Register Members List Search Today's Posts Mark Forums Read

Reply
 
Mod Options
vB Bad Behavior Details »»
vB Bad Behavior
Mod Version: 1.0.13, by Eric (Coder/Designer) Eric is offline
Developer Last Online: Jul 2014 I like it Show Printable Version Email this Page

vB Version: 3.8.x Rating: (13 votes - 5.00 average) Installs: 83
Released: 05 Apr 2011 Last Update: 23 Apr 2013 Downloads: 391
Supported DB Changes Uses Plugins Additional Files Re-usable Code Translations External Content  

/**
* vB Bad Behavior is free software; you can redistribute it and/or modify it under
* the terms of the GNU Lesser General Public License as published by the Free
* Software Foundation; either version 3 of the License, or (at your option) any
* later version.
*
* This program is distributed in the hope that it will be useful, but WITHOUT ANY
* WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
* PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
*/


What is vB Bad Behavior?
This is an integration of the Bad Behavior software with vBulletin.

What is Bad Behavior?
Bad Behavior is a PHP-based solution for blocking link spam and the robots which deliver it. Bad Behavior complements other link spam solutions by acting as a gatekeeper, preventing spammers from ever delivering their junk, and in many cases, from ever reading your site in the first place. This keeps your site's load down, makes your site logs cleaner, and can help prevent denial of service conditions caused by spammers.

Visit http://bad-behavior.ioerror.us/ for more.

Features
For more information on the features of Bad Behavior (and subsequently this mod) please go to Bad Behavior's site:

http://bad-behavior.ioerror.us/documentation/benefits/

For features related to the mod itself, please take a look at the screenshots.

This mod should work with the entire 3.x series (well, beginning with 3.5), but it's only been tested on 3.8.x. I'm not sure if this works on vB 4.x yet, as I've not tested it - but if you try it out, let me know!

Installation
1. Extract the contents of the zip file.
2. Upload the contents of the `upload` folder to your forum root.
3. Enter your AdminCP and go to Plugins & Products > Manage Products > [Add/Import Product]
4. Import the product using the `product-vb_badbehavior.xml` file.
5. Configure the mod in AdminCP -> vBulletin Options -> vBulletin Options -> vB Bad Behavior Options

Upgrading

vB Bad Behavior
In many cases, all you'll need to do to upgrade is follow the installation instructions above.

The only difference, will be you'll need to allow the files to overwrite. Also, when re-importing the product file, you'll need to set "Allow Overwrite" to "Yes".

Bad Behavior
Bad Behavior's files are at `/includes/bad-behavior/`. If you wish to update manually go to:

http://bad-behavior.ioerror.us/download/

And download the latest development version. Extract the zip, and upload the contents of `bad-behavior` to `/includes/bad-behavior/` allowing the files to overwrite.

Versions
The current version of Bad Behavior this mod is using is: v2.2.14
The current version of Bad Behavior (development) is: v2.2.14

Changelog
Version 1.0.13, 04/23/2013
  • Bad Behavior upgraded to 2.2.14

Version 1.0.12, 12/21/2012 -- Released: 02/05/2013
  • Bad Behavior upgraded to 2.2.13
  • Added some more ranges to whitelist.ini

Version 1.0.10, 09/09/2012
  • Bad Behavior upgraded to 2.2.10

Version 1.0.9, 06/17/2012
  • Bad Behavior upgraded to 2.2.7

Version 1.0.8, 06/12/2012
  • Bad Behavior upgraded to 2.2.6
  • New Setting: EU Cookie

Version 1.0.7, 05/04/2012
  • Bad Behavior upgraded to 2.2.3
  • Cron/Scheduled Task for automatic log pruning added.

Version 1.0.6, 01/04/2012
  • Bad Behavior upgraded to 2.1.15

Version 1.0.5, 05/26/2011
  • Added option for bypassing users/members.
  • If the visitor is a user, and is in usergroup 5, 6, or 7 (admin/mod/super mod) - Bad Behavior is bypassed.
  • Modified bad-behavior core to check for Google Web Preview
    • file edited: /includes/bad-behavior/core.inc.php
  • Added a link beside the IP address in the log for WhoIs.

