1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Fixed Banned spammers still show homepage and signature links in profile

Discussion in 'Resolved Bug Reports' started by Sim, Aug 30, 2011.

  1. Sim

    Sim Well-Known Member

    I created a new forum the other day. My very first user (before I had even had a chance to finish setting things up), was a signature spammer (user who registers with multiple links to drug websites in their signature).

    I banned them using the spam cleaner, but they still show up in the members list (at the top since there are no other users yet!!), and what is worse, the Recent Activity list shows them setting a link to their home page (which, because they are a spammer, is a spam link). The following screenshots are from a non-logged in user.

    recent_activity.png

    Also, clicking on their profile shows their signature, completely with spam links!!

    member_profile.png

    This is a serious problem that needs to be addressed by the core software - if a spam user is banned, we need to remove all reference to that user - especially their home page and signature from their profile that contain the spam links!!

    This is not just a regular user who has been banned - this is a spam user and as such, all traces of them need to be removed to discourage further spamming.

    I realise that these links are all nofollow, so there is little (or no) search engine benefit to be had - but the fact that these clearly spam links are still visible to my other users lowers the tone of the site and may spook new members.

    I believe this is a flaw in the spam cleaner.
     
    Veer, Brett Peters, Walter and 6 others like this.
  2. erich37

    erich37 Well-Known Member

  3. Digital Doctor

    Digital Doctor Well-Known Member

    Xenforo websites could be targeted specifically if the link farmers get wind of this.
     
    Sim, Alien and Blue like this.
  4. Crazyfruitbat

    Crazyfruitbat Well-Known Member

    realising the same thing for me too - its getting on my nerves - sick of deleting stuff
     
    erich37 likes this.
  5. CyclingTribe

    CyclingTribe Well-Known Member

    I would hope there is something in 1.1 to help with this ... my CycleChat mods won't take kindly to having to go to those lengths to get rid of spam content. :(
     
  6. MYstIC G

    MYstIC G Active Member

    Deebs likes this.
  7. Kier

    Kier XenForo Developer Staff Member

    Banned and unconfirmed users never show up in the activity feed with Beta 2.
     
    Deebs, MYstIC G and erich37 like this.
  8. CyclingTribe

    CyclingTribe Well-Known Member

    Do banned members still show up in the members list though?

    Also, would deleting a user remove all of that additional stuff?
     
  9. MYstIC G

    MYstIC G Active Member

    Cheers!
     
  10. erich37

    erich37 Well-Known Member

  11. Blue

    Blue Well-Known Member

  12. Kier

    Kier XenForo Developer Staff Member

    No, I think that has been addressed too.
     
    GeeksChat and Deebs like this.
  13. Kier

    Kier XenForo Developer Staff Member

    erich37, Sim, Veer and 4 others like this.
  14. Deebs

    Deebs Well-Known Member

    Damn you, Mike, you and XenForo rock. Awesome.
     
    Kier likes this.
  15. Kier

    Kier XenForo Developer Staff Member

    Pretty simple change actually - this lives just before the return true of XenForo_Model_UserProfile::canViewFullUserProfile()
    PHP:
    // user profiles of permanently-banned users should be unavailable to all but privacy-bypassing users
    if ($user['is_banned'])
    {
        
    $ban $this->getModelFromCache('XenForo_Model_Banning')->getBannedUserById($user['user_id']);

        if (
    $ban && $ban['end_date'] == && !$userModel->canBypassUserPrivacy($null$viewingUser))
        {
            
    $errorPhraseKey 'this_users_profile_is_not_available';
            return 
    false;
        }
    }
     
  16. Ingenious

    Ingenious Well-Known Member

    Any chance profiles for unconfirmed users can be unavailable too please, if that is not already the case (since the profile spam above could be replicated on an unconfirmed account on 1.0)?
     
    erich37 likes this.
  17. Kier

    Kier XenForo Developer Staff Member

    Yes, I'll add that.
     
    DaKat likes this.
  18. Kier

    Kier XenForo Developer Staff Member

    (Done)
     
    MYstIC G, Ingenious, erich37 and 5 others like this.
  19. Carlos

    Carlos Well-Known Member

    Geez. I mean, It's amazing what you can do or are capable of. :eek:

    I'm stunned...
     
  20. Ingenious

    Ingenious Well-Known Member

    Thanks Kier.
     

Share This Page