Announcement

Collapse
No announcement yet.

spammers appear to be signing up via iphone app

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • spammers appear to be signing up via iphone app

    im using the latest API and iphone app.

    3 questions

    1) i'm using GD / image verification for the forum, but iphone users do not see a captcha image when sign up . i'm positive they are coming from the iphone app based on 1) useragent "iPhone/1.0" 2) API logs i have enabled 3) IP geolocation. is this a bug?

    2) is there a way to simply disable users from registering on the app altogether? 99% of the users already will have a username using it

    and no i don't want to use question and answer verification for the forum

    if this is not possible, i would suggest having a feature for it.

    3) is it possible that if someone reverse engineer the app and analyze API key and/or POST data, they could make a script to register users bypassing registration verification based on #1 above (since no image verification)? yes or no? If no, why, what prevention would stop this? please explain, thanks

  • #2
    anyone ?

    Comment


    • #3
      1. We are using reCaptcha here and that does not show for iPhone registration either. The registration went through without it. If you feel this is a bug, please report this in the vB4 Bug Tracker here:

      http://tracker.vbulletin.com/secure/Dashboard.jspa

      2. Sorry, there is no function to do this. This requires modifying the code. We cannot officially support code modifications or forums running modified code, however you can try searching or asking for help with this over at www.vbulletin.org.

      3. Not sure I understand how someone could reverse engineer this and replace your app. I highly doubt this is feasible at all.
      Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
      Change CKEditor Colors to Match Style (for 4.1.4 and above)

      Steve Machol Photography


      Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


      Comment


      • #4
        "If you feel this is a bug"? Really?

        Comment


        • #5
          Originally posted by nakedanvil View Post
          "If you feel this is a bug"? Really?
          Slight oversight and massive understatement from me

          Comment


          • #6
            Originally posted by nakedanvil View Post
            "If you feel this is a bug"? Really?
            Yep, seriously. It could be working just as designed or within the limits of iOS. I really don't know.
            Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
            Change CKEditor Colors to Match Style (for 4.1.4 and above)

            Steve Machol Photography


            Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


            Comment


            • #7
              I like that apple gives you the option to offer your app by country. No reason to offer to RIPE or APNIC since 99% of my spam originates from there.

              Comment


              • #8
                Originally posted by m0rgulvale View Post

                3) is it possible that if someone reverse engineer the app and analyze API key and/or POST data, they could make a script to register users bypassing registration verification based on #1 above (since no image verification)? yes or no? If no, why, what prevention would stop this? please explain, thanks
                Technically this is very much possible and it IS a possibility. Practically I don't know how smart these spammers are.
                Hosting Coupons: Hostmonster @ $3.95 and 20% off Mediatemple

                Comment

                widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                Working...
                X