Version 1.0.4, 04/28/2011
  • Bad Behavior upgraded to 2.1.13 (fixes search engine block issues)
  • Added Paypal/Paypal IPN IP address to the whitelist.
  • Added payment gateway file names to the whitelist.

Version 1.0.3, 04/21/2011
  • Fix #1: Pruning log doesn't work.
  • Fix #3: POST more than two days after GET (added support for BB's javascript)
  • Fix #5: Cannot modify header information error (suppressed error in BB's function)
  • Implemented #6: Filter per key (new admincp option to list keys not to be shown in log)
  • Implemented #9: Show link to member profile (if userid is found in headers, link to profile)

Version 1.0.2, 04/10/2011
  • Updated /includes/functions_vb_badbehavior.php to:
    • disable Reverse Proxy if Reverse Proxy Addresses are empty
    • distinguish SQL queries using "SET", for example: SET @@session.wait_timeout = 90 - which is used by BB
    • set "offsite_forms" to false by default, as it's not really needed in vB IMHO, and it can cause problems with certain setups
    • cleaned up the bb2_read_settings() function and fixed a typo in one of the vbulletin options calls
  • Updated /includes/whitelist.ini to include the following GOOGLE ranges:
    • 74.125.0.0/16
    • 216.239.32.0/19
    • 209.85.128.0/17
    • 66.102.0.0/20
  • Updated /admincp/vb_badbehavior.php
    • Log pruning was pruning all logs, despite what was entered for number of days

Version 1.0.1, 04/06/2011
  • Bad Behavior upgraded to 2.1.12
  • Changed files:
    • /includes/bad-behavior/core.inc.php
    • /includes/bad-behavior/searchengine.inc.php
  • "Verbose" admin option now set to "No" by default.

Version 1.0.0, 04/05/2011
  • Initial release.


Screenshots
Screenshots can now be seen at: http://www.secondversion.com/images/vb/vb_badbehavior/

I was running out of room for attachments here on vB.org


Development

https://github.com/ericsizemore/vb_b...ree/master/vb3


Only those who "Mark As Installed" will receive support for this modification.

Download Now

Only licensed members can download files, Click Here for more information.

Show Your Support

  • To receive notifications regarding updates -> Click to Mark as Installed.
  • If you like this modification support the author by donating.
  • This modification may not be copied, reproduced or published elsewhere without author's permission.
Similar Mod
Mod Developer Type Replies Last Post
Project HoneyPot HTTP Blacklist Addon ( with Bad Behavior integration) TheSupportForum Modification Graveyard 51 09 Apr 2011 13:59
Bad Behavior Integration SemperFideles vBulletin 4.x Add-ons 45 06 Apr 2011 01:27

  #136  
Old 08 May 2011, 11:09
Eric's Avatar
Eric Eric is offline
 
Join Date: May 2006
Real name: Eric
Originally Posted by Trac
The user anonymous has been granted the permission TICKET_MODIFY.
You should be able to now.

And thanks for going into a little bit more detail on those for me

Originally Posted by Alfa1 View Post
I do not seem to have commenting or editing functionality on trac. So here goes:

Send registered member explanation how to resolve blacklisting
Yes, an email would be more effective than a PM.

Trace IP directly from the log.
In the log hotlink the IP of the user. The link should point to a whois for the user. For example /admincp/usertools.php?do=gethost&ip=xx.xx.xx.xx
Or a better whois service like http://who.is/whois-ip/ip-address/xx.xx.xx.xx/

Alert the admin which members have been blocked by BB and why.

