Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 09-29-2014, 12:33 PM   #1
SykkBoy
Jesus loves bacon
 
SykkBoy's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: Sin City, Motherfucker
Posts: 19,969
Detecting XRumer

Our dating site has been getting hit pretty hard with profiles created by XRumer. I wouldn't care so much if they weren't so shitty ;-)

Is there a way to detect XRumer? I'd like to be able to autoblock as soon as we start seeing the profiles come in.
SykkBoy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 12:47 PM   #2
Ferus
Bye - Left to do stuff
 
Industry Role:
Join Date: Feb 2013
Posts: 4,109
Like most will say
Quote:
Take the time to create 15-20 Q/A and change them when the flood starts again.
No point in investing $XXXX, in a golden solution sold by security-pushers
Ferus is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 12:57 PM   #3
SykkBoy
Jesus loves bacon
 
SykkBoy's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: Sin City, Motherfucker
Posts: 19,969
It looks like that's the way we'll be going, I was just hoping someone might have a decent blocking solution or detection solution so we can write our own blocker.
SykkBoy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 01:25 PM   #4
klinton
So Fucking Banned
 
Industry Role:
Join Date: Apr 2003
Location: online
Posts: 8,766
check out stopforumspam.org for latest XR IPs and used emails...

as someone above posted, the only efficient and smart way is to post a some specific questions and answers...and change/ modify them from time to time
klinton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 03:27 PM   #5
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Ferus suggestion sound quite fine to me,questions which can be answered by human only usually do the trick
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 03:53 PM   #6
RazorSharpe
Confirmed User
 
RazorSharpe's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Scotland
Posts: 2,238
Quote:
Originally Posted by SykkBoy View Post
Our dating site has been getting hit pretty hard with profiles created by XRumer. I wouldn't care so much if they weren't so shitty ;-)

Is there a way to detect XRumer? I'd like to be able to autoblock as soon as we start seeing the profiles come in.
The solution we use (not a dating site):

We create a hidden field named "email" and we generate the field name for the real email address on-the-fly. Most automated softwares will fill in the hidden field and won't know how to handle the real email field. The beauty of changing the field name per page load makes sure people can't just manually update their software. We use a combination of hash and time stamp. Works well for us ...
__________________
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning.
RazorSharpe is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 04:21 PM   #7
sarettah
see you later, I'm gone
 
Industry Role:
Join Date: Oct 2002
Posts: 14,057
Quote:
Originally Posted by RazorSharpe View Post
The solution we use (not a dating site):

We create a hidden field named "email" and we generate the field name for the real email address on-the-fly. Most automated softwares will fill in the hidden field and won't know how to handle the real email field. The beauty of changing the field name per page load makes sure people can't just manually update their software. We use a combination of hash and time stamp. Works well for us ...
That is quite a nice solution. Simple. Wish I had thought of that


.
__________________
All cookies cleared!
sarettah is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 04:27 PM   #8
_Richard_
Too lazy to set a custom title
 
_Richard_'s Avatar
 
Industry Role:
Join Date: Oct 2006
Location: Vancouver
Posts: 30,986
Quote:
Originally Posted by RazorSharpe View Post
The solution we use (not a dating site):

We create a hidden field named "email" and we generate the field name for the real email address on-the-fly. Most automated softwares will fill in the hidden field and won't know how to handle the real email field. The beauty of changing the field name per page load makes sure people can't just manually update their software. We use a combination of hash and time stamp. Works well for us ...
_Richard_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 05:45 PM   #9
HerPimp
Confirmed User
 
HerPimp's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Earth
Posts: 1,197
Captcha does not work, for a penny people will type it out. Only use Q/A and get creative.
__________________
HerPimp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 07:17 PM   #10
AmeliaG
Too lazy to set a custom title
 
AmeliaG's Avatar
 
Join Date: Jan 2003
Location: Los Angeles
Posts: 10,526
Quote:
Originally Posted by RazorSharpe View Post
The solution we use (not a dating site):

We create a hidden field named "email" and we generate the field name for the real email address on-the-fly. Most automated softwares will fill in the hidden field and won't know how to handle the real email field. The beauty of changing the field name per page load makes sure people can't just manually update their software. We use a combination of hash and time stamp. Works well for us ...
Ooh, that is a nice elegant solution!
__________________
GFY Hall of Famer

AltStar Hall of Famer




Blue Blood's SpookyCash.com

Babe photography portfolio
AmeliaG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 07:26 PM   #11
SDSimon
Confirmed User
 
Join Date: Aug 2002
Location: Calif. USA
Posts: 140
Quote:
Originally Posted by SykkBoy View Post
Our dating site has been getting hit pretty hard with profiles created by XRumer. I wouldn't care so much if they weren't so shitty ;-)

Is there a way to detect XRumer? I'd like to be able to autoblock as soon as we start seeing the profiles come in.
Hi SykkBoy.
Would HTaccess work here?

