Joomla! Discussion Forums



It is currently Wed Nov 25, 2009 4:06 pm (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 3 posts ] 
Author Message
Posted: Wed Mar 12, 2008 8:44 pm 
Joomla! Intern
Joomla! Intern
Offline

Joined: Tue Apr 04, 2006 10:58 pm
Posts: 58
A few days back, my site was hit by spammers looking to post spam on my commenting system. JomComment. My server admins blocked the offending IP addresses. Now, I'm having issues with my nightly mySQL dump. Further research shows that I have what appears to be 5 million rows of data in the jos_messages table.

Q: What exactly should reside in the jos_messages table? How can I rectify the situation?

Q: Is there a way to help prevent this type of attack?


Thanks in advance.
Chris


Top
  E-mail  
 
Posted: Thu Mar 13, 2008 5:15 am 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Sat Oct 21, 2006 10:20 pm
Posts: 730
Location: Wisconsin USA
Um, messages. I know, that didn't help much.

That is what one of mine contains, another sites table is empty. They are messages that look like when I was testing submitting articles from the front end. I could be wrong and I would make a successful backup of the table before doing anything just in case. I would then use phpMyadmin to empty the table.

_________________
Phil


Top
   
 
Posted: Fri Mar 14, 2008 2:41 pm 
Joomla! Intern
Joomla! Intern
Offline

Joined: Wed Nov 28, 2007 10:16 pm
Posts: 82
Yeah, use phpMyAdmin to empty the table.

Then I would install sh404SEF. You might have some hiccups with your website after installing it (especially if you already use another 3rd party SEF program), but it includes a great security component that works with Project Honey Pot.

Two reasons why you should use sh404sef:

1) Anti-flood control.

sh404sef has a setting that will allow you to activate anti-flood control, which is essentially what happened to you. You can also activate it only for forms (like messages), so that people wont flood your database.

2)Project Honey Pot.

While Project Honey Pot is primarily intended to stop email harvesters from grabbing emails off of your webpage, it also will set up "traps" for people who continually attempt to access your webpage over and over again (as would be the case with a spammer). If all the spammer is only running a script (and isn't watching it run), eventually a "Trap" page will pop up that will be easy for a human being to spot and evade, but a bot might fall into the trap (hence the name, "Honey Pot). If it does, the IP address will be blacklisted and the spammer will no longer be able to access the page. The additional benefit of this is that his IP address will be broadcasted to everyone that uses Honey Pot, so he won't be able to spam any other websites that are members of the HoneyPot anti-spam coallition.

Hope that helps.

_________________
It's really easy to make things complicated- the trick is to make them simple.
http://guitarhangar.com - webmaster
http://www.amediacreative.com - programmer/security (they didn't make the above site)


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

Quick reply

 



Who is online

Users browsing this forum: Google Adsense [Bot] and 22 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group