<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "Spam on AdvancedGuestBook 2.3.3"]]></title>
		<link>https://proxy2.de/forum/posts/list/5.php</link>
		<description><![CDATA[Latest messages posted in the topic "Spam on AdvancedGuestBook 2.3.3"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>Spam on AdvancedGuestBook 2.3.3</title>
				<description><![CDATA[ Hi,<br /> Can someone help me plz,i am getting between 80 and 100 messages a day on my guestbook,i am using AdvancedGuestBook 2.3.3 version.<br /> I have tried to block ip address but there are too many but some of them are like [code]Host&#58; localhost [/code]<br /> Thanks in Advance]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18369.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18369.php</link>
				<pubDate><![CDATA[Thu, 13 Oct 2005 06:59:42]]> GMT</pubDate>
				<author><![CDATA[ zaki]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ I should hope none are localhost as that would mean the spam is coming from your own server. Read the very first thread in this forum.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18370.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18370.php</link>
				<pubDate><![CDATA[Thu, 13 Oct 2005 08:18:23]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Carbonize"]I should hope none are localhost as that would mean the spam is coming from your own server. Read the very first thread in this forum.[/quote]<br /> <br /> I'm sorry, I've searced for the first thread in this forum, but I really couldn't find it. Where can I find it? I have the same problem as zaki and I really want to solve it.....]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18619.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18619.php</link>
				<pubDate><![CDATA[Tue, 8 Nov 2005 15:36:53]]> GMT</pubDate>
				<author><![CDATA[ kleinechris]]></author>
			</item>
			<item>
				<title>Spammers can use faked IP addresses</title>
				<description><![CDATA[ There's a bug in Advanced Guestbook that allows spammers or hackers to use faked IP addresses (incl 127.0.0.1 localhost). I've released a new version of Guestbook that solves this and many more security issues. It can be downloaded from <a class="snap_shots" href="http://www.freerelationshipadvice.com/downloads/guestbook27.zip" target="_blank" rel="nofollow">http://www.freerelationshipadvice.com/downloads/guestbook27.zip</a>]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18658.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18658.php</link>
				<pubDate><![CDATA[Fri, 11 Nov 2005 16:36:43]]> GMT</pubDate>
				<author><![CDATA[ markus56]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ IP banning is not a way to stop spam. It will sto pa few prolific spammers but a lot come from a variety of IP's. That is why I made my anti spam modifications to stop the posts before they happen.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18659.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18659.php</link>
				<pubDate><![CDATA[Fri, 11 Nov 2005 16:39:14]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Yes, Carbonize, I am aware of that. I invite you to have a closer look at the whole package. Security features include:<br /> - Distinguishing between real and fake IP<br /> - enforced delay for posting<br /> - protection against fake of significant form data (such as form load timestamp)<br /> - 2 level human verification: User must enter a value shown in an randomly chosen image at display time. Plus optional approval mode (Guestbook Administrator must approve new incoming messages). All these options (and many more) can be turned off and on at any time through the Administration panel<br /> <br /> Additional convenience feature for the Administrator:<br /> - necessary database upgrades are automatically discovered upon upload of a new version (no matter which version you are on currently)<br /> - /admin/config.inc.php no longer needs to be saved away and restored<br /> <br /> Full list of features: <a class="snap_shots" href="http://www.freerelationshipadvice.com/guestbook/whatsnew.txt" target="_blank" rel="nofollow">http://www.freerelationshipadvice.com/guestbook/whatsnew.txt</a>]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18660.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18660.php</link>
				<pubDate><![CDATA[Fri, 11 Nov 2005 19:32:34]]> GMT</pubDate>
				<author><![CDATA[ markus56]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Yes I have already looked at your 2.7 code including the 255 premade images you have for your image verification which prevents your guestbook being used with any language other than English. You should of just made the image contain the characters and left the message as part of the lang file. <br /> <br /> Any spammer who is actually going to go to the bother of spoofing the [b]HTTP_X_FORWARDED_FOR[/b] header is not going to be stopped by IP banning. As you have now implemented you need to stop the spam from getting posted in the first place otherwise you will end up having to go in and delete the spam entries that get made before your auto ban kicks in.<br /> <br /> Advanced Guestbook has come with a required field/time limit since version 2.3.3.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18661.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18661.php</link>
				<pubDate><![CDATA[Fri, 11 Nov 2005 19:46:54]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Yes, that's a good point, Carbonize. The images are not yet language sensitive. This will be included in an upcoming revision.<br /> <br /> As the validation value is a mandatory field, spam posted by bots will be rejected. As an additional security feature, a validation mode is in place (as mentioned before), so that new posts will not show up unless they're authorized. Since the introduction of the user validation field, my spam rate dropped by 100% !!<br /> <br /> Your comment re non-banning of spammers using the  [b]HTTP_X_FORWARDED_FOR[/b] header is not quite correct. In my version, users are banned based on their real IP address ($_SERVER['REMOTE_ADDR']) while the HTTP_X_FORWARDED_FOR address is kept in a separate variable. If acceptance of faked IP addresses is disabled (default), any difference between an existing HTTP_X_FORWARDED_FOR address and the real IP address will be rejected.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18663.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18663.php</link>
