Jury is still out... - Postet den (3664 Views)
Junior Member
gary b
Innlegg: 267
267
My forum has been getting hammered by 'registration bots' lately. For technical/logistical reasons, I cannot use captcha. I do use email validation, but there are probably a dozen or so "membership applications" (AKA 'registrations') per day. What's a guy to do???
I decided to try a novel (?) approach. I REVERSED the buttons on the policy page... you know, the ones that say 'Accept' and 'Cancel'. The first paragraph states that the Applicant *must* click the 'Cancel' button. Since my assumption is that bots don't read, I figured I would try this approach.
It is too soon to draw any conclusions, but ZERO bot registrations in past 24 hours! bigsmile I will keep you posted. Even if it works, it may be only a matter of time until my 'hook' is rendered useless... but I *am* enjoying no bogus 'applicants' for a while.
gary b
<
   
 Sidestørrelse 
Postet den
Snitz Forums Admin
ruirib
Innlegg: 26364
26364
That's an imaginative trick smile.

Have you tried forcing the registrants to fill in the birth date, using Shaggy's code?<
Postet den
Retired Support Moderator
MarcelG
Innlegg: 2625
2625
Eh...Gary, you do know that most real people also don't actually read buttons?
Perhaps it's better to rename the text on the button from 'Accept' to 'Yup, I agree', and from 'Cancel' to 'Heck no!'. tongue<
Postet den
Support Moderator
Shaggy
Innlegg: 6780
6780
Has the added bonus of ensuring peoples actually read the terms smile
<
Search is your friend “I was having a mildly paranoid day, mostly due to the
fact that the mad priest lady from over the river had
taken to nailing weasels to my front door again.”
Postet den
Junior Member
gary b
Innlegg: 267
267
cool
Another 18 hours and all is well!! No bot registrations as of yet! Whoopie!
And no... I did not try the birth date thingy. smile
<
Postet den
Advanced Member
JJenson
Innlegg: 2121
2121
We should start a pool on how long it takes for the bots to figure it out. bigsmile<
Postet den
Support Moderator
Podge
Innlegg: 3776
3776
In order to keep bots out all you really need is to require one unique thing at registration time. If they figure it out you just change it.<
Postet den
Junior Member
gary b
Innlegg: 267
267
That is an interesting point that I too wondered about. *IF* the activity (success/failure rate) of the bots is monitored, then it becomes more likely that bots will be modified to sidestep the change. But based on the 'automated' nature of the bots and the sheer volume of their actions, I'm betting my little piece of cyberspace will get lost in the numbers.
My goal was to concoct something that bypasses email validation if the test fails. So far, so good!!
And Podge... it took me less code (AKA 'pain') to change the button function than anything requiring User input. I'm still betting that this is not likely to be found... unless the bot writers read this topic! blackeye<
Postet den
Forum Moderator
AnonJr
Innlegg: 5768
5768
It must be monitored... three months after I added Shaggy's birthday code (and a few other things) to the church website I'm back to getting bogus registrations like before (and like you mentioned). While they're not getting through due to the e-mail validation, I'd still like to not have to worry about it any more.
I think the next step is going to be a random, hidden, mandatory field....<
Postet den
Junior Member
gary b
Innlegg: 267
267
Let's see if I can beat Shaggy's 90 day record...
48 hours -- no bots!
[^]<
Postet den
Average Member
Panhandler
Innlegg: 783
783

The GateKeeper mod has worked well since I installed about a month ago. Zero fake registrations so far. <
"5-in-1 Snitz Common Expansion Pack" - five popular mods packaged for easy install
". . .on a mote of dust, suspended in a sunbeam. . ."
HarborClassifieds Support Snitz Forums
Du må legge inn en melding