Note: You are currently viewing documentation for Moodle 1.9. Up-to-date documentation for the latest stable version is available here: Reducing spam in Moodle.

Reducing spam in Moodle: Difference between revisions

From MoodleDocs
No edit summary
No edit summary
 
(29 intermediate revisions by 4 users not shown)
Line 1: Line 1:
==Strongly recommended==
==Background==


* Make sure that 'register_globals' is switched off in your PHP settings (this is the default). Otherwise your site may be at risk of being cracked, allowing spammers to modify your scripts and insert spam wherever they like.
What exactly is the problem? Read [[Why porn spam has been appearing in Moodle sites|why porn spam has been appearing in Moodle sites]].


==Further suggestions==
==The best thing to do==


* Keep "Force users to login for profiles" enabled in ''Administration > Security > [[Site policies]]'' to keep anonymous visitors and search engines away from user profiles.
Upgrade to the latest 1.9.x or 1.8.x and use the [[Security_overview| Security report]] to analyse your configuration.  Then do all the things it tells you.
* Keep "Profiles for enrolled users only" enabled in ''Administration > Security > [[Site policies]]'' (in Moodle 1.6.9, 1.7.7, 1.8.8 and in 1.9.4 onwards).
* Keep self registration disabled in ''Administration > Users > Authentication > [[Manage authentication]]'' common settings.
* Consider the [[Risks|spam risks]] involved in allowing certain capabilities, such as [[Capabilities/mod/forum:replypost| replying to forum posts]], for visitor accounts.


If [[Email-based self-registration]] is used for self registration:
Note this is not strictly necessary to combat just profile spam (see the critical settings below) but it will protect you against dozens of other known security vulnerabilities.
* Add spam protection to the new account form by enabling reCAPTCHA (in Moodle 1.9.1 onwards) - see [[Security FAQ]] for details of how to do so. ReCAPTCHA is quite effective against '''most''' automated spambots, but will not foil human spammers at all.
* Limit self registration to particular email domains with the allowed email domains setting or deny email addresses from particular domains, such as mailinator.com and temporaryinbox.com, with the denied email domains setting. Both settings are in ''Administration > Users > Authentication > [[Manage authentication]]'' common settings.
* Consider only enabling self registration for a short period of time to allow users to create accounts, and then later disable it.
* Keep "Email change confirmation" enabled in ''Administration > Security > [[Site policies]]'' (in Moodle 1.8.6 and in 1.9.2 onwards).


==Cleaning up profiles==
==Critical settings==
If your site was open and you have a spam problem then here are some things you can do to clean up the profiles:
 
   
# Make sure that 'register_globals' is switched '''off''' in your PHP settings (this is the default).  Otherwise your site may be at risk of being cracked, allowing spammers to modify your scripts and insert spam wherever they like.
* Browse your user list looking for patterns to detect users who need to be deleted.  For example, spammers might have chosen a country that none of your real users has.
# Keep "Force users to login for profiles" '''enabled''' in ''Administration > Security > [[Site policies]]'' to prevent anonymous visitors and search engines from seeing user profiles.
* Use the "Bulk user actions" tool under Admin > Users > Accounts to find all these users and delete them.  Note that versions prior to 1.6.7, 1.7.5, 1.8.6, 1.9.2 had a [http://moodle.org/mod/forum/discuss.php?d=101407 bug] that did not properly hide deleted user profiles, so make sure you have upgraded to a later version if you want to keep user profiles visible to the world.
# Keep "Profiles for enrolled users only" '''enabled''' in ''Administration > Security > [[Site policies]]'' (in Moodle 1.6.9, 1.7.7, 1.8.8 and in 1.9.4 onwards).  This will prevent affected profiles from being visible even to other users on the site.
* '''Spam Cleaner''' is a simple script to help you delete spammer accounts more easily:
 
** Download:  [http://cvs.moodle.org/contrib/tools/spamcleaner/spamcleaner.php?view=co spamcleaner.php]
==Strong recommendations==
** Feedback/discussion:  issue MDL-17144 in the Moodle tracker
 
*Make sure you '''upgrade your site often'''.  Recent versions of Moodle have new fixes and warnings that will help you avoid security issues.
*Consider the [[Risks|spam risks]] involved in allowing certain capabilities for visitor accounts, such as [[Capabilities/mod/forum:replypost| replying to forum posts]] or posting to blogs.
 
==Allowing self-registration==
 
If you don't need it, please keep self-registration '''disabled''' (it's the default) in ''Administration > Users > Authentication > [[Manage authentication]]'' common settings. 
 