				<pubDate><![CDATA[Fri, 11 Nov 2005 20:07:49]]> GMT</pubDate>
				<author><![CDATA[ markus56]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="markus56"]Yes, Carbonize, I am aware of that. I invite you to have a closer look at the whole package. Security features include:<br /> - Distinguishing between real and fake IP<br /> - enforced delay for posting<br /> - protection against fake of significant form data (such as form load timestamp)<br /> - 2 level human verification: User must enter a value shown in an randomly chosen image at display time. Plus optional approval mode (Guestbook Administrator must approve new incoming messages). All these options (and many more) can be turned off and on at any time through the Administration panel<br /> <br /> Additional convenience feature for the Administrator:<br /> - necessary database upgrades are automatically discovered upon upload of a new version (no matter which version you are on currently)<br /> - /admin/config.inc.php no longer needs to be saved away and restored<br /> <br /> Full list of features: <a class="snap_shots" href="http://www.freerelationshipadvice.com/guestbook/whatsnew.txt" target="_blank" rel="nofollow">http://www.freerelationshipadvice.com/guestbook/whatsnew.txt</a>[/quote]<br /> <br /> <br /> Hi there i'm trying to install this version &amp; i'm running in some problems at this page mydomien/guestbook/install.php :<br /> <br /> <br /> Warning: main(/admin/ctl.inc.php): failed to open stream: No such file or directory in /home/sites/webhosting/jufkrista/jufkrista/www/guestbook/install.php on line 3<br /> <br /> Warning: main(): Failed opening '/admin/ctl.inc.php' for inclusion (include_path='.:/usr/lib/php:/home/sites/webhosting/uvmb/uvmb/phpincludes:/home/sites/webhosting/vbp/vbp/phpincludes') in /home/sites/webhosting/jufkrista/jufkrista/www/guestbook/install.php on line 3<br /> <br /> <br /> I'm installing from scratch.<br /> <br /> <br /> Please help.. i really need  a better version installed on my system.. too much spam.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18688.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18688.php</link>
				<pubDate><![CDATA[Tue, 15 Nov 2005 13:31:06]]> GMT</pubDate>
				<author><![CDATA[ anibal]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Hi,<br /> <br /> In file install.php, replace the 2nd line to read as follows:<br /> <br /> include_once "./admin/ctl.inc.php";<br /> <br /> Then it should work. Please give feedback.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18689.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18689.php</link>
				<pubDate><![CDATA[Tue, 15 Nov 2005 14:30:09]]> GMT</pubDate>
				<author><![CDATA[ markus56]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Thank you.. i'm switching to <a class="snap_shots" href="http://lazarus.carbonize.co.uk" target="_blank" rel="nofollow">http://lazarus.carbonize.co.uk</a><br /> <br /> Looks better &amp; is up to date  <img src="https://proxy2.de/forum//images/smilies/8a80c6485cd926be453217d59a84a888.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18690.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18690.php</link>
				<pubDate><![CDATA[Tue, 15 Nov 2005 16:12:42]]> GMT</pubDate>
				<author><![CDATA[ anibal]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Yes, it's true, the first version (2.5) removed a lot of spam, but not all of it, it e.g. limited the # of messages per day to 9 (or a different value set in the preferences). It though already distinguished between faked and real IP addresses (faked ones no longer admitted)<br /> <br /> The big break-through occurred with version 2.6 in which I added a 2 level human verification (by user and / or admin). From that time forward, the spam rate dropped to 0%.<br /> <br /> Other than in Lazarus, the human verfication value in version 2.6 / 2.7 is not a static per site value; it is randomly chosen from a range of 255 values at display time. Also, the antibot value is not parsable by spammers, because it's displayed as a graphical image.<br /> <br /> In version 2.7, I further added automated delta-checks for the database-structure. Any missing fields and/or tables will be added automatically, whereas existing columns and tables are NOT removed. <br /> <br /> New in version 2.7.3:<br /> - Language-safe: If a new value was not translated into the Advanced Guestbook target language, the English value will be displayed, along with the keyname between brackets. This helps the administrator to identify missing entries in their language file<br /> <br /> - Graphic files for antibot values no longer contain surrounding text ("Please enter value..."). This text may now be configured via the language file<br /> <br /> Get the latest version at <a class="snap_shots" href="http://www.freerelationshipadvice.com/downloads/guestbook27.zip" target="_blank" rel="nofollow">http://www.freerelationshipadvice.com/downloads/guestbook27.zip</a>]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18849.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18849.php</link>
				<pubDate><![CDATA[Sun, 27 Nov 2005 14:26:14]]> GMT</pubDate>
				<author><![CDATA[ markus56]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ I have to say sinds using lazarus the SPAM was complet gone <img src="https://proxy2.de/forum//images/smilies/8a80c6485cd926be453217d59a84a888.gif" /> i have 3 sites runing LAZARUS &amp; have less costumers contacting me everyday <img src="https://proxy2.de/forum//images/smilies/8a80c6485cd926be453217d59a84a888.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/18850.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/18850.php</link>
