[SAC] [OSGeo] #2671: Spam submissions to GeoforAll lab form

#2671: Spam submissions to GeoforAll lab form
-------------------------+-----------------------
Reporter: vrautenbach | Owner: vicky@…
     Type: task | Status: new
Priority: critical | Milestone: Unplanned
Component: WebSite | Keywords:
-------------------------+-----------------------
Over the last hour, there has been more than 600 lab submissions
(submissions are coming in per minute) via the form on the website. These
are all spam, seems to be a bot. Are you able to assist in either blocking
the bot or shutting down the form temporarily?

Thank you in advance.

--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/2671&gt;
OSGeo <Gter - OSGeo;
OSGeo committee and general foundation issue tracker.

#2671: Spam submissions to GeoforAll lab form
-------------------------+------------------------
Reporter: vrautenbach | Owner: vicky@…
     Type: task | Status: new
Priority: critical | Milestone: Unplanned
Component: WebSite | Resolution:
Keywords: |
-------------------------+------------------------

Comment (by vrautenbach):

I had a look at the settings and adjusted the max entries setting. See
below. This has stopped the current attack. But the form is now
temporarily closed, which is OK for a short period.

I would appreciate any advise or help to resolve this.

--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/2671#comment:1&gt;
OSGeo <https://osgeo.org/&gt;
OSGeo committee and general foundation issue tracker.

#2671: Spam submissions to GeoforAll lab form
-------------------------+------------------------
Reporter: vrautenbach | Owner: vicky@…
     Type: task | Status: new
Priority: critical | Milestone: Unplanned
Component: WebSite | Resolution:
Keywords: |
-------------------------+------------------------

Comment (by robe):

At a glance it doesn't look like we have any anti-spam tools in place for
forms.

We should review which ones would work best and have acceptable licensing
terms for us.
There are at a glance over 10.

1. Gravity Forms Zero spam: https://www.osgeo.org/wp-admin/plugin-
install.php?tab=plugin-information&plugin=gravity-forms-zero-spam

Doesn't have that many reviews but does have many installations and since
we are using Gravity Forms for our forms, might play well with what we
have.

2. Akismet Spam Protection - https://www.osgeo.org/wp-admin/plugin-
install.php?tab=plugin-information&plugin=akismet - many installations and
I think used by more than wordpress. Not sure how well it plays with
gravity Forms

Several more - https://www.osgeo.org/wp-admin/plugin-
install.php?s=spam%20form&tab=search&type=term

but some are tied to a different form plugin so won't work for us or more
of a firewall feature.

--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/2671#comment:2&gt;
OSGeo <https://osgeo.org/&gt;
OSGeo committee and general foundation issue tracker.

#2671: Spam submissions to GeoforAll lab form
-------------------------+------------------------
Reporter: vrautenbach | Owner: vicky@…
     Type: task | Status: new
Priority: critical | Milestone: Unplanned
Component: WebSite | Resolution:
Keywords: |
-------------------------+------------------------
Comment (by cvvergara):

Maybe only people with ldap account can access the form
--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/2671#comment:3&gt;
OSGeo <https://osgeo.org/&gt;
OSGeo committee and general foundation issue tracker.

#2671: Spam submissions to GeoforAll lab form
-------------------------+------------------------
Reporter: vrautenbach | Owner: vicky@…
     Type: task | Status: new
Priority: critical | Milestone: Unplanned
Component: WebSite | Resolution:
Keywords: |
-------------------------+------------------------
Comment (by cvvergara):

This is comment is a test for discourse
--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/2671#comment:4&gt;
OSGeo <https://osgeo.org/&gt;
OSGeo committee and general foundation issue tracker.