|
-
December 6th, 2005, 06:44 PM
#1
Ideas for stopping spam attacks
Ok we all know whats going on and by who, we also know how difficult it is to stop as even if we put restrictions at a member level he can just create a new account and start again.
So here is a few suggestions...am not sure of the set up for this board so some may already be in place - if they are, great! Now lets get the rest in place as well 
- Unique Email address for every sign up (so he has to regsiter for a new email addrress as well as here)
- Email verification of address
- only 1 sign up from any given IP every 24hrs
- Cookie placed to block any new registrations from machine for 24hrs
- New thread limit of 4 per hr per member / IP
- If a thread is bumped which is over 2 months old a 'send back' button which senior members can use to _unbump_ the thread
- Increase flood protection time to 3mins
- Maximum of 10 posts per hr from any member / IP
- Add image verification to signup screen
- No more than 3 logins (to different accounts) from any ip in 24hrs
- Better swear word filters in username
Ok these are easy to implement features that wouldn't restict normal users too much - infact most people wont notice they are there.
Also I suggest some sort of 'smart' member managment.
For example :
each action performed which is normal for an attack such as this throws up a flag and adds to a total for that member.
so say a member bumps 2 threads over 2months old within 30mins - they score 1 point
they have a post rejected due to the flood protection 6 times in half an hr - another point
they create the maximum allowed number of new threads 2hrs running - 3rd point
and so on
then we could compare the number of points scored alongside ap status and length of membership. If the result is less than a certain cut off point - a notification is sent to an admin to review the users actions, and they are suspended until outcome is decided. Admin can then ban or remove suspension.
Oh and last idea :
as well as the report button link / negative aps - there should be a report member button. This could work similar to APs but with a lower cut off point.
Rather than banning member if they hit the limit of reports in any 24hr period they would have posting/ap rights removed and their account could be flagged for review by an admin.
Just some ideas - any chance of getting at least some of these implemented. There is nothing really difficult to code up in them...
what does everyone else think?
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|