Shield Security Integrates Enhanced GASP Comment SPAM Protection

By 31st August 2013 May 28th, 2021 Shield Security

A few days ago an update was released to the Growmap Anti Spambot Plugin for WordPress.

GASP WordPress Comments Filter

After reviewing it, it raised a few questions.

The new addition, while useful, is as far as we can see at best a temporary fix to solve the problem with the plugin.

Don’t get me wrong, it’s one of the first plugins I install on any new WordPress site – it’s great!

But we’ve decided to take the strengths of this plugin and add our own customizations.

Recently we developed our own simple but highly effective Shield Security plugin for WordPress, that actually integrates the GASP principles into the WordPress login screen.

We decided as we reviewed the updated GASP plugin that we would integrate their comment spam protection feature directly into our Shield Security plugin, and at the same time implement some of the ideas we have to further enhance it.

In this way, we’ll bring together some of the most powerful security and WordPress protection mechanisms under 1 roof – the Shield Security plugin for WordPress.

How the Shield Security plugin for WordPress SPAM Protection works

There are several key features to the SPAM protection offered by the Shield Security plugin for WordPress.

Combined, they offer very powerful protection against Spambot WordPress comments.

1. Growmap Anti Spambot Protection

As already mentioned, we’ve taken the GASP plugin principles and integrated them into this plugin. It works in much the same way with the checkbox that asks legitimate users to confirm they’re not a spammer.

It also the includes the honeypot mechanism they use also.

Also, with their latest release (at the time of writing v1.4.1) they use a new secret key, and we have taken that idea and enhanced it to use “Unique Comment Tokens”.

2. Unique Comment Tokens

We saw how GASP used their secret key idea and while we liked it, we saw 2 problems with it:

  1. it works by forcing a spambot to load a page twice before commenting. It’s not really complicated to circumvent this on the part of the spambot.
  2. the secret key is static – a user has to manually update the key. Updating is pointless anyway because once the spambot has succeeded with the first problem (reloading the page), the rest is easy. The secret key is used throughout the site, so once the key is discovered (it isn’t hidden) it can be re-used.

So we decided to approach this slightly differently. Instead, we:

  1. create a unique comment token (a secret key) per-page load.
  2. comment tokens have a both a cooldown period, and an expiration period.
  3. unique comment tokens can only be used once.

A unique key per page load is means a spambot can’t load your site, or any single page, record the secret key, and then use that going forward to post unlimited spam to your site.

Instead, each time they want to spam, they must load that page once to record the unique comment token.

The comment token is always different and must be known by the bot before it can successfully post a comment.

Advantages of the Shield Security plugin for WordPress’ Comment Tokens

Comment Token Cooldown

The cooldown period for a comment token means this: After a spambot “knows” a unique key that it can use to post a comment, it must now wait a specified period of time before it can do so.

This effectively puts the brakes on the commenting spambots. If spambots manage to (and I’m sure they will) work around this plugin’s enhancements, they will still always face the cooldown limits.

Another advantage of the cooldown is that if a spambot attempts to post a comment before the cooldown interval has passed, that comment token is invalidated and can’t be reused.

Token Expiration

The expiration limit means a comment token must be used within a given period of time and cannot be used far into the future.

If you contrast this with the secret key approach used in the original GASP plugin, you’ll see the benefit of dynamically generating these comment tokens and ensuring they expire.

No SPAM protection is perfect

That’s a fact.

GASP is a brilliant plugin and a solid approach to thwarting spambots – that’s why we’ve implemented it in ours.

Our enhancements, will I’m sure, be redundant in time as the spam networks adapt.  We have written our code to be completely unique each time a page is loaded, just to add another level of complexity to which the spambots must adapt.  I guess we’ll see in time if it works.

If you have any suggestions on how to improve this plugin, or what features you’ll like to see, please don’t hesitate to comment here, or in the WordPress.org support forums.

Join the discussion 5 Comments

  • Keith Davis says:

    Hi Paul
    Already had the SF plugin on all my sites and have just activated the comment form protection – so saf so good!

    Like you I was a big fan of Andy Bailey’s original GASP plugin, but recently the automated spam had started to appear.
    Good timing on your part!

    Thanks for the SF plugin and the new features are much appreciated.

    View Comment
    • Paul G. says:

      Great to hear that Keith!

      We developed this addition to the plugin so we had great flexibility in tweaking and managing our Comment SPAM instead of relying on 3rd party libraries to update, even though they’re great plugins of course.

      Fingers crossed this works as planned!

      As always, if you have suggestions or ideas for what you’d like to see in the plugin, let us know.
      Thanks!
      Paul.

      View Comment
  • Anonyumous says:

    Hi Paul,
    WordPress Firewall plugin integrates the GASP principles into the WordPress login screen.This feature make this simple firewall more powerful and effective in all type of firewall.
    If any one need any help in any type of email related issue can visit our site.

    View Comment
  • Nik says:

    WordPress firewall plugins protect your website against hacking, brute force and distributed denial of service (DDoS) attacks.

    View Comment

Leave a Reply

x Logo: ShieldPRO
This Site Is Protected By
ShieldPRO