If you '''must''' use [[Email-based self-registration]] to allow people to make their own accounts then:
# Add spam protection to the new account form by enabling reCAPTCHA (in Moodle 1.9.1 onwards) - see [[Security FAQ]] for details of how to do so. ReCAPTCHA is quite effective against '''most''' automated spambots, but will not foil human spammers at all.
# Limit self registration to particular email domains with the allowed email domains setting or deny email addresses from particular domains, such as mailinator.com and temporaryinbox.com, with the denied email domains setting. Both settings are in ''Administration > Users > Authentication > [[Manage authentication]]'' common settings.
# Consider only enabling self registration for a short period of time to allow users to create accounts, and then later disable it.
# Keep "Email change confirmation" enabled in ''Administration > Security > [[Site policies]]'' (in Moodle 1.8.6 and in 1.9.2 onwards).
 
==Cleaning up spam==
 
If your site was open in the past and you have a spam problem then here are some things you can do to clean up the profiles:
 
# Use our [[Spam cleaner]] report, available in all stable versions of Moodle released in February 2008 or later. Alternatively you can [http://cvs.moodle.org/contrib/tools/spamcleaner/spamcleaner.php?view=co download a version of the spam cleaner script] and run it in your existing Moodle site.
# Browse your user list looking for patterns to detect users who need to be deleted.  For example, spammers might have chosen a country that none of your real users has.
# Use the [[Bulk user actions]] tool under ''Administration > Users > Accounts'' to find all these users and delete them.  Note that versions prior to 1.6.7, 1.7.5, 1.8.6, 1.9.2 had a [http://moodle.org/mod/forum/discuss.php?d=101407 bug] that did not properly hide deleted user profiles, so make sure you have upgraded to a later version if you want to keep user profiles visible to the world.
 
== See also ==
* [[Security FAQ]]
* [[Hacked site recovery]]


[[Category:Security]]
[[Category:Security]]


[[es:Minimizar_el_spam_en_Moodle]]
[[eu:Spama_murriztu_Moodle-n]]
[[eu:Spama_murriztu_Moodle-n]]
[[fr:Réduire le spam]]
[[fr:Réduire le spam]]
[[ja:Moodleでスパムを減らすには]]
[[ja:Moodleでスパムを減らすには]]
[[de:Spam reduzieren in Moodle]]

Latest revision as of 01:51, 12 September 2009

Background

What exactly is the problem? Read why porn spam has been appearing in Moodle sites.

The best thing to do

Upgrade to the latest 1.9.x or 1.8.x and use the Security report to analyse your configuration. Then do all the things it tells you.

Note this is not strictly necessary to combat just profile spam (see the critical settings below) but it will protect you against dozens of other known security vulnerabilities.

Critical settings

  1. Make sure that 'register_globals' is switched off in your PHP settings (this is the default). Otherwise your site may be at risk of being cracked, allowing spammers to modify your scripts and insert spam wherever they like.
  2. Keep "Force users to login for profiles" enabled in Administration > Security > Site policies to prevent anonymous visitors and search engines from seeing user profiles.
  3. Keep "Profiles for enrolled users only" enabled in Administration > Security > Site policies (in Moodle 1.6.9, 1.7.7, 1.8.8 and in 1.9.4 onwards). This will prevent affected profiles from being visible even to other users on the site.

Strong recommendations

  • Make sure you upgrade your site often. Recent versions of Moodle have new fixes and warnings that will help you avoid security issues.
  • Consider the spam risks involved in allowing certain capabilities for visitor accounts, such as replying to forum posts or posting to blogs.

Allowing self-registration

If you don't need it, please keep self-registration disabled (it's the default) in Administration > Users > Authentication > Manage authentication common settings.

If you must use Email-based self-registration to allow people to make their own accounts then:

  1. Add spam protection to the new account form by enabling reCAPTCHA (in Moodle 1.9.1 onwards) - see Security FAQ for details of how to do so. ReCAPTCHA is quite effective against most automated spambots, but will not foil human spammers at all.
  2. Limit self registration to particular email domains with the allowed email domains setting or deny email addresses from particular domains, such as mailinator.com and temporaryinbox.com, with the denied email domains setting. Both settings are in Administration > Users > Authentication > Manage authentication common settings.
  3. Consider only enabling self registration for a short period of time to allow users to create accounts, and then later disable it.
  4. Keep "Email change confirmation" enabled in Administration > Security > Site policies (in Moodle 1.8.6 and in 1.9.2 onwards).

Cleaning up spam

If your site was open in the past and you have a spam problem then here are some things you can do to clean up the profiles:

  1. Use our Spam cleaner report, available in all stable versions of Moodle released in February 2008 or later. Alternatively you can download a version of the spam cleaner script and run it in your existing Moodle site.
  2. Browse your user list looking for patterns to detect users who need to be deleted. For example, spammers might have chosen a country that none of your real users has.
  3. Use the Bulk user actions tool under Administration > Users > Accounts to find all these users and delete them. Note that versions prior to 1.6.7, 1.7.5, 1.8.6, 1.9.2 had a bug that did not properly hide deleted user profiles, so make sure you have upgraded to a later version if you want to keep user profiles visible to the world.

See also