Such notification should be sent max once per X days and should list all blocked members since the last notification.
It would be useful to include some additional information like join date, post count and usergroup of the member. This makes it easier to see if the user is a legitimate user.
__________________
My modifications

Please do not contact me for support via PM or E-Mail unless I've asked you to do so. Otherwise, your message will be ignored/deleted.
Reply With Quote
  #137  
Old 08 May 2011, 11:32
Simon Lloyd's Avatar
Simon Lloyd Simon Lloyd is offline
 
Join Date: Aug 2008
Real name: Simon
Eric, as always, really appreciate the reply, this user is one of my more valuable ones so need to get this resolved. I have asked them to clear their cookies next time they log in, however this is happening to them from 3 different machines, this person is one of two actual members to be caught up although there are many "users awaiting confirmation" getting caught although i can't decipher how many of these are genuine or not without going through the many thousands of entries one by one and checking their IP's against Project Honeypot.

I do appreciate everything you are trying to do to resolve this.
__________________
Kind regards,
Simon Microsoft Office Help
My Mods: Find my modifications here
Please do not pm me for support unless i have invited you to!
Reply With Quote
  #138  
Old 08 May 2011, 13:01
Alfa1's Avatar
Alfa1 Alfa1 is offline
 
Join Date: Dec 2005
Originally Posted by Eric View Post
It's possible they are picked up as spiders visited before BB is ran.
I use Paul M's Track Guest Visits to monitor spiders.

Originally Posted by Eric View Post
You should be able to now.

And thanks for going into a little bit more detail on those for me
Could you give the user Alfa1 permission? I have an account at trac.

Some brainstorming:
An important factor in regards to bots being malicious or not, is if they respect robots.txt or not. If I want to block a bot, the first thing I do is disallow it in robots.txt
If after a week I still find it on my site (and therefore the bot has not respected robots.txt), then I blacklist the bot in BB.

I wonder if it would be a good idea to automatically blacklist bots that disrespect robots.txt ?


Does anyone (especially error10) know if the spiderlist.xml provided by Mosh is complete enough for the purposes of keeping an eye on malicious bots?
See: http://www.wolfshead-solutions.com/display-spiders
__________________
How to keep your board from getting blacklisted as a spammer
The vBulletin Add-on Directory
Block spam bots, content scrapers & malicious bots with vb Bad Behavior: save bandwidth costs and server resources.
Reply With Quote
  #139  
Old 09 May 2011, 06:08
Simon Lloyd's Avatar
Simon Lloyd Simon Lloyd is offline
 
Join Date: Aug 2008
Real name: Simon
Hi Eric, an update on the blocked users, it seems that they are getting as far as the login, they get the vb welcome message on logon, nothing at all from BB but after the welcome screen they are shown as though they have not logged on i.e username and password boxes remain blank and they remain in the "Unregistered/Not logged on" usergroup, however BB shows the results i have previously posted?
__________________
Kind regards,
Simon Microsoft Office Help
My Mods: Find my modifications here
Please do not pm me for support unless i have invited you to!
Reply With Quote
  #140  
Old 09 May 2011, 06:32
Eric's Avatar
Eric Eric is offline
 
Join Date: May 2006
Real name: Eric
Originally Posted by Simon Lloyd View Post
Hi Eric, an update on the blocked users, it seems that they are getting as far as the login, they get the vb welcome message on logon, nothing at all from BB but after the welcome screen they are shown as though they have not logged on i.e username and password boxes remain blank and they remain in the "Unregistered/Not logged on" usergroup, however BB shows the results i have previously posted?
Hmm. I'll be releasing an update soon that will allow you to skip members in the BB processing. If you want to try it out (** UNTESTED AS OF YET **) http://trac.assembla.com/vb-bad-beha...adbehavior.xml
__________________
My modifications

Please do not contact me for support via PM or E-Mail unless I've asked you to do so. Otherwise, your message will be ignored/deleted.
Reply With Quote
  #141  
Old 09 May 2011, 08:17
Simon Lloyd's Avatar
Simon Lloyd Simon Lloyd is offline
 