>>>Winners WIN because they NEVER GIVE UP!<<<
SDSimon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 07:26 PM   #12
freecartoonporn
Confirmed User
 
freecartoonporn's Avatar
 
Industry Role:
Join Date: Jan 2012
Location: NC
Posts: 7,683
Quote:
Originally Posted by RazorSharpe View Post
The solution we use (not a dating site):

We create a hidden field named "email" and we generate the field name for the real email address on-the-fly. Most automated softwares will fill in the hidden field and won't know how to handle the real email field. The beauty of changing the field name per page load makes sure people can't just manually update their software. We use a combination of hash and time stamp. Works well for us ...
this

we used to do hidden field technique but very simple way.
create a hidden field name it email and check serverside.
if filled then its bot else human.

but yours looks pretty interesting., theres one downside i can think of , is that , people have to retype email at every visit.

another way use javascript to hide field

Last edited by freecartoonporn; 09-29-2014 at 07:27 PM..
freecartoonporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-29-2014, 11:50 PM   #13
RazorSharpe
Confirmed User
 
RazorSharpe's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Scotland
Posts: 2,238
Quote:
Originally Posted by freecartoonporn View Post
this

we used to do hidden field technique but very simple way.
create a hidden field name it email and check serverside.
if filled then its bot else human.

but yours looks pretty interesting., theres one downside i can think of , is that , people have to retype email at every visit.

another way use javascript to hide field
Well considering that this is a registration form, the user should essentially only be filling this form in once so "every visit" shouldn't really be an issue.
__________________
Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning.
RazorSharpe is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2014, 12:17 AM   #14
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,381

Quote:
Originally Posted by RazorSharpe View Post
We create a hidden field named "email" and we generate the field name for the real email address on-the-fly.
Yep. I'm using the similar method on my sites since 2003. BTW, another good solution is to encrypt your signup form with JavaScript. It will stop 99% of spamboats that automatically searching for forms at your webpages.
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2014, 12:28 AM   #15
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,381
Also you can generate a special token (using the visitor's IP for example) and set it as a cookie when your registration form was visited. Then just check it when the form will be submitted. I was using this method long time ago to protect against so-called referrer spoofing. AFAIK this method is still being used by many high-trafficking websites like Pinterest.

Edit: Course ANY protection can be compromised but not by XRumer or regular spambots. The one will need to create a special software to bypass your protection. For example, this my WP plugin allows to automatically pin the post images to various pinboards including pinterest.com, sex.com and many others: http://www.cyberseo.net/xpinner/

__________________
Obey the Cowgod

Last edited by just a punk; 09-30-2014 at 12:37 AM..
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2014, 12:33 AM   #16
freecartoonporn
Confirmed User
 
freecartoonporn's Avatar
 
Industry Role:
Join Date: Jan 2012
Location: NC
Posts: 7,683
Quote:
Originally Posted by CyberSEO View Post
Yep. I'm using the similar method on my sites since 2003. BTW, another good solution is to encrypt your signup form with JavaScript. It will stop 99% of spamboats that automatically searching for forms at your webpages.
wont this stop ppl from joining if their javascript is disabled ?
freecartoonporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2014, 12:36 AM   #17
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,381
Quote:
Originally Posted by freecartoonporn View Post
wont this stop ppl from joining if their javascript is disabled ?
Almost all sites now require JavaScript, so I don't see a problem with that. Even this board won't work as it should w/o JavaScript. Not even mention all these new responsive sites.
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2014, 02:09 PM   #18
SykkBoy
Jesus loves bacon
 
SykkBoy's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: Sin City, Motherfucker
Posts: 19,969
Quote:
Originally Posted by RazorSharpe View Post
The solution we use (not a dating site):

We create a hidden field named "email" and we generate the field name for the real email address on-the-fly. Most automated softwares will fill in the hidden field and won't know how to handle the real email field. The beauty of changing the field name per page load makes sure people can't just manually update their software. We use a combination of hash and time stamp. Works well for us ...
I like this, thanks

Also, going to test out the Q/A
captchas are pretty much useless and will just piss of actual users (although they're probably used to them by now)

we're also working with dynamic membera area/login pages.
SykkBoy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-30-2014, 02:13 PM   #19
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by SykkBoy View Post
I like this, thanks

Also, going to test out the Q/A
captchas are pretty much useless and will just piss of actual users (although they're probably used to them by now)

we're also working with dynamic membera area/login pages.
Yeah i get pissed every time when i see monstrosity known as re-captcha.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.