PDA

View Full Version : Forum fake user registrations



ErosOlmi
14-02-2024, 08:23
Recently there was an increase of fake user registration in thinBasic forum.
Every day 10 to 20 bots are able to register but not to activate the mail

This forum implements a protection system that verify if user name or user IP or user email being used to register are known as spammer or bot getting data from a remote database.
But it seems there are some intelligent bots that are able to register, activate the mail, and also make a post that seems very "human".
Usually in response to old forum thread or even make a new post with questions related to thinBasic language.

To try to reduce those events I've added a new dummy question during user registration and user profile change.
New dummy question asks new user to choose from a combo box one word from a list.
Any word is valid but it is not a text field easy to be filled but a combo box that should be a little more difficult to be selected from a bot.

Let's see it this will make any difference in next days.

Eros

ReneMiner
08-09-2024, 15:43
The Author of HLA and the Art of Assembly Language, Randall Hyde uses a very simple approach to reduce spambots that run through registration process without getting caught about 90%
I do not suggest to use all of his "bot-filters" but maybe there are some interesting ideas that could be adapted
https://randallhyde.com/Forum/viewtopic.php?t=2

ErosOlmi
09-09-2024, 16:01
Ciao Renč,

thanks for the suggestion.
A little bit "drastic" and too manually managed dur to manual verification.
I need something almost 100% automatic.

At the moment the problem is quite under control for what I can see.
Fake user registration is quite high every day but our anti-spam system is able to keep this forum a safe place.

Attached a screen shot of the log of registrations blocked by our system just for the last few hours.
Registration are blocked by IP, email, registration name ... if one of these is inside bad guys DB registration will be blocked.

What is really creating more problems not are AI crawlers from big companies come here to scan and stole info for their AI systems.
I had to block many IPs coming from Apple and other big tech otherwise web site and forum were blocked for too high traffic

Will see