Join Date: Aug 2008
Real name: Simon
Thanks Eric, installed, i have cleared my logs and will download them as a csv after around 5 days, you're quite welcome to have it for your analysis.
__________________
Kind regards,
Simon Microsoft Office Help
My Mods: Find my modifications here
Please do not pm me for support unless i have invited you to!
Reply With Quote
  #142  
Old 09 May 2011, 08:48
Simon Lloyd's Avatar
Simon Lloyd Simon Lloyd is offline
 
Join Date: Aug 2008
Real name: Simon
Eric, the user has reported back:
Tried from home computer. Different result. Got the following:
Unable to add cookies, header already sent.
File: /home/thecodec/public_html/forumz/global.php(1091) : eval()'d code
Line: 95
__________________
Kind regards,
Simon Microsoft Office Help
My Mods: Find my modifications here
Please do not pm me for support unless i have invited you to!
Reply With Quote
  #143  
Old 09 May 2011, 08:52
Simon Lloyd's Avatar
Simon Lloyd Simon Lloyd is offline
 
Join Date: Aug 2008
Real name: Simon
In fact just noticed that that is showing all the time at the top of the forum so i have reverted back to bb1.0.4
__________________
Kind regards,
Simon Microsoft Office Help
My Mods: Find my modifications here
Please do not pm me for support unless i have invited you to!
Reply With Quote
  #144  
Old 09 May 2011, 13:19
tpearl5's Avatar
tpearl5 tpearl5 is offline
 
Join Date: Nov 2001
Real name: John
While one of my moderators was removing a thread she got this vbulletin message on login.php?do=login:

"Your submission could not be processed because a security token was missing"

Last edited by tpearl5 : 09 May 2011 at 13:35.
Reply With Quote
  #145  
Old 11 May 2011, 17:03
Simon Lloyd's Avatar
Simon Lloyd Simon Lloyd is offline
 
Join Date: Aug 2008
Real name: Simon
Hi Eric, i still cannot get your new beta version working so am running the previous update, hwoever we have finally got to the bottom of that valued user not being able to log on with the help firstly of Trend Micro HouseCall free online scan found a lot of malware on her PC, it had also crippled her useragent string which we discovered by getting to go here http://user-agents.my-addr.com/user_...gent_types.php and see what it said her useragent was whilst there, now for some reason in the forum here useragent showed as
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.6; .NET CLR 1.1.4322; .NET CLR
but on visiting that site its showed
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.6; .NET CLR 1.1.4322; .NET CLR 2.0.50727;http://www.hyperpromote.com/tags/sho...code%3D666098; BVGDT=21600; pBVPU=yes; InfoPath.3; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
so there was much more to the string and it had been corrupted, even though i was whitelisting all her IPs it was still denying her. Now we know what the issue is we need to find out how to fix her UA string.

Thanks for your help
__________________
Kind regards,
Simon Microsoft Office Help
My Mods: Find my modifications here
Please do not pm me for support unless i have invited you to!
Reply With Quote
  #146  
Old 16 May 2011, 08:04
Eric's Avatar
Eric Eric is offline
 
Join Date: May 2006
Real name: Eric
Originally Posted by Simon Lloyd View Post
Eric, the user has reported back:
Originally Posted by Simon Lloyd View Post
In fact just noticed that that is showing all the time at the top of the forum so i have reverted back to bb1.0.4
Argh, looks like a rogue ')' in the plugin code, will fix.

Originally Posted by tpearl5 View Post
While one of my moderators was removing a thread she got this vbulletin message on login.php?do=login:

"Your submission could not be processed because a security token was missing"
This mod doesn't mess with the security token, so I am not sure why they would get that error.

