FORUM HOME | WHUK BLOG   
WEB HOSTING UK AFFORDABLE WEBSITE HOSTING SERVICES IN UNITED KINGDOM
PHP LINUX SHARED HOSTING WINDOWS ASP.NET HOSTING PACKAGES
ECOMMERCE HOSTING ASP MSSQL MS ACCESS ODBC FRONTPAGE HOSTING
CPANEL WHM FANTASTICO RESELLER DEDICATED SERVER WEB HOSTING
CHEAP PLESK CPANEL HTML MYSQL BEST UK VPS HOSTING COMPANY
CHEAP RELIABLE UK HOSTING PROVIDER SINCE 2001
MANAGED WEB HOSTING SERVICE
AFFORDABLE WEBSITE HOSTING SERVICES IN UNITED KINGDOM

Web Hosting UK Forums | Linux Windows Dedicated Server and cPanel VPS Hosting Forum » Technical Support » cPanel Shared Hosting

Reply
 
LinkBack Thread Tools Display Modes

  #1 (permalink)  
Old 03-03-10, 09:33 AM
new member
 
Join Date: Mar 2010
Posts: 9
Default Testimonials SQL table being spammed

Hi,
I don't know if anyone can help me but here goes anyway.
I have been using the RSMonials (ver 1.5.2) component to enable my customers to leave testimonials on my site.
About a month ago a spammer began leaving up to 5 spam testimonials each day.
I activated a setting that notified me by email each time a testimonial is posted. I can then go into the administration side of the RSMonials component and delete the spam.
This is obviously tedious. I would prefer to block the spammer but don't know how.

In an effort to stop the spammer I disabled the RSMonial component and the Testimonial menu and left it for 24 hours. This successfully stopped the spam, but obviously prevented genuine customers leaving a testimonial as well.
I then re-enabled the component but left the Testimonial menu disabled. After about 12 hours the spamming began again.
Therefore the spammer seems to be able to access the component without using the testimonials menu option (possibly via a carefully crafted web link?)
Can anyone offer advice on how to track the spammer down and block him?
Many thanks.
Reply With Quote

  #2 (permalink)  
Old 03-03-10, 12:40 PM
Senior Member
 
Join Date: Jan 2007
Location: Dorset
Posts: 1,117
Default

Hi, unfortunately its one of those situations that affects most of us where a form can be spammed by bots.
Your only solution is to get support from rsmonails whom i would have thought had options to add or improve the captcha or offer some other blocking scripts.

No experience with that open source script but is there not an option for you to validate the testimonials before they go live on the site?.

other option would be to add another form field where they have to add a certain word, phrase, or combo and then check for that before the testimonial is entered.
Reply With Quote

  #3 (permalink)  
Old 03-03-10, 01:54 PM
new member
 
Join Date: Mar 2010
Posts: 9
Default

Hi Jon123,
Thanks for your quick response and comments.
I am already validating the testimonials, as you suggest, and screening out the spam, so, yes, the spam does not get published which is good news, but it is still a task that I'd rather not have to do.
Your suggestion to add another check to the form, I don't think would work. The spammer seems to bypass the form altogether. Also I have disabled the Testimonial menu entry so there is no way he can get to the form. Using the previous link [compuguide.info/joomla15/index.php/testimonials] to the testimonials form fails with a 404 error.
Reply With Quote

  #4 (permalink)  
Old 04-03-10, 06:02 PM
Senior Member
 
Join Date: Jan 2007
Location: Dorset
Posts: 1,117
Default

hi, if the spambots are bypassing the form then the form isnt being validated at the insert end. Adding another form field and checking the contents of that field on the insert page before the entry is executed should stop the insertion.

As a minimum on my forms i check that the form submit button has been clicked by passing the value of the submit button along with the rest of the form. If the submit button hasnt been clicked (i.e they have tried to enter data without using the form), then the entry is rejected.

As mentioned, that is a minimum, I also have a captcha or a text field to help stop the problems you are facing.
Reply With Quote

  #5 (permalink)  
Old 04-03-10, 06:24 PM
new member
 
Join Date: Mar 2010
Posts: 9
Default

Thanks for the advice, but sadly it is over my head, I barely knew enough to get the component installed. Hacking the php code is beyond me.
I can't complain, though, it was a free component. I guess it's time to go out and buy a commercial Testimonial component.
Thanks
Reply With Quote

  #6 (permalink)  
Old 05-03-10, 12:45 PM
Senior Member
 
Join Date: Jan 2007
Location: Dorset
Posts: 1,117
Default

you're welcome.
Isnt there a mod for that script them? I presume a lot of folk are having the same problems as you are. Common problem really with popular form scripts, they are targeted by the spambots.

Just been to their website and support isnt to be found apart from an email address. As you say a freebie so cant complain.
Reply With Quote

  #7 (permalink)  
Old 05-03-10, 01:07 PM
new member
 
Join Date: Mar 2010
Posts: 9
Default

I may hold off on switching to a new Testimonials component.
I have discovered that I can delete a whole bunch of the spams directly from the SQL table in one go, using the cPanel's "phpMyAdmin" option, rather than deleting each one individually from the component's admin page.
This makes it much less tedious to keep clean.
Reply With Quote

Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump


All times are GMT. The time now is 04:34 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Copyright 2001-2010 Web Hosting UK. All rights reserved.
Web Hosting UK Forum





Site Map

Shared Cloud
Shared Cloud From £1

Affiliate Program
Earn up to £300 Per Sale

Dedicated Servers
Dedicated Server Hosting

Cloud Hosting
Cloud Server Hosting

Load Balanced Server
Load Balancing Server

VPS Hosting
Linux VPS Hosting

Windows VPS
Windows 2003 VPS

Zimbra Hosting
Zimbra Email Hosting

cPanel Hosting
Shared Linux Hosting

Windows Hosting
Shared Windows Hosting

Coldfusion Hosting
Windows Coldfusion Hosting

cPanel Reseller Hosting
Shared Windows Hosting

Windows Reseller
Windows Reseller Hosting

Email Web Hosting
Email Hosting

Semi-Dedicated Server
Semi-Dedicated Hosting

Remote Backup Plans
Offsite Backup Service


cpanel hosting
Knowledgebase Articles

Pre-Sales Question
Web Hosting FAQ's

Dedicated Hosting
Dedicated Server FAQ's

Virtual Private Servers
VPS Hosting

PHP MySQL Hosting
cPanel Hosting

Windows Hosting
ASP MSSQL Hosting

Domain Name
Domain registration FAQ's

CMS Hosting
CMS Hosting FAQ's

Payment Gateways
Payment FAQ's


Support Tutorials

cPanel Tutorials
cPanel Flash Tutorials

Wordpress Tutorials
Wordpress Flash Tutorials

Plesk Tutorials
Plesk Flash Tutorials

PhpMyadmin Tutorials
PhpMyadmin Flash Tutorials

Drupal Tutorials
Drupal Flash Tutorials

Mambo Tutorials
Mambo Flash Tutorials

Joomla Tutorials
Joomla Flash Tutorials

More Hosting Tutorials