Home Private Messages Search
CPG Dragonfly™ CMS stopsoftwarepatents.eu petition banner
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ Banning system :: Archived


Banning system :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page Previous  1, 2
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Fri Apr 01, 2005 6:05 pm
Post subject: Re: Banning system

thank you. after last night hope you came away with a new appreciation on the issue.


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Sun Apr 03, 2005 3:19 pm
Post subject: Re: Banning system

DJdevon, don't think I don't appreciate it. Hell I advocate it.

There's an old saying, 'if you can't beat em, join em.' So why not get over how important your site is and let the rugrats terrorize your site. After a while they'll get bored and move on.

I still do not think banning is a solution and I'm not about to rehash why it's a bad idea. I think most webmasters understand why banning is a bad idea, and if you still think this is your solution then so be it. Choice is what the world is about.

But.....to stay on topic for this forum...

Banning does not stop troublemakers it annoys them. Annoying troublemakers is like painting a target on your home and asking them not to use it for target practice.

Banning cannot control access or restrict access except by using what I call 'sledge hammer' techniques. Unless you ban huge blocks of IP's it's never effective to your average dynamic user.

What does work is gathering the evidence that the offenders violated your usage policies, and a report of that violation to the ISP in control of the block. This will get the little rug rags outta your hair very quickly.

Of course you could also call their mother and have a chat too. If they are underage you should get a Guardian approval to use the site, and request a contact phone number for approval. Then when they apply you can call them and advise them that any abuse will hold the parent accountable.

COPPA in fact demands you do this especially when the content (most gaming sites) are rated Mature.

Just my two cents. Smile

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
MajorHeadache
Supporter
Supporter

Offline Offline
Joined: Mar 05, 2005
Posts: 263
Location: My Little Pony Arena
PostPosted: Fri Apr 22, 2005 8:38 am
Post subject: Re: Banning system

I'm very interested in this topic too. I had the same idea of cookie-ing trolls. The majority of which would likely never realize what was keeping them out.

I also agree that to annoy (ban) these types of people can have quite the opposite effect that you want, but let me tell you, once you've had a troll on your site, for say a YEAR, and they constantly aggravate your members, your staff, and you, start looking for solutions. Paint the target, bring it on.

I used to use Protector which was quite nice because when they came back to the site, they were remembered as who they were and their new IP was banned automatically. This was quite successful, most of the time.

As for reporting it to their ISP, I have tried this a few times with my main problem child. First, the ISP won't even take a report unless it's from a police agency. Even the police have to leave a message. Emails were never reposnded to, and apparently never dealt with because nothing changed. And the police aren't even going to get involved unless there is a serious threat made. "So and so violated my TOS" isn't going to get much attention in these understaffed overworked times. But if you've had different results, I'd love to hear about it.

So after realizing that a user can change their IP, email and username with impunity, you start thinking about a way to tag them where they live and the cookie is the only thing that comes to mind. It may be a small thing, but another tool in the arsenal can't hurt.

My current strategy is getting the email when a new user joins. It includes their IP so if they're not using AOL, at least I have a chance to indentify them early on.


MajorHeadache's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Redhat Enterprise 4/Apache 2.2/MySQL 4.1.22/PHP 5/CPG 9.1.2.1
Back to top
View user's profile Visit poster's website
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Sat Apr 23, 2005 3:05 pm
Post subject: Re: Banning system

We do understand and share in the grief of trolls. We have had and continue to have our share of trolls and other nuisance makers. What is our magical solution? Active administrators keeping the site clean. Simple.

There is no automagic solution except to kill every one on the planet. Hmm that's not going to work is it, then nobody will visit your web site except you Wink

So being a webmaster is all about MANAGING your SITE FOR your USERS. Having a ban system is all about banning actual IP's from connecting to your site which is about as useful as fighting fire with gasoline.

HTH,

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 2 of 2
All times are GMT
Go to page Previous  1, 2

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

Διαβάστε περισσότερα ...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy