<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.webmaster-forums.net/crss/node/1029576" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title></title>
    <link>https://www.webmaster-forums.net/crss/node/1029576</link>
    <description></description>
    <language>en</language>
          <item>
    <title></title>
    <link>https://www.webmaster-forums.net/html-css-and-javascript/guestbook-spammers-bypassing-my-entry-forms#comment-1177891</link>
    <description> &lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;&lt;strong&gt;fifeclub wrote:&lt;/strong&gt; Then it ends off with &quot;If see this message email THIS url to [email=complaints2@land.ru]complaints2@land.ru[/email]&quot;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;  I&#039;ve seen enough spam to say I think this is just a poorly translated &quot;click here to remove&quot; message.&lt;/p&gt;
&lt;p&gt;    And did you try the suggestion in my last message I had posted about this topic?&lt;/p&gt;
&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;&lt;strong&gt;RangerLord wrote:&lt;/strong&gt; I can tolerate the situation, but what I would like to know is (1) Is this a security issue I should be concerned about? and (2) Is it possible to put a stop to this, or will I just be chasing IP&#039;s?&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt; First, welcome to the forums! Now as to your questions. The security issue well that would depend on the script you are using, if it has any security issues. Mainly it is just going to be an annoyance filling up your guestbook (why do you think there are so many &quot;Type the characters in the box below (that you need some good drugs to make look like letters)&quot; things in effect anymore.&lt;/p&gt;
&lt;p&gt; As to putting a stop to it, again the filtering would be based on your script and/or your own coding ability to do so. If you can don&#039;t filter by individual IP addresses, do a whole group of them that the one IP address belongs to. This really comes down to how much time you want to spend on it. &lt;/p&gt;
&lt;p&gt; The whole thing in general is just something you ahve to put up with when you offer a free place for people to post what ever they want. &lt;/p&gt;
&lt;p&gt;    -Greg&lt;/p&gt;
 </description>
     <pubDate>Wed, 31 Aug 2005 21:37:53 +0000</pubDate>
 <dc:creator>Greg K</dc:creator>
 <guid isPermaLink="false">comment 1177891 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/html-css-and-javascript/guestbook-spammers-bypassing-my-entry-forms#comment-1177884</link>
    <description> &lt;p&gt;Hi everyone... I&#039;m new on here, and this is my first post.  I&#039;ve been searching the web regarding a question I have about guestbooks and spammers, and that brought me here.  I&#039;m glad to be on board.&lt;/p&gt;
&lt;p&gt;After reading &lt;strong&gt;fifeclub&lt;/strong&gt;&#039;s posts (and dropping in on his site) I feel guilty posting my question &#039;cause I&#039;m not getting spammed, yet.  Here it is, though....&lt;/p&gt;
&lt;p&gt;I have a hobby site that&#039;s been up just short of two months.  Shortly after it opened, I installed a guestbook (phpBook 1.50).  Within days I got spammed, but only two messages.  Both had some BS text that had nothing to do with the gambling site they were promoting, and the log showed the hits coming from Slovenia and Israel.  The spam links were within the message text.  I deleted the two entries, and I haven&#039;t been spammed since.  But....&lt;/p&gt;
&lt;p&gt;I am seeing some odd behaviour in my site tracker.  After the spam entries, I would receive hits from Israel every few days, from 80.74.111.114.  The hits always came in pairs, a few minutes apart, and went straight to the guestbook.  Nothing was entered in the book, however.  After seeing this for a couple weeks, I decided to use phpBook&#039;s IP blocker and shut them out.  Five days later, the Israel/guestbook hits started again, this time from IP 212.29.214.240.  Still no spam.&lt;/p&gt;
&lt;p&gt;My apologies again to &lt;strong&gt;fifeclub&lt;/strong&gt; for complaining about something so insignificant compared to his problem.  This is a startup site, and traffic is low, and it just annoys me that almost 7% of the hits listed in my site tracker are from this Israel/guestbook IP.  I&#039;ve considered blocking this new IP, but I figure the problem will just migrate to a new one.&lt;/p&gt;
&lt;p&gt;I can tolerate the situation, but what I would like to know is (1) Is this a security issue  I should be concerned about? and (2) Is it possible to put a stop to this, or will I just be chasing IP&#039;s?&lt;/p&gt;
&lt;p&gt;Thanks!&lt;br /&gt;
R/L&lt;/p&gt;
 </description>
     <pubDate>Wed, 31 Aug 2005 19:42:50 +0000</pubDate>
 <dc:creator>RangerLord</dc:creator>
 <guid isPermaLink="false">comment 1177884 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/html-css-and-javascript/guestbook-spammers-bypassing-my-entry-forms#comment-1177720</link>
