Bitcoin Forum
May 05, 2024, 08:09:21 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 [27] 28 29 30 »
  Print  
Author Topic: [Updated 19/Jul/2016] Faucet Owners Against Scammers and Bots  (Read 36624 times)
felicita
Legendary
*
Offline Offline

Activity: 1582
Merit: 1031



View Profile
August 18, 2016, 04:48:10 PM
 #521

you can test here with a proxy !
it blocks only ISP so it will only bann Servers no real users !!!
http://yannik.biz/vpntest.php

if you get good isp but u using a proxy give me the proxy ip and i can add this to my blocklist soon we will block all bots !!


kind regards
1714939761
Hero Member
*
Offline Offline

Posts: 1714939761

View Profile Personal Message (Offline)

Ignore
1714939761
Reply with quote  #2

1714939761
Report to moderator
1714939761
Hero Member
*
Offline Offline

Posts: 1714939761

View Profile Personal Message (Offline)

Ignore
1714939761
Reply with quote  #2

1714939761
Report to moderator
If you want to be a moderator, report many posts with accuracy. You will be noticed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
vartox
Newbie
*
Offline Offline

Activity: 41
Merit: 0


View Profile WWW
August 18, 2016, 05:14:24 PM
 #522

Just noticed that I have no protection against scammers and bots on my facet, thanks for this epic thread  Grin
alfaboy23
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500



View Profile
August 19, 2016, 12:08:41 AM
 #523

you can test here with a proxy !
it blocks only ISP so it will only bann Servers no real users !!!
http://yannik.biz/vpntest.php

if you get good isp but u using a proxy give me the proxy ip and i can add this to my blocklist soon we will block all bots !!


kind regards
I'm using a proxy, but still says "good isp". I think you missed the ISP named Hurricane Electric.
felicita
Legendary
*
Offline Offline

Activity: 1582
Merit: 1031



View Profile
August 19, 2016, 01:51:54 PM
 #524

you can test here with a proxy !
it blocks only ISP so it will only bann Servers no real users !!!
http://yannik.biz/vpntest.php

if you get good isp but u using a proxy give me the proxy ip and i can add this to my blocklist soon we will block all bots !!


kind regards
I'm using a proxy, but still says "good isp". I think you missed the ISP named Hurricane Electric.

thanks for this  great infromation . Added this to the blocklist .
Can you name the proxy u used ?

kind regards
alfaboy23
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500



View Profile
August 20, 2016, 12:37:54 AM
 #525

you can test here with a proxy !
it blocks only ISP so it will only bann Servers no real users !!!
http://yannik.biz/vpntest.php

if you get good isp but u using a proxy give me the proxy ip and i can add this to my blocklist soon we will block all bots !!


kind regards
I'm using a proxy, but still says "good isp". I think you missed the ISP named Hurricane Electric.

thanks for this  great infromation . Added this to the blocklist .
Can you name the proxy u used ?

kind regards
It's a Windows application called Freegate by Dynaweb. It uses the Hurricane Electric as ISP.
alfaboy23
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500



View Profile
August 28, 2016, 10:57:57 AM
Last edit: August 29, 2016, 08:07:32 AM by alfaboy23
 #526

I just want to add this for a little security to Xapo faucet script:

First, find this in your /index.php on your root directory:
Code: (php)
if ($_SERVER['REQUEST_METHOD'] === 'POST' && !isset($_POST["new_password"])) {

  $view['main']['result_html']  = '';
  $view['main']['waiting_time'] = 0;
  $success                      = "false";
  $ip                           = get_ip();

Just after that, place this:
Code: (php)
$disallowedWords = array(
  'yandex.',
  'inbox.',
  'mail.',
  'ukr.net',
  'bigmir.net',
  'meta.ua'
);
// Search for disallowed words.
foreach ($disallowedWords as $xword) {
  if (strpos($_POST['username'], $xword) !== false) {
    $view['main']['result_html'] = '<div class="row text-center"><div class="col-sm-6 col-md-offset-3 bg-danger"><p><b>The e-mail you are using is not allowed!</font></b></p></div></div>';
    $message                     = "Forbidden";
    goto error;
  }
}

It will not allow the e-mail addresses with that specified word. You can also specify whole e-mail addresses.

I hope it will help even just a little.


BitBustah
Hero Member
*****
Offline Offline

Activity: 1218
Merit: 534



View Profile
August 28, 2016, 07:27:12 PM
 #527

you can test here with a proxy !
it blocks only ISP so it will only bann Servers no real users !!!
http://yannik.biz/vpntest.php

if you get good isp but u using a proxy give me the proxy ip and i can add this to my blocklist soon we will block all bots !!


kind regards

"nothing to look here !"