				<pubDate><![CDATA[Sun, 27 Nov 2005 15:01:11]]> GMT</pubDate>
				<author><![CDATA[ anibal]]></author>
			</item>
			<item>
				<title>Lazarus can still be spammed!</title>
				<description><![CDATA[ This simple, stupid script will create spam entries into the lazarus.co.uk guestbook with an arbitrary name.<br /> <br /> [code]CODE REMOVED BY CARBONIZE[/code]<br /> <br /> - It gets the entry form<br /> - then it grabs the special value by parsing the source code and enters it into the bottest field<br /> - then it waits for 30 seconds before it posts it to the forum<br /> <br /> This is where the advantage of a picture display over a parsable text display shows up.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/19611.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/19611.php</link>
				<pubDate><![CDATA[Sun, 12 Feb 2006 10:33:35]]> GMT</pubDate>
				<author><![CDATA[ markus56]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ So long as the persons host has GD compiled. <br /> Also given that the question/answer can be anything <br /> you have to visit the site to know what to parse.<br /> <br /> I am flattered you went to such lengths to make <br /> a script to spam my guestbook. Note I say MY guestbook <br /> as your script will only spam my copy of Lazarus and <br /> therefore is pointless.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/19612.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/19612.php</link>
				<pubDate><![CDATA[Sun, 12 Feb 2006 10:38:47]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Well, I assume it's not quite pointless. I deliberately wrote the script in a way that it spams only 1 site with ONE message. I'm sure that each of our forum readers has enough programming skills to enhance it (i.e. read website names from an Array or database).<br /> <br /> the point was to prove that Lazarus boards CAN BE spammed, which you now have admitted.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/19614.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/19614.php</link>
				<pubDate><![CDATA[Sun, 12 Feb 2006 11:59:17]]> GMT</pubDate>
				<author><![CDATA[ markus56]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Well, I assume it's not quite pointless. I deliberately wrote the script in a way that it spams only 1 site with ONE message. I'm sure that each of our forum readers has enough programming skills to enhance it (i.e. read website names from an Array or database).<br /> <br /> the point was to prove that Lazarus boards CAN BE spammed, which you now have admitted.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/19615.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/19615.php</link>
				<pubDate><![CDATA[Sun, 12 Feb 2006 12:04:15]]> GMT</pubDate>
				<author><![CDATA[ markus56]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Yes but I suggest you take a look at your own guestbook. The only post it has had since you introduced image verification is in fact a spam entry.<br /> <br /> You cannot make a universal Lazarus spamming script as the anti bot question on every site will be different. Some may contain the answer in the question and some wont. Not all of them are in English for a start. The only way you could make a script to spam multiple Lazarus sites is to actually visit the site and manually put the answer into the script. <br /> <br /> Oh and do you really think I'm stupid enough to have left the useragent exploit in place? Who do you think it was reported the exploit in the first place?]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/19616.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/19616.php</link>
				<pubDate><![CDATA[Sun, 12 Feb 2006 12:07:08]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Sorry to disappoint you, but the entry you talk about is NOT a spam entry. Before releasing this one to the list of entries, I carefully checked the log. The positive statement (even though also used in spam entries) is in this particular case a manually entered message by someone who visited the site in fact.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/19617.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/19617.php</link>
				<pubDate><![CDATA[Sun, 12 Feb 2006 13:05:41]]> GMT</pubDate>
				<author><![CDATA[ markus56]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Spam is spam regardless of whether it was posted manually or by a script/program. There are people out there who manually spam guestbooks and forums.<br /> <br /> <a class="snap_shots" href="http://www.google.com/search?hl=en&amp;lr=&amp;q=%22class-first-travel.50webs.com%22" target="_blank" rel="nofollow">http://www.google.com/search?hl=en&amp;lr=&amp;q=%22class-first-travel.50webs.com%22</a>]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/19618.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/19618.php</link>
				<pubDate><![CDATA[Sun, 12 Feb 2006 13:24:09]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Personally carb I wouldnt give [b]markass[/b] the time of day. He is just pissed because you came up with the better ideas and all he can do is copy you!]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/19627.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/19627.php</link>
				<pubDate><![CDATA[Sun, 12 Feb 2006 21:08:25]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ no we came up with different ways of takling the same problem. The reason Lazarus is more popular is because as well as anti spam I added more features and options as well as improved existing ones.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/5087/19631.php</guid>
				<link>https://proxy2.de/forum/posts/preList/5087/19631.php</link>
				<pubDate><![CDATA[Sun, 12 Feb 2006 21:16:49]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
	</channel>
</rss>