esotalk / esoTalk

Fat-free forum software.
GNU General Public License v2.0
1.47k stars 239 forks source link

ReCaptcha plugins don't work - bots still getting registered #464

Open phplego opened 7 years ago

phplego commented 7 years ago

Tons of spam everywhere on esoTalk forums. Even on http://esotalk.org/forum.

Is there any solution?

mroi commented 7 years ago

Do you happen to know whether this is an issue in the esoTalk core or in the ReCaptcha plugin? Because if this is a problem with the plugin, you should also file an issue there.

phplego commented 7 years ago

is an issue in the esoTalk core

Not sure about reCapture plugin. But I tried to wrote my own plugin which also use reCapture API plus I have added some extra difficulties for bots - with no luck - looks like they get registered not via join page :(. Maybe they know some vulnerability in the core - it is difficult to know for sure...

mroi commented 7 years ago

Possible. If you have access to a forum that shows these problems, maybe you could enable the web server’s access log to capture the URL flow of how the bots register? Or maybe @tobscure could to that for the esoTalk forum.

I could try looking into this if it’s not too involved, but I would need to know what to look for.

knownsyntax commented 7 years ago

Try to enable the following plugins, it will help remove or stop a vast majority of spam: Akismet Honeypot reCAPTCHA StopForumSpam