Register Members List Search Today's Posts Mark Forums Read

Reply
 
Thread Tools
  #1  
Old 27 Dec 2016, 21:08
Snowhog's Avatar
Snowhog Snowhog is offline
 
Join Date: Oct 2011
Real name: Paul L
Hyperlink feature of editor being used to spam

Running vBulletin 4.2.3 Patch Level 2

The Basic and Enhanced Editor (we have the Enhanced Editor as the default when a user registers) has a Hyperlink button. We have been experiencing a number of (maybe the same person using different usernames) new registrations where the first post is responding to an existing post and 'almost' makes sense given the prior posts contents, but they always contain a hyperlink (the text varies) pointing to the same services website.

If I remember correctly, changing the default editor under User Registration Options > Default Registration Options > Options > Message Editor Interface to Do Not Show Editor Toolbar is the only way to prevent this from happening without the new member going into Settings > General Settings and changing the editor to either Standard or Enhanced.

Is there any way to make the Standard and Enhanced editor available as a function of Usergroups Promotion, forcing new registrations to use of the Basic editor only?
__________________
"It is a capital mistake to theorize in advance of the facts." - Sherlock Holmes
Kubuntu Forums . Net | ZB BLOCK | StopForumSpam
Reply With Quote
  #2  
Old 27 Dec 2016, 21:17
Seven Skins's Avatar
Seven Skins Seven Skins is offline
 
Join Date: Sep 2008
That will not make any difference they can still type manually ..

[URL]www.site.com[/URL]

However there is mod here which can stop users from posting links ..search for "url posting" or something similar.
Reply With Quote
  #3  
Old 27 Dec 2016, 21:21
Kane@airrifle's Avatar
Kane@airrifle Kane@airrifle is offline
 
Join Date: Jun 2011
Real name: Kane
http://www.vbulletin.org/forum/showthread.php?t=233979

--------------- Added 27 Dec 2016 at 21:23 ---------------

or, if it is the same url every time you can add it to your style RVM and change it to something arbitrary.
Reply With Quote
  #4  
Old 27 Dec 2016, 21:28
Snowhog's Avatar
Snowhog Snowhog is offline
 
Join Date: Oct 2011
Real name: Paul L
Originally Posted by Seven Skins View Post
That will not make any difference they can still type manually ..

[URL]www.site.com[/URL]
I don't think that is an issue for us, as we disallow use of BB code for all new registered users; they gain use of BB code when they get promoted (based on number of posts) into the next usergroup.
__________________
"It is a capital mistake to theorize in advance of the facts." - Sherlock Holmes
Kubuntu Forums . Net | ZB BLOCK | StopForumSpam
Reply With Quote
  #5  
Old 28 Dec 2016, 19:30
Dragonsys's Avatar
Dragonsys Dragonsys is offline
 
Join Date: Jan 2008
Real name: Eric
Originally Posted by Snowhog View Post
I don't think that is an issue for us, as we disallow use of BB code for all new registered users; they gain use of BB code when they get promoted (based on number of posts) into the next usergroup.
If they cannot use BBCode, how are they posting links?
Reply With Quote
  #6  
Old 28 Dec 2016, 20:26
Snowhog's Avatar
Snowhog Snowhog is offline
 
Join Date: Oct 2011
Real name: Paul L
Originally Posted by Dragonsys View Post
If they cannot use BBCode, how are they posting links?
Thru the Link button in the Editor.

Use of BB Code as Yes or No only exists in the Blog and Signature sections of Usergroup settings; it isn't in Post/Thread section. So, the Editor is the vector for spamming with hyperlinks.
__________________
"It is a capital mistake to theorize in advance of the facts." - Sherlock Holmes
Kubuntu Forums . Net | ZB BLOCK | StopForumSpam

Last edited by Snowhog; 28 Dec 2016 at 20:57.
Reply With Quote
  #7  
Old 28 Dec 2016, 20:51
Dragonsys's Avatar
Dragonsys Dragonsys is offline
 
Join Date: Jan 2008
Real name: Eric
Originally Posted by Snowhog View Post
Thru the Link button in the Editor.
which uses BBCode. If they cannot post BBCode, then the link button won't get around it, as that check is performed in POST

You might want to double check the usergroup permissions & the forum permissions, which they are posting to.
Reply With Quote
  #8  
Old 28 Dec 2016, 21:09
MarkFL's Avatar
MarkFL MarkFL is offline
 
Join Date: Feb 2014
Real name: Mark
If you wish to remove the link button from the toolbar, create a plugin hooked at "editor_construct" and use the Plugin PHP Code:


