The MU forums have moved to WordPress.org

Spam and Splogs defeated ( Montyspam looking for testers) (257 posts)

  1. fouad.fakhr
    Member
    Posted 16 years ago #

    @suleiman
    i agree with you about bypassing the user defined preferences regarding comments control
    WPMU is wonderful in letting your users having all the fun running a free blog/site and controlling every aspect in it
    and this plugin is very needed too , i think this option should be defined by the site admin or to be removed at all from the plugin
    i'm testing it now on a test site - even doesn't have links on any other site but got 20 spammers on the first day !!! - and let's see , i'll post the stats later here isa

  2. macgruder
    Member
    Posted 16 years ago #

    Yes, actually the intention was simply to make Monty over-ride the URL count defined by the user for 'probable spam'. The reason behind this is that he uses this as a Bayesian spam indicator anyway and so that setting becomes unnecessary for the user, as Monty will catch those anyway. However, it seems that this over-ride may affect other settings that hadn't occurred to me at the time - nothing major but something that I'll look at.

    Bear in mind, Monty is designed to put spam control in the hands of the site admin. Otherwise, you'll just encourage spammer to sign up manually one time and spam their own sites.

    My own experience is that Monty is very effective with comment spam. I don't have enough signup Spam to tell. But in fact, when he rates something as unknown in signup spam I find myself often unable to tell either - making him more difficult to train.

  3. Ovidiu
    Member
    Posted 16 years ago #

    any news on the single wp version?

  4. macgruder
    Member
    Posted 16 years ago #

    Working on it. Hopefully by the 10th.

  5. honewatson
    Member
    Posted 16 years ago #

    One annoying aspect is not having the url of the trackback in the administer trackback list.

    If I can see the url I can quickly ascertain as to whether or not its spam.

    Instead I have to click through to see the details to see the url, select spam, process, then click a link to get back to the main trackback list.

  6. macgruder
    Member
    Posted 16 years ago #

    Yes, you are right. There are a few interface things that need adjustment. They annoy me too. Post here and I'll fix them quicker :-)

  7. musnake
    Member
    Posted 16 years ago #

    Seeing as monty is domain-specific at this time, is there a workaround for those of us that use domain mapping with Mu? I've recently started experimenting with not only domain mapping but it's variant, quantum-Mu (Mu's of Mu's) where the child instances source a parent code-base (including plugins) and the abstraction is all db trickery (and woe).

    How about it? Domain mapping (parked domains) and Monty?

  8. musnake
    Member
    Posted 16 years ago #

    Ok, forget the quantum-Mu stuff, I allowed myself to become distracted by the possibilities...

    Single WPMu instance with a subdomain/blog mapped to domain2.tld

    Monty coughs up the goat with this. On the horizon...?

  9. macgruder
    Member
    Posted 16 years ago #

    @Musnake,
    I'm going to be dealing with these issues as soon as possible. Been busy with that thing that seems to always get in the way: work :-)

    I'm hoping this month.

  10. musnake
    Member
    Posted 16 years ago #

    Thanks man. I was actually expecting a fellow WPMuer to respond but the man himself works too!

    I was wondering if there are any issues related to integrating bbPress. If the forum subdirectory is locked out of Mu the only content that makes it to Mu would be piped stuff like 'Hot Threads' etc...

    Thanks.

  11. macgruder
    Member
    Posted 16 years ago #

    I don't think there will be issues. Monty hooks into Post actions so with bbPress I guess nothing will happen.

    The main issues (which need to be addressed) are things like when Monty asks you to check something. Especially with new users on potential Splogs if you have set Monty to check every first blog post (not comment) Monty will tend to ask you to check all the posts of that user until you do that first check. If you are getting a lot of people signing up this can be a little annoying, and this is the kind of interface issue that needs to be improved.

    Also, there seems to be a small bug whereby Monty doesn't automatically spam the signup data if you mark the blog post as spam - I've just noticed this. It means an extra step of doing this manually - I'll fix it in due course.

    On the other hand, stopping comment spam works almost perfectly in my experience, and since on my installs this is a far bigger problem, this has been great.