Is that good or bad?
FaucetRank.com
Hero Member
*****
Offline Offline

Activity: 868
Merit: 500



View Profile WWW
August 29, 2016, 03:21:09 AM
 #528

I'm again saying blocking proxy is not solution for bots you have to be tricky to flight with them I also tired many ip blocking  tricks but did not get the success because bot may come from any country and you can't block all countries just to keep your faucet live, you also have to earn money from your traffic.

  ████
█ ████
█ ████
█ ████
█ ████ █
█ ████ █
█ ████ █
█ ████ █
█ ████ █
  ████ █
  ████ █
  ████ █
  ████
  ████
█ ████
█ ████
█ ████
█ ████ █
█ ████ █
█ ████ █
█ ████ █
█ ████ █
  ████ █
  ████ █
  ████ █
  ████
  .SCAMMERS.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
  .EXPOSED.
.
▄▄▄▄▄▄▄▄
  ████
█ ████
█ ████
█ ████
█ ████ █
█ ████ █
█ ████ █
█ ████ █
█ ████ █
  ████ █
  ████ █
  ████ █
  ████
FaucetSystem.com
Member
**
Offline Offline

Activity: 127
Merit: 10


View Profile WWW
August 30, 2016, 07:28:38 PM
 #529

If you pay user before proxy detection it makes no sense, you lost your money. In my faucet script at the beginning we try detect a proxy and after pay; plus non standart captcha (http://faucetsystem.com/img/screens/fullsize/8.png).

Bitcoin microtransactions service -> https://cryptobara.com
NeedIfFindIt
Full Member
***
Offline Offline

Activity: 500
Merit: 100



View Profile
September 09, 2016, 08:30:25 PM
 #530

Bots are insane today 50% of the claims from a ~100 satoshi faucet with nastyhosts disabled + no anti bot links.

They continue to try even when I stopped paying them a week ago.

I've port scanned few of the bot IPs - no open ports at all  Huh He probably uses "port knocking".

The only common thing between his IPs is that they are not pingable (it is not really practical to check for this).

confirmed:
- the default puzzles of anti-bot links 2.x are broken - either delete the default ones and create your own or upgrade to 5.01
- once the antibotlinks 5+ is in place (make sure ttf/otf fonts work) the bot will stop trying to claim (I hope for long).
catcatcatcaty
Full Member
***
Offline Offline

Activity: 152
Merit: 100


View Profile
September 09, 2016, 08:51:11 PM
 #531

Bots are insane today 50% of the claims from a ~100 satoshi faucet with nastyhosts disabled + no anti bot links.

They continue to try even when I stopped paying them a week ago.

I've port scanned few of the bot IPs - no open ports at all  Huh He probably uses "port knocking".

The only common thing between his IPs is that they are not pingable (it is not really practical to check for this).

confirmed:
- the default puzzles of anti-bot links 2.x are broken - either delete the default ones and create your own or upgrade to 5.01
- once the antibotlinks 5+ is in place (make sure ttf/otf fonts work) the bot will stop trying to claim (I hope for long).

looking at that screenshot - what is waterfallmanager? how to use it in my faucet? it looks effective against bots!
NeedIfFindIt
Full Member
***
Offline Offline

Activity: 500
Merit: 100



View Profile
September 09, 2016, 09:39:47 PM
 #532

Bots are insane today 50% of the claims from a ~100 satoshi faucet with nastyhosts disabled + no anti bot links.

They continue to try even when I stopped paying them a week ago.

I've port scanned few of the bot IPs - no open ports at all  Huh He probably uses "port knocking".

The only common thing between his IPs is that they are not pingable (it is not really practical to check for this).

confirmed:
- the default puzzles of anti-bot links 2.x are broken - either delete the default ones and create your own or upgrade to 5.01
- once the antibotlinks 5+ is in place (make sure ttf/otf fonts work) the bot will stop trying to claim (I hope for long).

looking at that screenshot - what is waterfallmanager? how to use it in my faucet? it looks effective against bots!

It is still in development (planned to be paid service since it uses alot of resources) but it is not perfect for now. Today it screwed 3 legit users Sad

Maybe in a week or two I'll start a beta with all the users that have helped in the past few months and if everything is ok I'll make it available to everybody else.
sabotag3x
Legendary
*
Online Online

Activity: 2534
Merit: 2170


Crypto Swap Exchange


View Profile
September 10, 2016, 12:55:12 PM
 #533

Bots are insane today 50% of the claims from a ~100 satoshi faucet with nastyhosts disabled + no anti bot links.

They continue to try even when I stopped paying them a week ago.

I've port scanned few of the bot IPs - no open ports at all  Huh He probably uses "port knocking".

