Have to agree with you there on every point.
I was getting maybe 10 registrations a day. I took the forum down for a few days, hoping an upgrade from 1.2.22 to 1.3.4 would help solve spamming issues.

It didn't - and when I upgraded and switched back on - I had 10 reg's in about one hour.
It seems I'm targetted by manual spammers and I think there are teams of people in low-wage countries who are paid a pittance to do this - India seems to be a favourite source of such team-spamming.

I also thought the antispam mod would relieve the pressure - but as you said above - it doesn't seem to help much.

I suspect the ultimate mod would be one that allow users to put whatever they like in the signatures, but if it contains a URL, either live or not, an email gets sent to the admin to approve the signature.

Sadly, I don't have the time to do this myself but it would be a welcome addition.

The reply came...

****reply 3****
Hi,

Please can you provide the specific rule that needs removing and we can do this for you which should fix this issue.

Regards,

Matthew James
WebFusion 2nd Line Support
PIPEX
***************

to which I candidly replied:

Hi Matthew (or whoever gets this!)

If I had known what mod_security was all about, I might be able to help. However, I was relying on your tech support team to know where the issue lies.
I have given you all of the information required to replicate the problem, and it shouldn't take too much effort to find out what rule is causing the block.

I'd never heard of mod_security before this problem...so I'm definitely the wrong person to be asking!

Could you take the time to follow the steps I included in my previous e-mails, and find out what is going on?

Thank you


They then came back with@

****rpley 4****

Hi,

As previously mentioned, we do not know which mod_security rule needs removing in order for this to work.

The best thing to do would be to contact the software vendor or ask on their website/forum.

Regards,

Matthew James
WebFusion 2nd Line Support
PIPEX


***********

So, that, it seems, is that....they're not willing to help.

Does anyone know what mod_security rule does need to be changed?

thanks for any help!

Torbz

So how does that actually show up in punBB and where?
Does anyone have a working version that I can look at?

Still a little unclear as to what accesses what and how. Is there a menu link automatically put into punBB horizonta lnav menu?

Hey guys,

Still quite new to punBB and X7 chat.
I have a forum install at www.hangfan.co.uk/forum
and X7 chat at
www.hangfan.co.uk/hangout

I've not really had the head to understand how to cleanly tag the two up together, could you give me step by step instructions?

Thanks for you help,

Torbz

hi folks,

It was the first time I've ever succesfully hosted a forum and it wouldn't be possible without you lovely 'pun'ters.
Even managed a couple of mods too.

Bless you all!

Torbz
www.hangfan.co.uk
www.hangfan.co.uk/forum

Very good mate. Fits in nicely.

Well, I've written back a few hours ago, so we'll see what comes of it.
Have found log file and will scan through it now.

Found one line...among a dazzling myriad of data:
http://www.newagenet.co.uk/hangfan/foru … e.php?id=4 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.1;+SV1;+InfoPath.2;+.NET+CLR+1.1.4322)
www.newagenet.co.uk 82.153.65.208 - 2007-07-18 16:28:04 POST /hangfan/forum/profile.php section=admin&id=4&action=foo 406 276

Dunno if it would tell them anything new, but have sent it.

If you have a better suggestion for european based hosting with a 60gb + traffic, 6GB hdd space & 1500 e-mail account package, let me know.
I pay around £15 (~25 euros) a month currently on a shared linux/apache server package.

Thanks again for your speedy help too,

torbz

Nope didn't make an ounce of difference. Still getting the same old....

Is that the only line I should have in my htaccess file and should it be in the forum root folder?

I agree with the shoddy english situation but that's the free market for you...

The 2nd guy who replied seemed to have a better command of English!

I will try again (I did spot the &quot problem and did try it in the correct format). Still no luck though.

Will try again now.

Thanks,
torbz

Hi there,

I've read up on all of the troubleshooting topics regarding this issue. I just wanted to catalogue the progress with my ISP (webfusion/pipex uk) as I've challenged them to find the problem.

I sent this after explaining my problem and they asked for the control panel login on the forum:


***E-mail 1***
Dear Pipiex/Webfusion support,
In reply to your request you can replicate my problem, log in to the forum installation as:
(www.newagenet.co.uk/hangfan/forum)
User: *******
Pass: *******
Then click on "user list" (2nd option in top menu) Select the user "hammertime" (4th name listed) Then click on "Administration" in the left hand vertical menu.
From there you should be able assign account type (user, moderator etc.) or delete/ban them

When you attempt any of these actions, the server throws up a 406 error, stating the resource cannot be found.

Searching on the net reveals a possible mod_security setting that may interfere with this sort of http operation.
I'm merely regurgitating stuff here, I have no experience in this area (as yet!).

I hope this helps resolve the problem,

Take care,

Torbz
***************

They then replied:


***REPLY 1****
Hi,

When you attempt to delete a user or any of teh actions as you have stated you receive a 406 error as the file it is looking for to action the delete command wither has become corrupted or it can't find teh command in the script.

It is looking for:

/hangfan/forum/profile.php

You can check the forums on teh internet for this error, can youy please confirm when you first received this error. We have not carried out any php updates or upgrades in the last few weeks so this should not be the cause. Please also check teh file permissionns for the above file as they should be 755.

If you can provide further information on this we can try to help you reolve this or provide further information for you to try.

Regards

Minesh Patel
WebFusion 2nd Line Support
PIPEX
********************

I basically then told them that the issue wasn't punBB and definitely the mod_security settings and that they should look in to it further.

They replied:

****Reply 2****
Hi,

Thank you for your email.

We do run Mod_security on the server, if you could let us know the page you are having problems with we can ask the engineers to adjust the rules for you.

In the meantime you can turn mod_security off by adding a .htaccess file with the following line.

SetEnv MODSEC_ENABLE "Off"

I hope that this helps.

Regards,

Keith Boyd
Webfusion 2nd Line Support
PIPEX
*************

So, I fiddled about for half an hour with their code, then looked into it further and tried all sorts of variations including:

SecFilterEngine Off
SecFilterScanPOST Off

which I'd found on other forums regarding similar mod_security issues.

none of it worked, despite me putting the .htaccess code in all the directories I could think of (root, the hangfan sub-directory and the forum sub directory).

Has anyone any advice on how to go forward? I've since sent them an e-mail saying it doesn't work and we'll see what reply comes, but never having heard of mod_security before, I'm left with too steep a learning curve to know what to do next.

Help and advice appreciated greatly!

thanks,

torbz
www.hangfan.co.uk
PunBB installation at www.hangfan.co.uk/forum