailto:safetyp1@box230.bluehost.com]
Sent: Thursday, July 10, 2008 6:29 PM
To: info@safetypartnersinc.com
Subject: Information Request
The following information request has been submitted from the website.
From: Mr. Devidr Devidr
Hello
Home
Address: devid574@gmail.com
devid574@gmail.com
mexico, NY 856414
Phone: 13 255 645 135
Fax: 13 255 645 135
E-mail: devid574@gmail.com
INQUIRY:
Hi! Nice place. My sites:
fake coach purses
discount kitchen cabinets
http://fakecoachpurses.blogs.experienceproject.com/49186.html
https://labs.mozilla.com/forum/index.php?action=profile;u=4105
[url=http://fakecoachpurses.blogs.experienceproject.com/49186.html]fake
coach purses[/url]
[url=https://labs.mozilla.com/forum/index.php?action=profile;u=4105]discount
kitchen cabinets[/url]
==================== END ====================
Updated•17 years ago
|
Component: Other → labs.mozilla.com
QA Contact: other → labs-mozilla-com
Comment 1•17 years ago
|
||
I have removed this user's account, and cbeard has tightened up the account registration process to make it a bit harder to get an account. We'll want to go through existing accounts and delete other spammers' accounts, though. There appear to be quite a lot of them. Leaving this bug open pending that.
Comment 2•17 years ago
|
||
Alex, this is a serious problem. With the new Vanilla forums, the tag cloud on the left is overrun with spam tags!
Severity: normal → major
OS: Mac OS X → All
Hardware: PC → All
Comment 3•17 years ago
|
||
I'm adding a reCaptcha to the register form.
If tags aren't important to you, then the simplest solution to a couple problems would be to disable the Discussion Tags extension. (problem 1: recent tags block is clutter, 2: site-wide spam entry in tags)
If tags are important than we can hack out the recent tags block (problem 1) and run a query to delete spam tags, since there is not way to delete them from UI yet.
Comment 4•17 years ago
|
||
recaptcha added in r18580
tagged for prod in r18582
bug filed for push to production
I also decided to turn off discussion tags, cause they're being a pain.
there is an extension to verify membership application by email, but it's in
beta and won't work without modifying the theme.
http://lussumo.com/addons/index.php?PostBackAction=AddOn&AddOnID=135
If spam problems continue, we can look into more options.
Anything I can do to clear out spam? e.g. run a delete query on the DB?
Comment 5•17 years ago
|
||
recaptcha is live
Comment 6•17 years ago
|
||
There are currently 200+ spam posts per day in the forum, can anybody care about this, please?
| Assignee | ||
Comment 7•17 years ago
|
||
Looks like someone turned down throttling to 3 posts a minute, 5 discussions a minute. Now we have 2000+ spam messages and the forum needs to be taken offline and the DB needs to be scrubbed.
Short-term we can add reCAPTCHA to discussion creation and comment forms. I'll post a patch for that shortly.
Long-term we can re-evaluate forum options if it continues to be a problem.
| Assignee | ||
Comment 8•17 years ago
|
||
| Assignee | ||
Comment 9•17 years ago
|
||
FYI - I'm having the forum temporarily disabled until Monday afternoon. Before the 503 is removed:
* db will be sanitized and cleared of spam
* patch adding reCAPTCHA to discussion and comment forms will be checked in and deployed
| Assignee | ||
Updated•17 years ago
|
Attachment #349712 -
Flags: review?(buchanae)
Comment 10•17 years ago
|
||
The other change that would really help is a super-simple two-click process for deleting an account along with all of its posts and banning the IP address from which the account was registered.
For example, when an administrator is logged in, there could be an delete button next to the names of posters that brought the admin to a page listing all their posts and requesting confirmation of the delete account/delete posts/ban IP address.
| Assignee | ||
Comment 11•17 years ago
|
||
Yeah, that's essentially what we will have to do manually. I'll see if I can improve this add-on: http://lussumo.com/addons/index.php?PostBackAction=AddOn&AddOnID=65
That'll be two extensions we've improved... I'll make sure the changes get submitted upstream.
| Assignee | ||
Comment 12•17 years ago
|
||
There's also some discussion about this:
http://lussumo.com/community/discussion/5238/want-to-be-able-to-delete-users/#Comment_65566
If I can find an extension that deletes user content, I can make the delete user extension stupider and less dangerous.
| Assignee | ||
Updated•17 years ago
|
Assignee: nobody → morgamic
| Assignee | ||
Comment 13•17 years ago
|
||
| Assignee | ||
Comment 14•17 years ago
|
||
Comment on attachment 349712 [details] [diff] [review]
v1, adds recaptcha to spammer points of entry
I'm going to check this in. Would like to get this taken care of today.
Attachment #349712 -
Flags: review?(buchanae)
| Assignee | ||
Comment 15•17 years ago
|
||
Comment 16•16 years ago
|
||
Resolving fixed, but captchas for logged-in users is suboptimal.
Status: NEW → RESOLVED
Closed: 16 years ago
Resolution: --- → FIXED
You need to log in
before you can comment on or make changes to this bug.
Description
•