Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: Database: MS SQL Server
 SQL Injections?
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

stan9040
Starting Member

USA
2 Posts

Posted - 21 August 2010 :  17:12:54  Show Profile
I need a little help. I am using standard SQL and is working fine. The SQL is on same web server as the forums. I am getting spam which is being enter in directly to SQL and by passing Snitz forums. I have applied all the security patches from here.

Does anyone have any ideas on how to stop this?

Thanks in advance.

HuwR
Forum Admin

United Kingdom
20584 Posts

Posted - 21 August 2010 :  18:06:34  Show Profile  Visit HuwR's Homepage
How do you know it is not coming from the forum?
what version are you using?
Do you have any MODS installed?
Do you have access to your web or sql logs?

There are no known vulnerabilities in the current forum code, so if you could provide some more info we may be able to help.

MVC .net dev/test site | MVC .net running on Raspberry Pi
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 23 August 2010 :  07:13:02  Show Profile  Send ruirib a Yahoo! Message
If you are not using 3.4.07, the fix in the link below is a fix known to correct a situation that allowed spam to apparently be posted by a normal forum member:

http://forum.snitz.com/forum/topic.asp?TOPIC_ID=67497&whichpage=2#383240

Maybe it will help.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

stan9040
Starting Member

USA
2 Posts

Posted - 23 August 2010 :  12:50:24  Show Profile
Yes sir we are running 3.4.07 with all the patches. We are not running any mods.
We are running SQL 2005
http://www.peachtreeforums.com/forum/forum.asp?FORUM_ID=14

Here is the link and what we are getting.
Thanks I am more then happy to pay someone to fix this for me.

Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 23 August 2010 :  13:07:47  Show Profile  Send ruirib a Yahoo! Message
I don't understand why you say they are bypassing the Snitz forums. Looks like posts made by users who registered on the forum, so they are using the forum to post that.

I suggest a reading of this post: http://forum.snitz.com/forum/topic.asp?TOPIC_ID=65057

Some possible solutions are there. I would voice my preference for two of them:

1. Configure the forums for email validation and user pre-aproval - named restrict registration, both available from the Email server configuration page of snitz.

This option will allow you to approve a member before he is able to post. It's rather easy to use registration details to see if a user is a spammer or not and delete the applications of those that are not.

2. Use a mod like Gatekeeper mod, that forces users to answer a configurable question before they are allowed to register.

With this (either or both options), you will stop these spammers registering and your problem will be sorted.

Just FYI, we approve every member application here and have hardly had any spams issue, ever.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 23 August 2010 :  13:11:53  Show Profile  Send ruirib a Yahoo! Message
Just to add the likely you have a few users who posted immensely. You can zap them and delete all their posts when doing that, which should be a good way to get rid of all that garbage.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.12 seconds. Powered By: Snitz Forums 2000 Version 3.4.07