    For comment spam (see below) we have 12,000 comment blocks, 10 checks by me, 0 errors ( I got lucky there - Monty usually makes one or two errors to begin with). The interesting thing is that he has only 22 spams in his database meaning that most spams are fairly similar. It's interesting to see the techniques that spammers try to use. My favourite is the random word stuff:

    tnhhn nthuyknth ypri nhuou ntheus

    When Monty sees this he goes, "Ah, 5 words I don't know". Rate each 50%, overall rating 50%, but there may be other issues that suggest the post is spam. But since the poster has a spammy rating of 50% he hasn't hit the magical 10% that he needs anyway. Monty will tell you to check this, and when you do he gets the other header data that the spammer sent. So these random words just help him because they teach him the patterns that spammers use.

    Stats
    Total Number of Spam Block
    12702 accesses. Oh Yeah!

    Straight Block
    10610 accesses. Yeah!

    Comment Spam
    Token Database

    Spams: 22 messages with a total of 2412 tokens

    Hams: 13 messages with a total of 1265 tokens
    Overall

    Spam Stopped:2075
    Ham Let Through:13

    Classified as Unknown
    Spam:6
    Ham:4

    These are messages that Monty needed help with. Will be higher in the early stages.
    Errors

    Wrongly spammed:0
    Wrongly hammed:0

  12. Ovidiu
    Member
    Posted 16 years ago #

    any news on the single wp version?
    I would really love to get rid of my other anti spam tools.

  13. macgruder
    Member
    Posted 16 years ago #

    I'll try to get it done this month.

    Bug me by email occasionally!

  14. Ovidiu
    Member
    Posted 16 years ago #

    I know I shouldn't be posting this here, but email you, but I am at work :-(

    monty caught a spammy trackback, he was unsure about, so I confirmed as spam, but after going to the admin panel, monty still said:

    Trackback
    Token Database

    Spams: 0 messages with a total of 0 tokens

    Hams: 0 messages with a total of 0 tokens
    Overall

    Spam Stopped:0

    Ham Let Through:0
    Classified as Unknown

    Spam:0

    Ham:0
    Errors

    Wrongly spammed:0

    Wrongly hammed:0

    AND I found the same trackback in my moderation queue.

  15. macgruder
    Member
    Posted 16 years ago #

    Hey Ovidiu,
    There's probably something wrong with your install because they are all zero - you may have gotten a download where I accidently put 256 as a var length rather than 255 which barfs on some systems. Try deleting the Monty tables and reinstalling - then do a test message. Let me know if you get the same problem.

  16. Ovidiu
    Member
    Posted 16 years ago #

    well, but thats only the trackback part that doesn't seem to work...
    comments, splogs, etc. all work...

    I'll try and do a reinstall later on after work.

  17. gape2
    Member
    Posted 16 years ago #

    hi
    i installed monty on wp-mu that is installed in subdirectory
    domain.com/blogs

    trouble is - from begining, when i click on install button, install mises the directory
    it assumes my install is in the root of the domain
    i fixed the code (paths - added the name of the dir - 41 ocurences) in
    montypsamm/admin.php
    install went thru ok
    all functions as far i can tell work
    but, when i get email from monty, to check contributions, it is still missing the name of the subdir in path, so if i click on link - i get 404 eror
    imho i checked all the rest of the files (of monty's) and did not find where the error is.

    since u re still loooking 4 testers ...
    :P

    tyvm in advance and for all the work u did till now

  18. macgruder
    Member
    Posted 16 years ago #

    Hey Gape2,
    I'll take a look to see if I can update that.

    Ovidiu
    Ah yes, I didn't notice that it was just trackbacks. Do you want to send me the database dump and I'll take a look.

  19. gape2
    Member
    Posted 16 years ago #

    one more thing
    maybe i shold make this setting elsewhere but

    when new user aplies he/she gets a checkmark
    Verification:
    Please verify that you are a legitimate user.
    Please check here to confirm you are a real user.:

    user checks the thing, but gets the same page again
    they check it few times and i have to revise them - same user - but more entries
    imho
    when user checks the box, a mesage should apear that someone needs to aprove the user and blog
    or similar

    now i see
    after i aproved the user in monty
    and user clicked again (the checkbox and the button to create blog)
    the message apeared
    and the mail got to the user
    clicked the link and the blog is up and runing

    this happens only in early stages of learning?

    one more thing
    seems like chaptcha is not working - no picture ... or is this chapta diferent ... just a checkmark (when installing i had to remove the checkmark - couse the squre below was dpisplaying BROKEN)?

