31
32
Support / Re: After trying to put the forum into maintenance mode, it “disappeared”
Last post by Spuds -33
Support / Re: After trying to put the forum into maintenance mode, it “disappeared”
Last post by Steeley -I've not encountered the problem you refer to, but that's the first location I'd sniff around in to see what's there. If no clues there hopefully Spuds (or someone else more knowledgeable than I) has a better idea..
34
Support / After trying to put the forum into maintenance mode, it “disappeared”
Last post by Mrs. Chaos -I'm currently having a problem with my forum that I caused myself ...
Apparently, there was a DDoS attack on it for two days. It wasn’t a very large one, and it doesn’t seem like anyone was trying to sign up or log in, but around the clock, there were 8 to 10 times as many visitors as usual. These “visitors” all had completely different IP addresses, so I couldn’t simply block certain IP ranges.
I then decided to put the forum into maintenance mode for almost a day, hoping that would put an end to these fake visits. But I apparently did something wrong in the process.
There are apparently two ways to set maintenance mode, and I must have chosen the wrong one. In any case, the forum is now completely inaccessible via the internet. A page loading error and a “500 Internal Server Error” are displayed.
I can log into the database through my host. There, I simply restored/imported the latest backup, which I had made two days ago, hoping that the forum would be back online afterward. Unfortunately, it isn’t. It’s still gone.
What else can I try now? What is the correct way?
Greetings to all
35
Feature Discussion / Re: Searching for words adjacent to an underscore
Last post by Spuds -36
Feature Discussion / Re: Searching for words adjacent to an underscore
Last post by korth -We're currently using 1.1.8 and no joy there.
(note: I'm not an administrator)
37
Feature Discussion / Re: Searching for words adjacent to an underscore
Last post by Spuds -In 2.0 I've done several iterations on the best indexing to use (when using custom search index) and I sometimes forget to rebuild the index. There could also be a bug or two that I need to track down!
38
Feature Discussion / Searching for words adjacent to an underscore
Last post by korth -There doesn't seem to be a way to search for words adjacent to an underscore.
Example: https://www.elkarte.net/community/index.php?t/Re%3A-Features-or-permissions-required-to-delete-your-own-post-attachments-6070.msg43189#msg43189 contains the term "edit_disable_time".
Searching for edit_disable_time does not return any matches.
Searching for disable does not* return the post referenced above or the replies that follow.
Searching for disable time does not return any matches.
*edit: incorrect word replacement: the > not
39
Chit Chat / Re: Tips for Bots
Last post by Spuds -Quote from: "shawnb61" – So... The idea is good - don't use PHPSESSID, and, since you're not generating it anymore, you can then block it via .htaccess.
I been playing with various defensive options on several sites during bot storms including custom jails for fail2ban or behaviors in crowdsec but when they hit hard those functions can begin to consume a lot of CPU and have memory growth problems to the point your server will likely be overwhelmed. They are however effective.
Country Code / ASN blocks help somewhat, really depends on how aggressive you want to be. Many of the bot blocks come out of US based residential groups so things can get ugly if you just block at the ASN level.
Connection and rate limiting in Nginx are also effective, but still have an impact on resources as as its still handling the traffic even if its 444 response.
Bots also love sending urls with printpage and prev_next links, a sure sign of crawler activity. I use those as honeypots of sorts to say bu-bye.
I was often seeing 10-15K guests during a storm, I know for other sites this is trivial, but for my VPS it was just to much the bots could just roll through ip/24 or ip/20 as needed (some ipv4 some ipv6).
I was (am) using the PHPSESSION trick to detect bot activity as well, you will often see the same PHPSESSION being used across multiple IP's. As I blocked on that over time, those started to not be included in the crawl links. Ah the gift of AI.
Ultimately I ended up using Cloudflare and its free level reverse proxy. I did not want to, you know you feel like you have been beat! After enabling that and a few custom security rules I do not see more than 100 guests at a time, which is quite normal. What is nice about the service is you can add Country/ASN blocks as wanted, and various security checks, like URL sniffs etc. These requests are then dropped at the edge and your server never has to deal with any of that traffic.