The only common thing between his IPs is that they are not pingable (it is not really practical to check for this).

confirmed:
- the default puzzles of anti-bot links 2.x are broken - either delete the default ones and create your own or upgrade to 5.01
- once the antibotlinks 5+ is in place (make sure ttf/otf fonts work) the bot will stop trying to claim (I hope for long).

Same here, my faucet is dry(2-3 days) and still have ~1500 visits from bots..

I think they have a faucetlist and keep trying to enter/claim in everyone  Cheesy

I was using a big blacklist, well it ban real user too, however it can stop a lot of bots..

I'm waiting your defense system be ready to everyone!

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
felicita
Legendary
*
Offline Offline

Activity: 1582
Merit: 1031



View Profile
September 10, 2016, 06:26:51 PM
 #534

Bots are insane today 50% of the claims from a ~100 satoshi faucet with nastyhosts disabled + no anti bot links.

They continue to try even when I stopped paying them a week ago.

I've port scanned few of the bot IPs - no open ports at all  Huh He probably uses "port knocking".

The only common thing between his IPs is that they are not pingable (it is not really practical to check for this).

confirmed:
- the default puzzles of anti-bot links 2.x are broken - either delete the default ones and create your own or upgrade to 5.01
- once the antibotlinks 5+ is in place (make sure ttf/otf fonts work) the bot will stop trying to claim (I hope for long).

looking at that screenshot - what is waterfallmanager? how to use it in my faucet? it looks effective against bots!

It is still in development (planned to be paid service since it uses alot of resources) but it is not perfect for now. Today it screwed 3 legit users Sad

Maybe in a week or two I'll start a beta with all the users that have helped in the past few months and if everything is ok I'll make it available to everybody else.

great to here this we need this !
iam also working on a VPN Defense !!
http://shielded.cf/index.php?id=1

but its not ready yet !!


kind regards
sabotag3x
Legendary
*
Online Online

Activity: 2534
Merit: 2170


Crypto Swap Exchange


View Profile
September 10, 2016, 08:01:58 PM
 #535

Bots are insane today 50% of the claims from a ~100 satoshi faucet with nastyhosts disabled + no anti bot links.

They continue to try even when I stopped paying them a week ago.

I've port scanned few of the bot IPs - no open ports at all  Huh He probably uses "port knocking".

The only common thing between his IPs is that they are not pingable (it is not really practical to check for this).

confirmed:
- the default puzzles of anti-bot links 2.x are broken - either delete the default ones and create your own or upgrade to 5.01
- once the antibotlinks 5+ is in place (make sure ttf/otf fonts work) the bot will stop trying to claim (I hope for long).

looking at that screenshot - what is waterfallmanager? how to use it in my faucet? it looks effective against bots!

It is still in development (planned to be paid service since it uses alot of resources) but it is not perfect for now. Today it screwed 3 legit users Sad

Maybe in a week or two I'll start a beta with all the users that have helped in the past few months and if everything is ok I'll make it available to everybody else.

great to here this we need this !
iam also working on a VPN Defense !!
http://shielded.cf/index.php?id=1

but its not ready yet !!


kind regards

I thinked in your system too felicita, and other day I saw this topic https://bitcointalk.org/index.php?topic=1599533.0, is your alt account?

Well, a lot of people trying to bring security for faucet owners, that's great!

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
CroSany
Full Member
***
Offline Offline

Activity: 196
Merit: 100



View Profile
September 10, 2016, 08:06:44 PM
 #536

I suggest you guys update your script or add some sort of email verification for users. I have reduced my botting almost completely since I implemented this change - in fact, I predict that most large faucets will need to implement such features if they are to survive.

The Faucetbox script as standard suits small-medium faucets, anyone offering more than 500 satoshi per hour is at risk.

You need to surgically remove bots and not delete large referral trees.
FaucetRank.com
Hero Member
*****
Offline Offline

Activity: 868
Merit: 500



View Profile WWW
September 12, 2016, 03:06:35 AM
 #537

I just want to add this for a little security to Xapo faucet script:

First, find this in your /index.php on your root directory:
Code: (php)
if ($_SERVER['REQUEST_METHOD'] === 'POST' && !isset($_POST["new_password"])) {

  $view['main']['result_html']  = '';
  $view['main']['waiting_time'] = 0;
  $success                      = "false";
  $ip                           = get_ip();

Just after that, place this:
Code: (php)
$disallowedWords = array(
  'yandex.',
  'inbox.',
  'mail.',
  'ukr.net',
  'bigmir.net',
  'meta.ua'
);
// Search for disallowed words.
foreach ($disallowedWords as $xword) {
  if (strpos($_POST['username'], $xword) !== false) {
    $view['main']['result_html'] = '<div class="row text-center"><div class="col-sm-6 col-md-offset-3 bg-danger"><p><b>The e-mail you are using is not allowed!</font></b></p></div></div>';
    $message                     = "Forbidden";
    goto error;
  }
}

It will not allow the e-mail addresses with that specified word. You can also specify whole e-mail addresses.