  20. macgruder
    Member
    Posted 16 years ago #

    This stuff only happens in the early stages of learning. Once Monty has learnt then you'll find this happens:

    Spammers 95 - 99% spam score
    Good users: 0% - 5%
    Occasional: 10%- 90% which you'll need to confirm.

    If a user gets more than 90% then even if he passes the captcha/check-test the message will not appear unless the blog owner over-rides it.

    In the early stage Monty is still learning so he tends to get more messages in the 30% - 70% range but these will soon disappear.

    Don't worry about there not being a captcha. The captcha is not necessary really. Spammers get a score of over 90% anyway, and the spam has to get checked by you whether they pass or not:

    For example here are my stats:

    Spam Stopped:2210 [scored over 90%]

    Classified as Unknown
    Spam:6 [scored between 10% - 90% but spam]
    Ham:4 [scored between 10% - 90% but good]

    Errors:
    0

    In addition to this, Monty has blocked 12738 repeat spammers (through the IP blocked system)

    This means for comment spam, it's approx
    10 checks in 15000 spams
    -> 1:1500
    99.94% of spams are stopped without you needing to check anything.

    Monty is less effective with signups as there is less data, but I'm working on an option to allow you to ignore signups until they actually post a message.

  21. gape2
    Member
    Posted 16 years ago #

    ty for the info

  22. Ovidiu
    Member
    Posted 16 years ago #

    sorry for being a nuisance, but I couldn't write you an email about this so I'll ask again here:

    how is your single user version getting along? Is it in a stage where you could already use some beta testers? I really wanna jump off the last anti spam solution I am using..

  23. jack_sparrow
    Member
    Posted 16 years ago #

    @macgruder

    We have just downloaded and installed this excellent piece of art in the official Moblog site at " moblog dawt mobi " and it seems to be working fine .

    We have a feature where a user can post directly to his/her blog from his/her mobile phone by sending a post or a pic as an attachment. As of now people or spammers do not use the luxusry of a gprs connection to post spams ;) But we would be glad to make such posts also pass through Monty ... we have a php script doing the hard word of posting from mails. Please advice how we can include such posts to pass through Monty.

    Best.

    Jack.

  24. macgruder
    Member
    Posted 16 years ago #

    @ovi
    Hey sorry for the late reply. The single user version will definitely be finished this month. I'm overwhelmed at work right now, but I'll deal with it as soon as the chaos is done.

    @jack
    If you could send me an example post (especially I need to see the headers) then I can add such a feature to a future version. My email is somewhere in this thread! If you need help with grabbing the headers let me know.

    @everyone
    One issue I've noticed is that tracking at the signup phase can become an inconvenience. Because Monty tends to be a bit conservative in judging signups - he doesn't have much info to go on. I'll will be trying to improve this issue.
    Also, when tracking splogs Monty should group by user. I'll add this too.

  25. Ovidiu
    Member
    Posted 16 years ago #

    my monty now says:

    Montyspam will expire in 14 days

    :-( makes me sad, so what do I do? re-download?

  26. macgruder
    Member
    Posted 16 years ago #

    Don't worry about that, I'll extend this by a month or two. Just download in about 10 days (not yet though!)

  27. OutdoorsBlogger
    Member
    Posted 16 years ago #

    I don't mean to be an alarmist, but I re-downloaded & uploaded all the new MontySpam files as instructed, but the expiration is still listed as tomorrow.

    By the way, this plugin ROCKS.

  28. macgruder
    Member
    Posted 16 years ago #

    Hey,
    I updated it just a few hours ago. Could you try again? Let me know if it still doesn't update for you!
    And email me at
    montyspamnet
    at
    gmail * com
    if you have problems.

    Whoa, I see Monty has blocked 25,000 attempts on your site. Now that's good news :-)

  29. kdesilva
    Member
    Posted 16 years ago #

    Just uploaded it, but doesn't show under site admin ...?

  30. SteveAtty
    Member
    Posted 16 years ago #

    Seems to be working fine here on a subdirectory install. I think the footer stats might be a bit wrong but.....

About this Topic

  • Started 17 years ago by macgruder
  • Latest reply from anointed