Anti-Spam Countermeasures
Posted: Thu Apr 23, 2020 12:23 pm
Overnight, we had the first spammer join the board and they posted 14 adverts in various forums on the board. That user and all the posts have now been deleted. If you saw those posts, sorry but they have now all been removed. If you received them via email, simply delete those emails.
I had not set the User Registration security too high, in order to make it easier for legitimate members to join, but now spammers have found the board, I have significantly raised the anti-spam countermeasures to join the forum.
Now all new members have to be approved by the admin (Soroush or me) and their posts are moderated at first. On registration, they now have to give a justification as to why they want to join the forum.
The Stop Forum Spam system checks username, IP and email address against the Stop Forum Spam Database https://www.stopforumspam.com/ and denies those that are listed there and obvious spammers are added to that database. Their IP-address (the computer address they use to connect to the forum, this is not their email address) is then banned for a certain period to prevent them trying to join again.
Finally, an invisible Google reCATCHA test checks if the user is legitimate.
These tests will not prevent existing members from signing in, just those trying to register as a new member.
I had not set the User Registration security too high, in order to make it easier for legitimate members to join, but now spammers have found the board, I have significantly raised the anti-spam countermeasures to join the forum.
Now all new members have to be approved by the admin (Soroush or me) and their posts are moderated at first. On registration, they now have to give a justification as to why they want to join the forum.
The Stop Forum Spam system checks username, IP and email address against the Stop Forum Spam Database https://www.stopforumspam.com/ and denies those that are listed there and obvious spammers are added to that database. Their IP-address (the computer address they use to connect to the forum, this is not their email address) is then banned for a certain period to prevent them trying to join again.
Finally, an invisible Google reCATCHA test checks if the user is legitimate.
These tests will not prevent existing members from signing in, just those trying to register as a new member.