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

Replace "X, Y, Z" with the comma-delimited list of usergroupids of those groups for which you wish to remove the link button.
__________________
Former vBulletin.org Staff Member



Support for my products (as well as updates/new product publishing) has been moved to MHB - vBulletin Products and TAZ - Add-ons
Reply With Quote
  #9  
Old 28 Dec 2016, 21:29
Snowhog's Avatar
Snowhog Snowhog is offline
 
Join Date: Oct 2011
Real name: Paul L
I'm assuming that X,Y,Z simply means "a comma separated list of usergroup id's", and not simply "three different usergroup id's". Correct? What if I only want to remove the link for Registered Users (id: 2), the usergroup these spam posts are generated from? Would the array then take a single value?
__________________
"It is a capital mistake to theorize in advance of the facts." - Sherlock Holmes
Kubuntu Forums . Net | ZB BLOCK | StopForumSpam
Reply With Quote
  #10  
Old 28 Dec 2016, 21:34
MarkFL's Avatar
MarkFL MarkFL is offline
 
Join Date: Feb 2014
Real name: Mark
Yes, it you want just usergroup 2 then just put a 2 in the array, but for example if you wanted usergroups 2,3, and 8 then you would put 2, 3, 8 in there.
__________________
Former vBulletin.org Staff Member



Support for my products (as well as updates/new product publishing) has been moved to MHB - vBulletin Products and TAZ - Add-ons
Reply With Quote
  #11  
Old 28 Dec 2016, 21:45
Snowhog's Avatar
Snowhog Snowhog is offline
 
Join Date: Oct 2011
Real name: Paul L
Thank you.

Okay, created a test user. The default editor for all new registrants is the Enhanced Editor.

I logged out and logged in as the new user. Started a new Thread and the Link button is still in the editor and is functional. Previewing the post shows an active hyperlink.
__________________
"It is a capital mistake to theorize in advance of the facts." - Sherlock Holmes
Kubuntu Forums . Net | ZB BLOCK | StopForumSpam
Reply With Quote
  #12  
Old 28 Dec 2016, 21:54
MarkFL's Avatar
MarkFL MarkFL is offline
 
Join Date: Feb 2014
Real name: Mark
Originally Posted by Snowhog View Post
Thank you.

Okay, created a test user. The default editor for all new registrants is the Enhanced Editor.

I logged out and logged in as the new user. Started a new Thread and the Link button is still in the editor and is functional. Previewing the post shows an active hyperlink.
Odd, because it removes the "Link" button for me, whether I set the Standard or Enhanced editor. What code are using in the plugin?
__________________
Former vBulletin.org Staff Member



Support for my products (as well as updates/new product publishing) has been moved to MHB - vBulletin Products and TAZ - Add-ons
Reply With Quote
  #13  
Old 28 Dec 2016, 21:55
Snowhog's Avatar
Snowhog Snowhog is offline
 
Join Date: Oct 2011
Real name: Paul L

Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

__________________
"It is a capital mistake to theorize in advance of the facts." - Sherlock Holmes
Kubuntu Forums . Net | ZB BLOCK | StopForumSpam
Reply With Quote
  #14  
Old 28 Dec 2016, 22:02
MarkFL's Avatar
MarkFL MarkFL is offline
 
Join Date: Feb 2014
Real name: Mark
Are you certain your test user is a member of usergroup 2?

When you saved the plugin, did you make it active?
__________________
Former vBulletin.org Staff Member



Support for my products (as well as updates/new product publishing) has been moved to MHB - vBulletin Products and TAZ - Add-ons
Reply With Quote
  #15  
Old 28 Dec 2016, 22:04
Snowhog's Avatar
Snowhog Snowhog is offline
 
Join Date: Oct 2011
Real name: Paul L
Yes, the plugin is marked Active. The new user I created is in Primary Usergroup Registered User, which is usergroupid 2.

--------------- Added 28 Dec 2016 at 22:23 ---------------

What about using hook location editor_switch_wysiwyg_to_standard instead? What would the PHP code consist of for this for members of usergroupid 2?
__________________
"It is a capital mistake to theorize in advance of the facts." - Sherlock Holmes
Kubuntu Forums . Net | ZB BLOCK | StopForumSpam
Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
Anti-Spam Options [GlowHost] Spam-O-Matic - Spam Firewall stops forum spam GlowHost.com vBulletin 4.x Add-ons 3490 29 Jul 2019 20:11



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


New To Site? Need Help?

All times are GMT. The time now is 07:23.

Layout Options | Width: Wide Color: