Not sure if this is the right thread and I apologise if it isn’t. I am using modx 1.0.4 and new users have to be activated before being able to post. Yet somehow every day a bot is able to gain access and leave posts with urls and comments in my blog. When I view the admin backend I cannot see any reference to any new users and all web users/admin passwords have been changed twice. I do notice that all the info is in the three jot tables (content, fields and subscriptions) in the database and I usually delete everything from there. Is anyone else having this problem? I am now starting to go through every file in the directories looking for any new bits of code but haven’t found anything yet. Is this a smart bot or a hack?
Is there any kind of comment spam plugin to help mitigate this out there?
Update: Went through all code in every single file using winmerge and original files and didn’t see any hack evidence anywhere.
Well I’ve looked everywhere in the wiki and faq but cannot find any spam bot plugins or snippets so I assume there is nothing to combat this other than the captcha which is now being bypassed. No one can shed any light on what may be going on huh? I’ve removed the chunk that shows the comment text box so that has temporarily resolved it but the members would like to be able to comment on the blog/news at some point. Anyone??
There are a couple of things you can do. There is a mollom class around here somewhere that you could build a spam-proofer from.
Also, the SPForm add-on has version of Captcha with a math equation to solve that is quite effective. The captcha in the SPForm directory can be used independently to generate it for any form (With a little work).
SPForm has a number of spam-proofing options and, if you’ve got the time and skills, you could modify SPForm to be your comment form.
Unfortunately I don’t have the skills, I was looking for a cookie cutter solution. Guess there will be no commenting on the blog portion of the site until I can find someone to help me.
Not sure how to close this thread but I’ve hired someone to fix this for me. Thanks for trying to help me unfortunately I’m no coder and have a hard time understanding the lingo and ideas presented.