Originally Posted by Simon Lloyd View Post
Hi Eric, i still cannot get your new beta version working so am running the previous update, hwoever we have finally got to the bottom of that valued user not being able to log on with the help firstly of Trend Micro HouseCall free online scan found a lot of malware on her PC, it had also crippled her useragent string which we discovered by getting to go here http://user-agents.my-addr.com/user_...gent_types.php and see what it said her useragent was whilst there, now for some reason in the forum here useragent showed as but on visiting that site its showed so there was much more to the string and it had been corrupted, even though i was whitelisting all her IPs it was still denying her. Now we know what the issue is we need to find out how to fix her UA string.

Thanks for your help
Ahh, that explains it. For MSIE, I think you can fix the user agent by editing the registry. I'll look into that for you.
__________________
My modifications

Please do not contact me for support via PM or E-Mail unless I've asked you to do so. Otherwise, your message will be ignored/deleted.
Reply With Quote
  #147  
Old 16 May 2011, 08:08
Eric's Avatar
Eric Eric is offline
 
Join Date: May 2006
Real name: Eric
Originally Posted by Alfa1 View Post
I use Paul M's Track Guest Visits to monitor spiders.


Could you give the user Alfa1 permission? I have an account at trac.

Some brainstorming:
An important factor in regards to bots being malicious or not, is if they respect robots.txt or not. If I want to block a bot, the first thing I do is disallow it in robots.txt
If after a week I still find it on my site (and therefore the bot has not respected robots.txt), then I blacklist the bot in BB.

I wonder if it would be a good idea to automatically blacklist bots that disrespect robots.txt ?


Does anyone (especially error10) know if the spiderlist.xml provided by Mosh is complete enough for the purposes of keeping an eye on malicious bots?
See: http://www.wolfshead-solutions.com/display-spiders
Did you register? I don't think assembla allows registration, didn't see any accounts. Anonymous and registered users have the permission now either way though.

As far as blocking bots who disrespect robots.txt - I have an idea for that.
__________________
My modifications

Please do not contact me for support via PM or E-Mail unless I've asked you to do so. Otherwise, your message will be ignored/deleted.
Reply With Quote
  #148  
Old 16 May 2011, 08:12
Eric's Avatar
Eric Eric is offline
 
Join Date: May 2006
Real name: Eric
Originally Posted by Lee G View Post
Just checked my logs and another google bot got caught

User agent
Mozilla/5.0 (en-us) AppleWebKit/525.13 (KHTML, like Gecko; Google Web Preview) Version/3.1 Safari/525.13

ip
66.249.82.129

Full ip range
66.249.64.0/19

And another google ip range for google to whitelist
64.233.160.0/19

Bot from ip 64.233.172.18 got caught
Bad Behavior Core will need to be updated to work around this it looks like. It checks for "Googlebot", not just "Google". Will email error10
__________________
My modifications

Please do not contact me for support via PM or E-Mail unless I've asked you to do so. Otherwise, your message will be ignored/deleted.
Reply With Quote
  #149  
Old 16 May 2011, 23:00
Alfa1's Avatar
Alfa1 Alfa1 is offline
 
Join Date: Dec 2005
Originally Posted by Eric View Post
Did you register? I don't think assembla allows registration, didn't see any accounts. Anonymous and registered users have the permission now either way though.

As far as blocking bots who disrespect robots.txt - I have an idea for that.
Yes, I registered. I am afraid that I have permission to reopen and edit tickets. See: http://trac.assembla.com/vb-bad-behavior/ticket/4

Im glad that to see that 1.0.5 has Setting to make registered users bypass BB implemented.
__________________
How to keep your board from getting blacklisted as a spammer
The vBulletin Add-on Directory
Block spam bots, content scrapers & malicious bots with vb Bad Behavior: save bandwidth costs and server resources.
Reply With Quote
  #150  
Old 24 May 2011, 21:21
Lee G Lee G is offline
 
Join Date: Jun 2006
Real name: Lee
Hi Eric
Is there any news on the updates for this
Id the stop forum spam integration still going ahead or has that idea been shelved
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
Mod Options

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
Forum Jump


New To Site? Need Help?

All times are GMT. The time now is 23:24.

Layout Options | Width: Wide Color: