Bad Behavior / Bad Behaviour Plugin Plugin

A Joomla! plugin port of Bad Behavior 2.0.30 Bad Behavior is a spambot blocker that uses a range of filters, like HTTP known headers, IP lists, user-agent strings to determine if the requesting host is a spambot or a harvester. Read more at http://www.bad-behavior.ioerror.us/

Release 1.2 fixed a name change bug in.
Release 1.3 updated to latest Bad Behaviour version 2.0.23.
Release 1.4 updated to latest Bad Behaviour version 2.0.26.
Release 1.5 added whitelist capabilities and possibility of checking only certain groups.
Release 1.6 updated to latest Bad Behaviour version 2.0.28 and fixed 2 bugs.
Release 1.7 localization support on request.
Release 1.8 Fixed a bug in whitelist.inc.php, please update.
Release 1.9 Fixed a small disclosure in the logs and fixed localization bug.
Release 1.10 Fixed a bug:"Calls to undefined function bb2_email()"
Release 1.11 Updated to bad behavior 2.0.29
Release 1.12 Updated to bad behavior 2.0.30
Release 1.13 Updated to bad behavior 2.0.31 (bug fix release)
Release 1.14 Updated to bad behavior 2.0.32 (bug fix release)
Release 1.15 Bug fix release

Report

byrob684 on January 7, 2010
An excellent plugin, but... the version numbering for Joomla vs other platforms is confusing. It always takes time to sort out to see if you have the latest version.
Hello, thank you for this tool and your fast and prompt email, which you sent to my inquiry.

I hope that this tool gets updated as it becomes available.

Thanks,
Kelley
bytez on June 11, 2009
So far it looks good. I did a diff comparison between the original code and yours, nothing suspicious is added.

There were two whitelisted IPs though which I removed, 64.191.203.34, 208.67.217.130
64.191.203.34 resolved to diggstage01.digg.com
208.67.217.130 resolved to hit-adult.opendns.com

I get Acajoom signups every few days, I will come back later and report if they have stopped.

Re: User eldo
Did you ENABLE the plugin? That is the thing about Joomla PLG extensions, they never install as enabled, you must do that yourself! check administrator/index.php?option=com_plugins
Owner's reply

Those ips are in bad-behaviour(since 2.0.22) whitelist as well, I placed them as default but you can remove them savely if your site doesn't communicate with digg website.

byeldo on May 6, 2009
after i use this plugin, my spam user doesn't decreased, but increased!
Owner's reply

Could you provide evidence on how this might have happened as my plugin fights spam and doesn't provide any info to increase it.

bygavman on March 17, 2009
I add this and as soon as I click enable I lose everything. Page won't load anything in backend or frontend!!!

I am now going to have to ftp and manually remove the components/plugin....

Be careful when using.
Owner's reply

Could you post your server and joomla! info on our support board so I can locate the problem and update the plugin.

http://forum.4theweb.nl/forumdisplay.php?f=24

Sorry for the problems it might have given you.

Kind regards,
Michiel

I've used Bad Behaviour on wordpress blogs for many years now. Works great.
I am happy to see it on Joomla. Shall see how it goes... but if it's anything like WP then all will be well.

NOTE.
It would be nice to see a newer version of Bad Behaviour incorporated into this plugin. As I write this I think 2.0.26 is the latest.

Thanks for porting this into the Joomla world
Owner's reply

Hi,

It has been updated to latest version.

Kind regards,
Michiel

Great idea and fantastic if I can get some more confidence it is working. I've installed this version (1.3) on Joomla 1.5.8. However, the comments in the code say it is based on badbehavior 2.0.10, the comments on this web page say 2.0.23 and the comments when you enable the plugin also say 2.0.10. It installed okay but there seems to be no logging so I do not know if it is working or not. Also no place for Honeypot API key (all tables appear to be internal).

I had a look at the Joomla 1.0 plugin and that has room for an API key, also appears to be 2.0.23 based. However, as soon as I enable it, I am locked out of my web site & had to disable again from SQL.

So, the big question is: Is this version 1.3 actually using the 2.0.23 badbehavior code or is it using the old 2.0.10 code? How can I tell if it is doing anything? Nothing appears in the Joomla Log.

Regds,
Dave
Owner's reply

Hi Dave,

I have updated the plugin to be consistent in reporting which version and updated to 2.0.26 of Bad Behaviour.

This plugin doesn't use the http:bl from Bad behaviour but I have a plugin that does this for you, see http://extensions.joomla.org/extensions/access-&-security/site-access/2786/details.

It is tested on Joomla! 1.5.9, if you are still having problems please report them on our support forum.

kind regards,
Michiel Bijland

Anything that uses the Honey Pot Project database to block hacker and spammer IP’s is good to Joomla, I check some of the reported individual IPs in the database and they matched some previous hack and defacing we have experience in the pass, I wish I would know about this plug in before.

The last part we need is a good SSL plug in and will be more secure better than naked when you release a Joomla site without these tools.
Keep the good work.
bynathandiehl on June 25, 2008
This simple plugin stopped 100% (with no exceptions in the three months I've been using it) of the auto-bots hitting my acajoom registrations.
I've also used Bad Behavior to stop 99.99% of bots for form components.
It's way worth the install.
bylwheelr on September 12, 2007
I was so tickled to see this plugin adapted to Joomla. I've installed it as a standard on every Joomla site I own, and some of my client sites. If someone would release a stand-alone version, it would be on every domain I set up.
Owner's reply

Hi,

You can use the origenal package, jsut follow the link above.

kind regards,
Michiel