+ Reply to Thread
Results 1 to 4 of 4

Thread: SMF security

  1. #1
    The Evil Mod
    Last Activity Today 10:10 AM
    draggar's Avatar

    Join Date
    Dec 2007
    Location
    South Florida
    Country
    Posts
    9,351
    DNF$
    104,707
    Trader Rating: 38 reviews

    SMF security

    One of my sites (running SMF) had a spam attack - over 500 posts in 24 hours.

    I've installed new security measures but I'm afraid that it is not enough (heh, I'll know by tomorrow).

    I've installed better CAPTCHA and I've also installed Akismet but is there anything more?

    I know there is a hack for vBulliten that auto-moderates the first number of posts from new members - is there a similar hack for SMF?

    Also, i can hear some people now so I'll kill this now - don't tell me to get vBulliten. The site barely makes enough to pay the registration fees so vBulliten wouldn't be cost effective (plus converting from SMF to VB may not go well).


  2. #2
    Amms.com
    Last Activity Today 06:58 AM
    tristanperry's Avatar

    Join Date
    Jan 2007
    Location
    Wales, UK
    Country
    Posts
    1,568
    DNF$
    198
    Trader Rating: 53 reviews
    Spammers have been targetting phpBB/SMF quite a bit recently. One thing you can do (if you haven't installed this mod) is to install reCAPTCHA (http://custom.simplemachines.org/mod...x.php?mod=1044) - that's regarded as the best CAPTCHA out there.

    Also, anti-bot puzzles are invaluable - these are standard in SMF 2.0, and although it's only in RC I'd fully recommend the 2.0 branch (am a beta tester of SMF software). If not, look for an anti-bot puzzle/question mod for the 1.1 branch.

    Bots have got very clever recently, and can break reCAPTCHA sometimes, although nothing can really break through anti-bot puzzles/questions (I ask things like: "What is 2 + 5 - 1, answer in words?" and things like that etc)
    â–ˆ Devoted Hosting
    â–ˆ High Quality Shared And Reseller Hosting
    â–ˆ cPanel, 24/7 support, 99.9% uptime guaranteed


  3. #3
    The Evil Mod
    Last Activity Today 10:10 AM
    draggar's Avatar

    Join Date
    Dec 2007
    Location
    South Florida
    Country
    Posts
    9,351
    DNF$
    104,707
    Trader Rating: 38 reviews
    How stable is 2.0? Now I'm on 1.1.4 - the latest "stable" release is 1.1.9 - if 2.0 isn't stable enough, I may just upgrade to 1.1.9 this weekend.

    BTW - I like the avatar.


  4. #4
    Amms.com
    Last Activity Today 06:58 AM
    tristanperry's Avatar

    Join Date
    Jan 2007
    Location
    Wales, UK
    Country
    Posts
    1,568
    DNF$
    198
    Trader Rating: 53 reviews
    Quote Originally Posted by draggar View Post
    How stable is 2.0? Now I'm on 1.1.4 - the latest "stable" release is 1.1.9 - if 2.0 isn't stable enough, I may just upgrade to 1.1.9 this weekend.

    BTW - I like the avatar.
    Eek - there's been 5 security fixes in the 1.1.x branch since 1.1.4 - either way, it'd be best to upgrade (via the package manager; it's easy ) to 1.1.9 for the immediate short term.

    As for 2.0, I'd say it's stable enough now. It's got some bugs of course, although it's very stable overall and many sites with millions of posts use it fine:

    http://www.simplemachines.org/community/index.php - 2 million posts
    http://www.redandwhitekop.com/forum/ - 5.8 million posts
    http://www.hogville.net/yabbse/ - 3.5 million posts

    So it is stable really; they just say "Don't use it on a production site" just in-case a serious bug was introduced or something. Although I'm also using it (and have been since SMF 2.0 Beta 2) on forums I'm admin at which has over 1 million posts, and I haven't seen any real bugs.

    And thanks, it's a great show IMO
    Last edited by tristanperry; 06-19-2009 at 05:17 AM.
    â–ˆ Devoted Hosting
    â–ˆ High Quality Shared And Reseller Hosting
    â–ˆ cPanel, 24/7 support, 99.9% uptime guaranteed


+ Reply to Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts