View Single Post
Old September 30th, 2008, 10:17 PM   #1 (permalink)
Swanny
Member
Verified Customer
 
Swanny's Avatar
 
Join Date: Jun 2002
Location: Western Canada
Posts: 333
Exclamation Tons of comment spam, permissions not working...

So I'm running PP Pro v6.1 (integrated with phpbb3) and I've got a hardcore spam problem.

This photo has 1,898 comments between Sept 15 & 30, and they're all spam:
Ford Flex Photos - 2009 Ford Flex

There are 2,600+ total comments on all the photos and I'd guess less than 100 are real comments by humans. The problem is beyond just that one photo, but that photo is the worst.

The real problem is that the permissions in the Edit Usergroups are set right so registered users are the only ones that can post. Note with phpBB3 there is no Anonymous group, there is Guests however. They don't have access to anything but viewing. Also in the Edit Categories I've ensured that only registered users have the ability to post comments.

Why can hundreds of Anonymous people/spambots leave comments? Is there some security flaw? Has my server been compromised?

I also noticed a rash of comment spam on another of my PP pro installs to (forget the version number offhand).

Has anyone seen this before? If the usergroup permissions are set right how can Anonymous people leave comments?

I realize you're probably going to tell me to upgrade to v6.2, I'll do that. But this makes me wonder if there is a bug that you guys don't know about that's why I'm telling you about it.

Chuck, I can send you admin login details if you'd like. Just let me know what I should do next (I'm not sure an upgrade will fix the problem but...) In the meantime, I've just deleted the comments.php file from the server.
Swanny is offline   Reply With Quote