    <description> &lt;p&gt;It&#039;s not the database fields, it&#039;s the form input names that are the issue. What these bots do is rescrape the page source and retrieve the names.&lt;/p&gt;
&lt;p&gt;With a bit of programming you can generate random names for the inputs each time the page is opened, store the names &amp;amp; fields in a cookie\session variable and retrieve these on submission. This makes it absolutely impossible for auto-submitters to recover the names for future use because they will never be the same on two occasions.&lt;br /&gt;
For instance; You can use the session id and split that into say 8 char chunks for the names this will be unique for each visit.&lt;/p&gt;
&lt;p&gt;definitely don&#039;t reply&lt;/p&gt;
 </description>
     <pubDate>Mon, 29 Aug 2005 18:33:53 +0000</pubDate>
 <dc:creator>chrishirst</dc:creator>
 <guid isPermaLink="false">comment 1177720 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title>I&#039;m back!</title>
    <link>https://www.webmaster-forums.net/html-css-and-javascript/guestbook-spammers-bypassing-my-entry-forms#comment-1177711</link>
    <description> &lt;p&gt;I took the time to change all the fields of my mySQL database. It worked for over a month but they&#039;re starting to sneak back in again, even thought I customized all the database fields to non-standard names.&lt;/p&gt;
&lt;p&gt;I can&#039;t figure out if these new entries are automated or entered manually (automation should be much more difficult now) but the latest entry has an odd message that I wanted to ask about.  The website field is empty but the message field is full of spam links.  Then it ends off with &quot;If see this message email THIS url to &lt;a href=&quot;mailto:complaints2@land.ru&quot; class=&quot;bb-email&quot;&gt;complaints2@land.ru&lt;/a&gt;&quot;&lt;/p&gt;
&lt;p&gt;Is this a trick?  I assume that if I send an email to this address (from Russia once again) that I&#039;ll just be put on 10,000 more spamming lists.&lt;/p&gt;
 </description>
     <pubDate>Mon, 29 Aug 2005 16:58:00 +0000</pubDate>
 <dc:creator>fifeclub</dc:creator>
 <guid isPermaLink="false">comment 1177711 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/html-css-and-javascript/guestbook-spammers-bypassing-my-entry-forms#comment-1173099</link>
    <description> &lt;p&gt;You have to realize how this works.&lt;/p&gt;
&lt;p&gt; Normally you have a form on your site, that when submitted, sends the information to a script on your site that processes all of the information. (sometimes, it is the same file, usually not).&lt;/p&gt;
&lt;p&gt; Here is what is most likely happening. They call your script file, just as your form would. They have it programmed to send the same information your form sends in. (which is why changing the names of the form fields can make a difference). You script does realize that the information it is being sent is NOT coming from your form. &lt;/p&gt;
&lt;p&gt; If i remember right, your script is in PHP. If so, go in there where it saves the data to your database. Make a field in your database, and send to it the value of &lt;strong&gt;$_SERVER[&#039;HTTP_REFERER&#039;]&lt;/strong&gt;. This is the page that the person was at when they clicked to get to your script. Normally, this should be the URL of your form. &lt;/p&gt;
&lt;p&gt; Remember though, some people have this information blocked (either manually, or their antivirus software does it without them knowing). &lt;/p&gt;
&lt;p&gt; After a day, check these values, you will most likely notice all the spam ones are coming from &quot;-&quot; (or just an empty string) which indicates that it was directly called. Well you know your script should always be called from your form, so if the referer isn&#039;t your form, block the saving of information.&lt;/p&gt;
&lt;p&gt; Like I said, you may loose those whose refer is blocked, but that is a lot less  than how many you loose by shutting off the guestbook. Again, remember to leave a &quot;polite&quot; error message explaining why the information was not submitted. &quot;We&#039;re sorry, but we were unable to determine which page sent you here. Either you have your &#039;referer&#039; information disabled, or your antivirus software may have blocked this information.&quot;&lt;/p&gt;
&lt;p&gt; BTW, ever wonder why all these sites anymore have those weird text pictures and ask you to enter the text?? This is exactly why. Bots automatically making new accounts. &lt;/p&gt;
&lt;p&gt; -Greg&lt;/p&gt;
 </description>
     <pubDate>Wed, 15 Jun 2005 15:51:16 +0000</pubDate>
 <dc:creator>Greg K</dc:creator>
 <guid isPermaLink="false">comment 1173099 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/html-css-and-javascript/guestbook-spammers-bypassing-my-entry-forms#comment-1173092</link>
    <description> &lt;p&gt;Thanks everybody for the help.  &quot;IP Deny Manager&quot; may or may not have worked.  I woke up this morning to a new flood of guestbook spam and thought the Deny Manager didn&#039;t work because it wasn&#039;t using my webform anyway.  But after checking my database I can see that all the new spam is now from  	63.246.133.54  	unknown.sagonet.net.  So the bottom line is that it&#039;s pointless to try to ban them.  Crap!  I&#039;m about to notify my host provider and also try those links y&#039;all mentioned.  Thanks again.&lt;/p&gt;
