We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 38685
    • 59 Posts
    Hi all.... Here is my problem....

    I want to integrate the IPBanning module into Eform....

    Basically... all I want is a function in a snippet that I can load into the &EformOnValidate=`eformipban` that checks both/either/or the senders email, or the senders IP....

    This is because my site is completely public, with no web login users....

    I already have the IPBanning module setup which means the database tables are there!

    BTW If there is a post already on this let me know!!
      Paul AL Bakulich - Association for Computing Machinery Professional Member
      http://palbakulich.me/ | http://twitter.com/#!/palhmbs
      • 38685
      • 59 Posts
      Hi Guys... I’ve done it... so here it is....

      This needs to go at the top of the file (eform.inc.php)....
      $remoteip = $_SERVER["REMOTE_ADDR"];

      then add this to your eform.inc.php file just under the vericode check on line 224....
      
                        // Add $remoteip to placeholder 
      	if(!strstr($tpl,'[+remoteip+]'))
      		$fields['remoteip'] = str_replace('[+remoteip+]', 'IP:', $remoteip);
      
      
      
      	if ($eFormOnValidate) {
      	    		//Check banned IPs
      			$banipres = $modx->db->select('ip', $modx->getFullTableName('banip'),"ip='".$remoteip."'");
      			$baniprows = mysql_num_rows($banipres);
      			if ($baniprows > 0){
      				$url = $modx->makeURL('11');  // Please note put your resource id... in here!
      				$modx->sendRedirect($url); // return 'The Banned Email list!'; //we have a match - this email is banned
      				}
      
      			//Check banned emails
      			$banemailres = $modx->db->select('email', $modx->getFullTableName('banemail'),"email='".$fields['email']."'");
      			$banrows = mysql_num_rows($banemailres);
      			if ($banrows > 0){
      				$url = $modx->makeURL('11');  Please note put your resource id... in here!
      				$modx->sendRedirect($url); // return 'The Banned Email list!'; //we have a match - this email is banned
      				}
      			}
      


      and to give us the details of the Remote IP [+remoteip+] in the chunk (report) which is sent with all emails!

      I owe a big thanks to J Stover from Connecticut, USA who has helped me on this one!

      Please let me know if you have problems implementing, I will be glad to help!

      Thanks all!
      Paul
        Paul AL Bakulich - Association for Computing Machinery Professional Member
        http://palbakulich.me/ | http://twitter.com/#!/palhmbs
        • 3749
        • 24,544 Posts
        You should be aware the spammers are usually using fake IPs via zombie computers, WiFi IPs, forwarding, etc. and they contstantly change IPs. So getting heavily into banning IPs will often lock out legitimate users and barely slow down the spammers.

        SPForm has a very flexible IP, domain, and email banning system but I seldom use it except for persistent individual spammers. Modifying your .htaccess file to lock out spammers and using basic spam-proofing techniques will usually do a better job without penalizing regular users.

        Putting something like this in the .htaccess file will block many spammers before they get anywhere near eForm:

        #first, block bad bots
        RewriteCond %{HTTP_USER_AGENT} libwww-perl.*
        RewriteRule .* - [F,L]
        
        RewriteCond %{QUERY_STRING} snippet\.reflect\.php [NC,OR]
        RewriteCond %{QUERY_STRING} reflect_base [NC,OR]
        RewriteCond %{QUERY_STRING} (.*)(http|https|ftp):\/\/(.*) [NC]
        RewriteCond %{HTTP_USER_AGENT} ^libwww-perl [NC]
        RewriteRule .* - [F,L]
          Did I help you? Buy me a beer
          Get my Book: MODX:The Official Guide
          MODX info for everyone: http://bobsguides.com/modx.html
          My MODX Extras
          Bob's Guides is now hosted at A2 MODX Hosting
          • 38685
          • 59 Posts
          Thanks BobRay...
          But I did already have that one implemented from a previous post of yours on a different thread...

          BTW... There is the email blocking side of this IPBanning module that works great too!

          As long as the people are only normal people who don’t go running around changing their email adddresses all the time the Sendme.org.nz site should hold down the spam bots nicely!

          Kind regards
          Paul
            Paul AL Bakulich - Association for Computing Machinery Professional Member
            http://palbakulich.me/ | http://twitter.com/#!/palhmbs