If you do not want to fully block on a specific rule they do have two forms of challenges, the intrusive one with the annoying check box, and a passive one that checks for .... are cookies enabled? and is JS running? I use the later, real users/guests are not impacted and bots fail. They also have the appropriate allow rules for legit bots based on browser id and correct ASN for them. One last aspect of this, once you have it enabled, you then only accept traffic from cloudflare IP's (and you know your own just in case LOL) as those are vetted queries. Overall for me a massive reduction on site abuse. I still use crowdsec to further protect other areas, mail, ssh, ftp, etc but it has a lot less work to do.
All of this is not going to get better, the AI bots have access to what is essentially unlimited resources and will adapt on how to scrape a site down to its bones.
40
Chit Chat / Re: Tips for Bots
Last post by Steeley -First thing you need is a directory-privacy feature (htaccess, in Apache, for example). C-Panel makes it easy to manage. However, that's not something ElkArte can do.. you create the protected directory on your server, and then tuck ElkArte behind it.. It's the directory-privacy feature that keeps the bots out and away from ElkArte (and anything else you don't want the unwashed masses to access). It's not the most secure way, but I've not yet had anyone try to "hack in" (except valid users that couldn't remember their credentials.. eventually they send me an email or another access request..)
Then you need some software routines to support your validation of people that will have access to the protected area..
email-code.php (located in cgi-bin)
Code: [Select]
<?php
if(!isset($_POST['submit']))
{
//This page should not be accessed directly. Need to submit the form.
echo "error; you need to submit the form!";
}
$visitor_email = $_POST['email'];
$message = rand(100000, 999999);
//Validate first
if(empty($visitor_email))
{
echo "Email address is mandatory!";
exit;
}
if (!strstr($visitor_email, '@'))
{
echo "EMail Format is Incorrect - missing @ - press back button and try again";
exit;
}
if (strpos($visitor_email, ','))
{
echo "EMail Format is Incorrect - contains a comma - press back button and try again";
exit;
}
if(IsInjected($visitor_email))
{
echo "Bad email value!";
exit;
}
$email_from = 'no-reply@domain.url';
$email_subject = "Validation Code";
$email_body =
"Copy the following validation code into the request form. \n".
"(If you did not request a code, someone entered an incorrect email address,\n". "please accept our apologies and delete this email.) \n".
"Validation Code: $message. \n".
"Submitter address: \n".
$to = "$visitor_email \r\n";
$headers = "From: no_reply@domain.url \r\n";
$headers .= "Reply-To: no_reply@domain.url \r\n";
$headers .= "Bcc: access@domain.url \r\n"; //(goes to admin to match with later applicant form)
//Send the email!
mail($to,$email_subject,$email_body,$headers);
//done. redirect to code-pending page.
header('Location: ../pending.html');
form-to-email.php (located in cgi-bin)
Code: [Select]
<?php
if(!isset($_POST['submit']))
{
//This page should not be accessed directly. Need to submit the form.
echo "error; you need to submit the form!";
}
$Fname = $_POST['First'];
$Lname = $_POST['Last'];
$visitor_email = $_POST['email'];
$code = $_POST['code'];
$username = $_POST['Nick'];
//{other fields you want here}
$message = $_POST['Narrative'];
//Validate first
if(empty($Fname))
{
echo "First name is required! Please press back button and correct";
exit;
}
if(strpos($Fname, '_'))
{
echo "Valid first and last name is required! Please press back button and correct";
exit;
}
if(empty($Lname))
{
echo "Last name is required! Please press back button and correct";
exit;
}
if(strpos($Lname, '_'))
{
echo "Valid last name is required! Please press back button and correct";
exit;
}
if(empty($visitor_email))
{
echo "Email is required! Please press back button and correct";
exit;
}
if(IsInjected($visitor_email))
{
echo "Bad email value!";
exit;
}
if(empty($code))
{
echo "Verification Code is required. Please press back button and correct";
exit;
}
if(empty($username))
{
echo "If you do not provide a nickname/username, you might not like what we assign. Please press back button and correct";
exit;
}
if(strpos($username, '/'))
{
echo "If you do not provide a nickname/username, you might not like what we assign. Please press back button and correct";
exit;
}
//if(empty{otherfields}))
//{
// echo "Tthis data is required! Please press back button and correct";
// exit;
//}
$email_from = 'no-reply@domain.url';
$email_subject = "Access Request";
$email_body = "$Fname $Lname has submitted the following information for access: \n".
