Hey Aaron, I was just wondering if the spam pisses you off as much as it does me? I'd like to find that person that spammed every topic and ram my boot up their a**!! Are they all different people? Can you track IPs? Are there really that many people in this world who are looseriffic enough and have that much time on their hands? It really ticks me off! Thats all I have to say about that.
They are botnets running on machines all over the world. When people run insecure machines without an up to date AV (or any at all) then they get infected and begin spamming.
There's very little that can be done. Any method to prevent these bots from registering to the forum only lasts a few months. CAPTCHAs are now easy to decode, though they stop the dumber bots. There are a few more tricks that I can employ but I will try them out on the other forms on the site before I modify the (much more complicated) forum code.
I try to clean it out as quickly as possible, as well as delete the 5-10 spammer accounts created every day, but there are some days where I can't get to the forum.
It's not unique to the forum either. Every form on this site is spammed hundreds of times a day but I filter it out. I'm about to make a few more changes to the guestbook filters as well.
What a pain man! I don't understand most of that stuff.. I have a friend who hacks things like banks and security systems with his PSP... I don't like people like that! Atleast you do your best to stay on top of it though that is cool with me!
The spammers are motivated by money. They get referral fees and kickbacks from driving traffic to a site. Thus they have a reason to continue to develop their software.
In general though it's only unmaintained sites that have issues with spam.
That's a mod to PHPBB2 (interestingly, one of the most insecure forums ever written ;) ) so it's not too much use to me. This week I added a few minor mods to the forums code based on what I saw in the PHP mod. Specifically, this forum now denies known spam bots based on their user agent string (spammers are often too lazy to change this from the default). It seems to have helped.