XF 2.0 Spammers, help!

JoyFreak

Well-known member
I woke up this morning and found a number of registrants on my forums spamming my forums. I have Q&A on my forums and you also have to validate your email address. These guys have used number of email addresses same as their registered username i.e oyifecuc@outlook.com etc.

How do I keep these guys away? Even though I have Q&A and validate email? I checked and none share same IP nor any other accounts.

https://www.legendofmir.org
 
I have deleted all their accounts and they register like a second after, same name and start posting within seconds. WTH!?!?
How do you delete there posts in one click? Can't find it naywhere!!!!!!

This is really daunting that i have to delete them in moderation tool, select threads on every page and delete. There is 19 pages!!! Is there a quicker way?

I've had to close my site down because they just keep on coming. Like FLEAS!!!
 
Last edited:
You can use the spam cleaner, though there are constraints on when it's available. See the "Spam cleaner user criteria" option (use the ACP search to get to it). You may need to increase those limits.

Beyond that, personally, I don't think a Q&A captcha is usually ideal, on the basis that once it's solved (particularly if you only have one question), it provides nothing. You likely need to provide a reasonably large set of questions and be rotating them regularly.

Spam prevention will never be a truly automatic thing. Look at the various options in the "spam management" option group. Notably, you may want to configure spam phrases, words/phrases that when used will automatically block or cause manual approval for the message.
 
Yes, and make sure to give yourself the permission to use the spam cleaner, then it's part of the edit list on each post. Then do the things Mike mentions.

I have 2 sites that have very odd differences. One is busier, but I have nearly zero attempted spam registrations, I only use Q&A, and never change the questions, and the server load is minimal

The other is not very busy at all, but the server load is over triple, and it's under constant barrage of registration attempts. Once they crack the questions, I get a handful of successful registrations daily but very very rarely does a post ever make it through unmoderated, and their account always gets flagged as suspect. I then change the questions and for some reason they don't try to crack it again for another 3-4 months. And it's not like they're terribly difficult questions.

I also have a StopSpamForum API key as well as a Project Honey Pot Key in place on both sites.

I still check every registration as users will enter in a spammy website as their home page, dead giveaway, earns a ban.
 
The specific guide here is for XF1, but most of the concepts apply to XF2 as well: https://xenforo.com/help/spam/

If you have permission and the user meets the spam user criteria option I mentioned before, you'll see a link in their profile and on their content to spam clean them, which can automatically delete all of their content. If they have been posting for an extended period of time, you may need to increase the criteria options to allow it to run. (Note that it isn't necessarily designed to take out thousands of posts/threads at a time and server limits may apply then. If that's the case, the batch update thread tools in the control panel may be necessary.)
 
Ok I will try, so what is the best one to use other than Q&A? So i dont have to keep changing it every so often?

I mean on here it uses the click one and barely see any spams on here
 
We use ReCAPTCHA's invisible CAPTCHA, though you can use ReCAPTCHA standard without any configuration out of the box.

Other than that, most of our spam gets caught via the spam phrases system and Akismet. The little bit that slips through usually gets cleaned up quickly.
 
I did that ReCaptcha invisible, got the api and secret key. Even got the StopSpamForum API key as well as a Project Honey Pot Key and about half hour later, they on my forums made about 20+ threads already. Seriously what is this? I had to close my site and I do not want to close it for long. Please help.
 
I have deleted all their accounts and they register like a second after, same name and start posting within seconds. WTH!?!?
How do you delete there posts in one click? Can't find it naywhere!!!!!!

This is really daunting that i have to delete them in moderation tool, select threads on every page and delete. There is 19 pages!!! Is there a quicker way?

I've had to close my site down because they just keep on coming. Like FLEAS!!!
Don't delete them just ban them and delete their profile it wil prevent the other use the same ip to spam your 4rum
 
Top Bottom