"EMail Address: $visitor_email \n".
"Validation code: $code \n".
"Username: $username \n".
//etc.. for additional fields
"$username says: \n $message \n".
$to = "access@domain.msg \r\n";
$headers = "From: $email_from \r\n";
$headers .= "Reply-To: $visitor_email \r\n";
//Send the email!
mail($to,$email_subject,$email_body,$headers);
//done. redirect to submitted page.
header('Location: ../submitted.html');
// Function to validate against any email injection attempts
function IsInjected($str)
{
$injections = array('(\n+)',
'(\r+)',
'(\t+)',
'(%0A+)',
'(%0D+)',
'(%08+)',
'(%09+)'
);
$inject = join('|', $injections);
$inject = "/$inject/i";
if(preg_match($inject,$str))
{
return true;
}
else
{
return false;
}
}
?>
gen_validatorv31.js is located in cgi-bin/scripts for form validation
And of course, html pages
web form for email addy that will drive the above
gets email addy, assign code and send email..
working guts are:
Code: [Select]
(snip)
<SCRIPT language=JavaScript type=text/javascript
src="scripts/gen_validatorv31.js"></SCRIPT>
</HEAD>
<BODY >
(your instructions and formatting here..)
<TBODY>
<TR>
<TD><!-- Start code for the form-->
<DIV align=center>
<FORM method=post name="EMail Address Verification"
action=../cgi-bin/email-code.php>
<P>STEP 1</P>
<P><LABEL for=email>Enter Your Email Address
(carefully)</LABEL><BR><INPUT style="HEIGHT: 22px; WIDTH: 338px"
size=21 name=email> </P>
<P></P><INPUT type=submit value=submit name=submit> </FORM></DIV>
<SCRIPT language=JavaScript>
var frmvalidator = new Validator("EMail Address Verification");
frmvalidator.addValidation("email","req","Please provide your email");
frmvalidator.addValidation("email","email","Please enter a valid email address");
</SCRIPT>
Submit brings up a "pending" webpage, tells submitter to get the email sent, and then click on "I have the code".
When they click on that, it brings up the authorization-data html form.
That form contains the same form structure as the form above, but with different fields, and calls a different form-email routine
Code: [Select]
snip
<TD><!-- Start code for the form-->
<DIV align=center>
<FORM method=post name="Access Data"
action=../cgi-bin/form-to-email.php>
but with other fields (first name, last name, nickname/username, and any other pertinent information you desire to validate the applicant. Upon submit, it calls form-to-email.php, instead of email-code.php, and sends the applicant to a "success" page, informing them to wait for another email with their authorization data. and what to do with it to get into the "restricted section" behind the htaccess-directory check..
Of course, you would want to customize your authorization webpages to your needs, but the crux of the code is above.. it's simple stuff, really.. for example, I tell users to let their webbrowser remember the authorization data so it's just one extra mouse click to get into the restricted area. (HOWEVER - the ducklduckgo webbrowser - and maybe others - doesn't know wtf a directory-access prompts looks like so it doesn't bring up the username password like it does for other account-access prompts). Edge, Chrome, Firefox etc. does.
EDIT: OH, and you have have to configure mail.php to send smtp mail through your mail server, simple in concept, but your actual mileage may vary..