I hope it will help even just a little.




This is very useful code because recently I got bot attack from these domains email but now they gone forever because of this code.
thanks for sharing this with us.

  ████
█ ████
█ ████
█ ████
█ ████ █
█ ████ █
█ ████ █
█ ████ █
█ ████ █
  ████ █
  ████ █
  ████ █
  ████
  ████
█ ████
█ ████
█ ████
█ ████ █
█ ████ █
█ ████ █
█ ████ █
█ ████ █
  ████ █
  ████ █
  ████ █
  ████
  .SCAMMERS.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
  .EXPOSED.
.
▄▄▄▄▄▄▄▄
  ████
█ ████
█ ████
█ ████
█ ████ █
█ ████ █
█ ████ █
█ ████ █
█ ████ █
  ████ █
  ████ █
  ████ █
  ████
viperzero
Member
**
Offline Offline

Activity: 301
Merit: 10



View Profile
September 18, 2016, 12:30:37 AM
 #538

Bots are insane today 50% of the claims from a ~100 satoshi faucet with nastyhosts disabled + no anti bot links.

They continue to try even when I stopped paying them a week ago.

I've port scanned few of the bot IPs - no open ports at all  Huh He probably uses "port knocking".

The only common thing between his IPs is that they are not pingable (it is not really practical to check for this).

confirmed:
- the default puzzles of anti-bot links 2.x are broken - either delete the default ones and create your own or upgrade to 5.01
- once the antibotlinks 5+ is in place (make sure ttf/otf fonts work) the bot will stop trying to claim (I hope for long).

looking at that screenshot - what is waterfallmanager? how to use it in my faucet? it looks effective against bots!

It is still in development (planned to be paid service since it uses alot of resources) but it is not perfect for now. Today it screwed 3 legit users Sad

Maybe in a week or two I'll start a beta with all the users that have helped in the past few months and if everything is ok I'll make it available to everybody else.

great to here this we need this !
iam also working on a VPN Defense !!
http://shielded.cf/index.php?id=1

but its not ready yet !!


kind regards

I thinked in your system too felicita, and other day I saw this topic https://bitcointalk.org/index.php?topic=1599533.0, is your alt account?

Well, a lot of people trying to bring security for faucet owners, that's great!

I upgraded today to faucetbox R65 and NeeditFindit's  antiBotlinks 5.01 is not working anymore. I posted a message to him and hopefully this will be sorted out soon. So don't upgrade yet if you have antibotlinks in use and plan to continue to use it. I made a small donation and hope everybody else makes the same so we can have an update to antibotlinks. Keep up the good work fighting against bots!
Butord
Member
**
Offline Offline

Activity: 95
Merit: 10


View Profile
September 18, 2016, 11:44:53 AM
 #539

Hi, everyone.
I know that faucetbox script has btc address block function but what the code for it? For ex. if I want to use the code to block some certain btc address on other faucet script could smn write what the code it can be?
MONKEYJUNK
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
September 18, 2016, 05:32:54 PM
 #540

Hi, everyone.
I know that faucetbox script has btc address block function but what the code for it? For ex. if I want to use the code to block some certain btc address on other faucet script could smn write what the code it can be?

Maybe it's this part of the code
Code:
$security_settings = array();
    $q = $sql->query("SELECT `name`, `value` FROM `Faucetinabox_Settings` WHERE `name` in ('ip_check_server', 'ip_ban_list', 'hostname_ban_list', 'address_ban_list')");
    while($row = $q->fetch()) {
        if(stripos($row["name"], "_list") !== false) {
            $security_settings[$row["name"]] = array();
            if(preg_match_all("/[^,;\s]+/", $row["value"], $matches)) {
                foreach($matches[0] as $m) {
                    $security_settings[$row["name"]][] = $m;
                }
            }
        } else {
            $security_settings[$row["name"]] = $row["value"];
        }
    }

    if(!empty($_POST["mmc"])) {
        $_SESSION["mouse_movement_detected"] = true;
        die();
    }

    if($_SERVER["REQUEST_METHOD"] == "POST") {
        if($security_settings["ip_check_server"]) {
            if(!preg_match("#/$#", $security_settings["ip_check_server"])) {
                $security_settings["ip_check_server"] .= "/";
            }
        }

And you will have to add the address to this table on sql 'address_ban_list'
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 [27] 28 29 30 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!