How do we stop spams like this?

I included a sample spam here. How do we stop this ? thanks


SPAM SPAM SPAM SPAM SPAM


SPAM SPAM SPAM SPAM SPAM



S

P

A

M


S

P

A

M


S

P

A

M


S

P

A

M



S

P

A

M


S

P

A

M


S

P

A

M


S

P

A

M

This thread is done..
and looks like nobody from Boonex cares.

Quote · 13 Mar 2010

Orca is notorious for having multiple, well documented exploits and other vulnerabilities, such as this. There's little that can be done beyond BoonEx getting their arses in gear and fixing the problems.

Also, I understand how annoying it is; now please just upload a screenshot.

BoonEx Certified Host: Zarconia.net - Fully Supported Shared and Dedicated for Dolphin
Quote · 13 Mar 2010

No screenshot.. it was a problem in my old site.. and i see that the spam works in here too.. kinda annoying because it is allowing full html code.. would have been better to only allow bb codes and text

Quote · 13 Mar 2010

MS,

did you not see the blue image with the crumpled up font.

screen shot was too large, so i am providing a link

Orca Injection Even on Boonex.com/Unity

Regards,

DosDawg

When a GIG is not enough --> Terabyte Dolphin Technical Support - Server Management and Support
Quote · 13 Mar 2010

MS,

did you not see the blue image with the crumpled up font.

screen shot was too large, so i am providing a link

Orca Injection Even on Boonex.com/Unity

Regards,

DosDawg

I did, which is why I asked for a screenshot. It also appears non-crumpled for me, though (screen size?).

BoonEx Certified Host: Zarconia.net - Fully Supported Shared and Dedicated for Dolphin
Quote · 13 Mar 2010

I edited the spam so it's more clear.

can this be parsed ?

I recon it's a preg_match fix ... prolly clean up the html tags like preg_replace('/<div(.*)>/', ' ', $textwhatever);

The UGLIEST part is that, this can be touched up nicely, and it will look like part of the site.. but is actually SPAM !

Quote · 13 Mar 2010

1024 x 768

so did the screenshot help? :)

Regards,

DosDawg

When a GIG is not enough --> Terabyte Dolphin Technical Support - Server Management and Support
Quote · 13 Mar 2010

1024 x 768

so did the screenshot help? :)

Regards,

DosDawg

Yes, now, can we get rid of the annoying example that blocks my view of the posts?

BoonEx Certified Host: Zarconia.net - Fully Supported Shared and Dedicated for Dolphin
Quote · 13 Mar 2010

1024 x 768

so did the screenshot help? :)

Regards,

DosDawg

Yes, now, can we get rid of the annoying example that blocks my view of the posts?

well, if I did.. it will kind of defeat the purpose of showing the example.

Just sroll down :)

Quote · 14 Mar 2010

I thinks it's EASIER to see now :)

Quote · 14 Mar 2010

I thinks it's EASIER to see now :)

If you like, I'll force-disable the viewing of this topic, all without any moderation powers.

That should give you an idea of the kind of vulnerabilities you can pull-off.

BoonEx Certified Host: Zarconia.net - Fully Supported Shared and Dedicated for Dolphin
Quote · 14 Mar 2010

The good thing is that it's not allowing <script and <iframe tags

Quote · 14 Mar 2010

I thinks it's EASIER to see now :)

If you like, I'll force-disable the viewing of this topic, all without any moderation powers.

That should give you an idea of the kind of vulnerabilities you can pull-off.

Exactly.. or make a div that covers the WHOLE page.. make it look like LEGITLY from Boonex.

Any ideas for the fix ?

Quote · 14 Mar 2010

HOLY CRAP!

Ok, this is a real nut buster for me. I am quickly becoming disenfranchised with the whole Boonex project. I am disabling my forum and going ahead with the phpbb3 integration I already own.

This is just nitwitology, plain and simple.

One more major Faux pas like this and I'm outa here......

http://towtalk.net ... Hosted by Zarconia.net!
Quote · 14 Mar 2010

 

 

 

I thinks it's EASIER to see now :)

If you like, I'll force-disable the viewing of this topic, all without any moderation powers.