&lt;p&gt;One follow up question:  If they aren&#039;t using my webform to submit info to my MySQL database, then how can they add information without knowing my username and password????&lt;/p&gt;
&lt;p&gt; &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/confused.png&quot; title=&quot;Confused&quot; alt=&quot;Confused&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
 </description>
     <pubDate>Wed, 15 Jun 2005 13:56:15 +0000</pubDate>
 <dc:creator>fifeclub</dc:creator>
 <guid isPermaLink="false">comment 1173092 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/html-css-and-javascript/guestbook-spammers-bypassing-my-entry-forms#comment-1173075</link>
    <description> &lt;p&gt;You can try installing this:&lt;br /&gt;
&lt;a href=&quot;http://www.plebian.com/news.php?artc=138&amp;amp;&quot; class=&quot;bb-url&quot;&gt;http://www.plebian.com/news.php?artc=138&amp;amp;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;it will stop bots cold&lt;/p&gt;
 </description>
     <pubDate>Wed, 15 Jun 2005 01:45:07 +0000</pubDate>
 <dc:creator>CptAwesome</dc:creator>
 <guid isPermaLink="false">comment 1173075 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/html-css-and-javascript/guestbook-spammers-bypassing-my-entry-forms#comment-1173069</link>
    <description> &lt;p&gt;Since recently, I get poker spam in comments on my blog. I&#039;d been expecting it for about a year, since my site was launched. I was starting to worry that I had none while everyone else was getting it -- I saw it as a measure of success, or the extent of publication, I guess. &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/tongue.png&quot; title=&quot;Sticking out tongue&quot; alt=&quot;Sticking out tongue&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Anyway, I was prepared for it when it came a few weeks back. I spent a couple of weeks manually handling the spam to wait and see if it was the real thing. When I was satisfied that it was, I simply installed Drupal&#039;s &lt;a href=&quot;http://drupal.org/project/spam&quot; class=&quot;bb-url&quot;&gt;Spam.module&lt;/a&gt;. Works like a charm. &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/smile.png&quot; title=&quot;Smiling&quot; alt=&quot;Smiling&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
 </description>
     <pubDate>Tue, 14 Jun 2005 23:47:56 +0000</pubDate>
 <dc:creator>Abhishek Reddy</dc:creator>
 <guid isPermaLink="false">comment 1173069 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/html-css-and-javascript/guestbook-spammers-bypassing-my-entry-forms#comment-1173066</link>
    <description> &lt;p&gt;8 more since I wrote this morning.  That&#039;s a lot since my guestbook only had about 50 in the past several years.  They&#039;re starting to repeat similar phrases and names.&lt;/p&gt;
&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;&lt;strong&gt;Greg K wrote:&lt;/strong&gt; Have you notified your provider? Does it seem to be all coming form same IP (or IP range)? Notify them, maybe they can put a block on it.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Do you mean my host?  No, I haven&#039;t told them yet.  My gb program records a bunch of other information  Every single of my recent spammers lists the following info:   69.31.86.244  	neg229.named1.com  &lt;/p&gt;
&lt;p&gt;I have cPanel, which has a bunch of features I&#039;ve never used.  One says &quot;IP Deny Manager&quot;.  It looks like it should do the trick but will it work if they aren&#039;t actually using the website to access my database?  (note: my logs do show Mozilla 4.0 as a user agent).  I&#039;ll enter that IP in there and see what happens over the next 24 hours or so.&lt;/p&gt;
&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;&lt;strong&gt;Greg K wrote:&lt;/strong&gt; Did you try the requiring the referrer to match your site?&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;I wouldn&#039;t have a clue how to do that.  Me is simple man.&lt;/p&gt;
 </description>
     <pubDate>Tue, 14 Jun 2005 21:52:45 +0000</pubDate>
 <dc:creator>fifeclub</dc:creator>
 <guid isPermaLink="false">comment 1173066 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/html-css-and-javascript/guestbook-spammers-bypassing-my-entry-forms#comment-1173064</link>
    <description> &lt;p&gt;Have you notified your provider? Does it seem to be all coming form same IP (or IP range)? Notify them, maybe they can put a block on it.&lt;/p&gt;
&lt;p&gt;Did you try the requiring the referrer to match your site?&lt;/p&gt;
&lt;p&gt;-Greg&lt;/p&gt;
 </description>
     <pubDate>Tue, 14 Jun 2005 20:53:52 +0000</pubDate>
 <dc:creator>Greg K</dc:creator>
 <guid isPermaLink="false">comment 1173064 at https://www.webmaster-forums.net</guid>
  </item>
  </channel>
</rss>
