Announcement

  •  » Requests
  •  » Fighting spam? (user registration/comments/contact form)

#1 2023-02-03 16:10:50

matthys
Member
2014-04-02
188

Fighting spam? (user registration/comments/contact form)

Hello,

I wanted to start this topic as for me it seems to get a 'real' problem.
The last year I notice more and more spam from my Piwigo website.
I already disabled user registration, comments and moved to contact form.
For the contact form plugin I added the Google reCAPTCHA into the plugin.

I just wanted to know if there is anyone with the same issue and how you deal with it.
I was more thinking of a plugin solution, or core Piwigo solution, with anti spam solution.
Currently looking into Cloudflare Turnstile but there are of course others as well.
I know there is the "RV Akismet" plugin, but I have the feeling it's not really maintained.

PS .. I'm sorry if posted into the wrong topic, but I guess it's more like a request for a solution ....

Thanks,
Matthijs

Last edited by matthys (2023-02-03 16:12:13)

Offline

 

#2 2023-02-03 19:00:39

erAck
Only trying to help
2015-09-06
2032

Re: Fighting spam? (user registration/comments/contact form)

Even if unmaintained, RV Akismet only forwards all comment form input to Akismet and as long as their API works and answers the plugin should work. Don't know if it intercepts contact form as well. However, if it does then you should state so on your site (i.e. there'd be no privacy as everything would be forwarded including name and email and possibly IP).


Running Piwigo at https://erack.net/gallery/

Offline

 

#3 2023-02-03 22:19:44

matthys
Member
2014-04-02
188

Re: Fighting spam? (user registration/comments/contact form)

erAck wrote:

However, if it does then you should state so on your site (i.e. there'd be no privacy as everything would be forwarded including name and email and possibly IP).

Good point to mention. For the moment I moved from Google reCAPTCHA to hCaptcha and see if that will make a difference. I sure realize you cannot prevent 100%...

Offline

 

#4 2023-02-13 17:34:01

head_dunce
Member
2019-12-09
19

Re: Fighting spam? (user registration/comments/contact form)

Change your DNS
Once you move it, you can turn on "Bot Fight Mode" which will save you a lot of headaches
You'll also get the CDN for free

Offline

 

#5 2023-02-13 20:17:23

Katryne
Member
2016-12-03
369

Re: Fighting spam? (user registration/comments/contact form)

Did you try the plugin Stop Spammers ? https://piwigo.org/ext/extension_view.php?eid=721

For comments, I chose the validation settings. And I use the contact form plugin.

That's all I have to hold back spam. But my Piwigo sites are small ones.


http://photos.katrynou.fr/ v.14.1.0 https://album.chauvigne.info/ v.13.8.0
Système d'exploitation: Linux - Hébergeur 1&1-Ionos PHP: 8.0.28 - MySQL: 5.7.38
Bibliothèque graphique: External ImageMagick 6.9.10-23

Offline

 

#6 2023-02-13 23:07:34

erAck
Only trying to help
2015-09-06
2032

Re: Fighting spam? (user registration/comments/contact form)

head_dunce wrote:

Cloudflare

Bad advice. By using their DNS you hand control over access to your site to Cloudflare. The "Bot Fight Mode" will inject unsolvable captchas to Tor browser users. Their reverse proxy will learn about who interacts how with your site. Nothing is free. You pay with your and your visitors' data.


Running Piwigo at https://erack.net/gallery/

Offline

 

#7 2023-02-14 09:41:40

matthys
Member
2014-04-02
188

Re: Fighting spam? (user registration/comments/contact form)

Indeed, I do not want Cloudflare to control (all) my DNS traffic to my website. However it seems moving to hCaptcha made a huge difference. Maybe because I used Google reCAPTCHA in silent mode, where now there is a puzzle to solve. And the problem is that the contact form is filled by IA (bot).

To give you some statistic since 3 February until now (14 February):
Captchas served=236, solved=11, verified=9

And those 9 are only tests, so far no spam at all.
Before I got about 1 per 3 days ... :-(

Offline

 

#8 2023-02-18 09:35:48

Phil35
Member
France
2022-10-11
60

Re: Fighting spam? (user registration/comments/contact form)

My 2cts about DNS:
- I use in first position: my own DNS built with AD Guard (https://github.com/AdguardTeam/AdGuardH … /v0.107.24) on raspberry. Manual and Filters lists are perfectly handle by AD Guard
- in second position, in case of local DNS problem, I have setup for free Quad9 (https://www.quad9.net/) ie 9.9.9.9

as this is a piwigo for almost only family, registrations are required and handle by me :-)
Phil35


Piwigo 13.8 on production platform  raspberry pi 4 (os 11 (bullseye))
Piwigo 14.1 on test platform raspberry pi 4  (os 11 (bullseye))

Offline

 

#9 2023-02-18 13:49:49

matthys
Member
2014-04-02
188

Re: Fighting spam? (user registration/comments/contact form)

Phil35 wrote:

as this is a piwigo for almost only family, registrations are required and handle by me :-)
Phil35

So you do not have an email of contact form open to the internet?

Because for me it's public (everyone can access) but not register or make any comments.
But for questions or the use of my photo's, people (or bots) can use the contact form etc.

But happy how it's now .. I see a lot of traffic to my contact page, but no spam (for now).

Offline

 
  •  » Requests
  •  » Fighting spam? (user registration/comments/contact form)

Board footer

Powered by FluxBB

github twitter newsletter Donate Piwigo.org © 2002-2024 · Contact