We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 21759
    • 139 Posts
    Not sure if this is the right thread and I apologise if it isn’t. I am using modx 1.0.4 and new users have to be activated before being able to post. Yet somehow every day a bot is able to gain access and leave posts with urls and comments in my blog. When I view the admin backend I cannot see any reference to any new users and all web users/admin passwords have been changed twice. I do notice that all the info is in the three jot tables (content, fields and subscriptions) in the database and I usually delete everything from there. Is anyone else having this problem? I am now starting to go through every file in the directories looking for any new bits of code but haven’t found anything yet. Is this a smart bot or a hack?

    Is there any kind of comment spam plugin to help mitigate this out there?

    Update: Went through all code in every single file using winmerge and original files and didn’t see any hack evidence anywhere.
      • 21759
      • 139 Posts
      Well I’ve looked everywhere in the wiki and faq but cannot find any spam bot plugins or snippets so I assume there is nothing to combat this other than the captcha which is now being bypassed. No one can shed any light on what may be going on huh? I’ve removed the chunk that shows the comment text box so that has temporarily resolved it but the members would like to be able to comment on the blog/news at some point. Anyone??
        • 16278
        • 928 Posts
        Adding http to the &badwords list is quite effective in keeping spam links from being published. And I have an ever-growing list of IP addresses with "Deny from" in my .htaccess files, gathered from hours of otherwise impotent rage when I check server logs. I think the Jot records will tell you the IPs of submitters. Maybe a look at some specific unwelcome visitors in the server log (using the submit time to narrow your focus) will give you a clue as to how the perpetrators are getting in to post, and help you plug the security gap?

        Re comment spam plugins, I don’t know of one for MODx, but if you sign up with Project Honeypot they have an API for checking submitters against their database (haven’t tried to hook into it as yet). Then maybe you could change the address of your blog and set up a Honeypot trap at the old address. I still get attempts to spam a guestbook on a site that was completely rewritten two years ago, and is now a honeypot!

        sad KP
          • 3749
          • 24,544 Posts
          There are a couple of things you can do. There is a mollom class around here somewhere that you could build a spam-proofer from.

          Also, the SPForm add-on has version of Captcha with a math equation to solve that is quite effective. The captcha in the SPForm directory can be used independently to generate it for any form (With a little work).

          SPForm has a number of spam-proofing options and, if you’ve got the time and skills, you could modify SPForm to be your comment form.
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 21759
            • 139 Posts
            Unfortunately I don’t have the skills, I was looking for a cookie cutter solution. Guess there will be no commenting on the blog portion of the site until I can find someone to help me.
              • 21759
              • 139 Posts
              Not sure how to close this thread but I’ve hired someone to fix this for me. Thanks for trying to help me unfortunately I’m no coder and have a hard time understanding the lingo and ideas presented.