 

That should give you an idea of the kind of vulnerabilities you can pull-off.

Exactly.. or make a div that covers the WHOLE page.. make it look like LEGITLY from Boonex.

 

Any ideas for the fix ?

 Yeah remove the html button from the tinymce editor.

https://dolphin-techs.com - Skype: Dolphin Techs
Quote · 14 Mar 2010

 

HOLY CRAP!

Ok, this is a real nut buster for me. I am quickly becoming disenfranchised with the whole Boonex project. I am disabling my forum and going ahead with the phpbb3 integration I already own.

This is just nitwitology, plain and simple.

One more major Faux pas like this and I'm outa here......

 Well.... here is one more for ya...  see ya later.   http://www.boonex.com/unity/forums/?action=goto&my_threads=1#topic/a-Custom-Form-values-on-same-line.htm

https://dolphin-techs.com - Skype: Dolphin Techs
Quote · 14 Mar 2010

You wouldn't be able to do this if Boonex had integrated htmlpurifier into Orca.  I have no idea why they didn't.  They must have felt that their own filter was good enough.  Evidently, it isn't.

Bring on the IPB integration!

My opinions expressed on this site, in no way represent those of Boonex or Boonex employees.
Quote · 14 Mar 2010

You wouldn't be able to do this if Boonex had integrated htmlpurifier into Orca.  I have no idea why they didn't.  They must have felt that their own filter was good enough.  Evidently, it isn't.

Bring on the IPB integration!

Didn't Andrew say they would integrate third-party forums like they did with Dolphin 6.1?

Then again, we were promised allot of things.

BoonEx Certified Host: Zarconia.net - Fully Supported Shared and Dedicated for Dolphin
Quote · 14 Mar 2010

 

You wouldn't be able to do this if Boonex had integrated htmlpurifier into Orca.  I have no idea why they didn't.  They must have felt that their own filter was good enough.  Evidently, it isn't.

Bring on the IPB integration!

 

I'm with you on that brother ...

http://towtalk.net ... Hosted by Zarconia.net!
Quote · 14 Mar 2010

I remember him saying something like that when I suggested using a real forum for THIS site.  I'm not sure he meant a D7 integration for distribution.  These guys at Boonex are stuck on Orca.  I kinda like the blue spam bars... I think I prefer red ones though.


My opinions expressed on this site, in no way represent those of Boonex or Boonex employees.
Quote · 14 Mar 2010

actually there are some places I would love to do this in my forum, can someone pm me the instructions?

Quote · 14 Mar 2010

now this makes me really feel like investing money into this project...

ManOfTeal.COM a Proud UNA site, six years running strong!
Quote · 14 Mar 2010

actually there are some places I would love to do this in my forum, can someone pm me the instructions?

the example code is all over this thread :)

Quote · 14 Mar 2010

http://www.boonex.com/trac/dolphin/ticket/1921

http://www.boonex.com/trac/dolphin/changeset/13785

Rules → http://www.boonex.com/terms
Quote · 15 Mar 2010

Alex, your fix is a little to aggressive.  I used to be able to post code snippets directly, now I need to use the pre tag.

My opinions expressed on this site, in no way represent those of Boonex or Boonex employees.
Quote · 15 Mar 2010

Alex, your fix is a little to aggressive.  I used to be able to post code snippets directly, now I need to use the pre tag.

Yep.. it is indeed!

just removing the HTML button on the TinyMCE editor works for me :)

Quote · 16 Mar 2010

Maybe we could assign permissions to the html button? Make it available to admins only? Then we would have the best of both worlds

http://towtalk.net ... Hosted by Zarconia.net!
Quote · 16 Mar 2010

Maybe we could assign permissions to the html button? Make it available to admins only? Then we would have the best of both worlds

the bad thing is.. you can always inject JS codes to your browser and re-enable the html button on the client side :(

Quote · 16 Mar 2010
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.