Spambots beating captcha 2.2

15 years 3 months ago #84953 by ndee
Replied by ndee on topic Re:Spambots beating captcha 2.2
Nice info:
en.wikipedia.org/wiki/Captcha

reCAPTCHA seems to be secure and you support also a good purpose. But with some sites I realy had to refresh several times until there was a solvable CAPTCHA displayed. Maybe integration of a existing product is more effictive than developing CBs own solution.
en.wikipedia.org/wiki/ReCAPTCHA

Post edited by: ndee, at: 2009/01/11 21:59

###################
SPEED UP HELP, read first: Help us help you
###################

Please Log in to join the conversation.

15 years 3 months ago #85630 by ergohost
Replied by ergohost on topic Re:Spambots beating captcha 2.2
Odd, not sure what I did but over a couple of days the spambot submissions petered out, fingers crossed not seeing any more currently.

Please Log in to join the conversation.

15 years 3 months ago #85635 by beat
Replied by beat on topic Re:Spambots beating captcha 2.2
Well i got a simpler explanation possibility on this... :D

Are you sure that you did switch off joomla core registration and set CB's setting to allow registrations, independently of joomla core, like explained in CB's README ?

Probably your bots were registering without CB and CB captcha :D

Even if yes, Recaptcha isn't a solution in itself:

1. Often, spammers do pay very low labor force to manualy register. Any captcha solution won't help in that. :P

See blog.washingtonpost.com/securityfix/ for more info on how bad that spammers and internet criminals plague is. :angry:

CB powering lots of registration pages, CB captcha too, if it wasn't secure it would be known fast. ;)

2. Don't get me started regarding "google's noble cause" as you call it of collecting offline information by scaning librariries "for free" and then making online users work free for them using their captcha.

Try using the Internet without google Inc. (or is it Ltd. ?) for a week.

3. Do you know that by installing google's recaptcha on your form, you at same time are potentially giving them full access to all the data on that registration form to their remote servers ?!

I will not use recaptcha or any third-party server -powered captcha solution on my registration forms, sorry. I don't recommend it to you too, but you are free.

That's why we wrote CB Captcha the hard way.

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info

Please Log in to join the conversation.

15 years 3 months ago #85652 by ndee
Replied by ndee on topic Re:Spambots beating captcha 2.2
beat wrote:

Even if yes, Recaptcha isn't a solution in itself:

1. Often, spammers do pay very low labor force to manualy register. Any captcha solution won't help in that. :P

You are right, captchas are only an obstacle. The chance that your site is that important that somebody will pay for this service is less then with a captcha readable by bots.

2. Don't get me started regarding "google's noble cause" as you call it of collecting offline information by scaning librariries "for free" and then making online users work free for them using their captcha.

Try using the Internet without google Inc. (or is it Ltd. ?) for a week.

3. Do you know that by installing google's recaptcha on your form, you at same time are potentially giving them full access to all the data on that registration form to their remote servers ?!

I will not use recaptcha or any third-party server -powered captcha solution on my registration forms, sorry. I don't recommend it to you too, but you are free.

That's why we wrote CB Captcha the hard way.

You are right, I did not read the pages enough. I did not know that google is behind that. I fully understand that you do not trust 3rd party callback software.*

OT: * What about upcoming subcriptions, afaik it will also phone home. How do I know that I can trust you? Or will there at least be a version wich I can pay and which does not phone home?

Greets,
ndee

Post edited by: ndee, at: 2009/01/16 21:56

###################
SPEED UP HELP, read first: Help us help you
###################

Please Log in to join the conversation.

15 years 3 months ago #85906 by mediaguru
Replied by mediaguru on topic Re:Spambots beating captcha 2.2
I added a text field to my CB fields with a special question which is related to my site's core focus, golf.

This question serves as an extra security measure and has worked pretty well. I ask who their favorite pro golfer is.

If I see in the registration field that they wrote Tiger Woods and also solved the captcha, I'm pretty confident they're real.

If they put in xjshsjshx in the text field, they're either a spambot or someone I don't want in the site anyway.

CB/Joomla golf site: www.thegolfspace.com
Geek/joomla site: www.tkserver.com

Check out my Joomla/CB projects:

* LIKE thumbs up system for "liking" content items
* Karma - CB user rating system
* Golf Score Tracker
* Jitter - status update system. "What's on your mind?"
* CB Author Plug - Shows CB author link and avatar in content items. J1.5 compatible and very customizable!

Found on my web site or in the Joomlapolis Directory !

Please Log in to join the conversation.

15 years 2 months ago #88933 by dmitri
Replied by dmitri on topic Re:Spambots beating captcha 2.2
I have been having a similar problem which is impacting a couple Joomla 1.5 websites running Community Builder. From the registration confirmation messages I can see that the same bots are hitting both sites, commonly the second identical registration message shortly after the first. Always the same pattern. firstname = lastname = username.

I have email confirmation enabled. I verified that I have core login disabled. To be sure just now I moved the mod_login out of modules to an obscure folder.

Yes I understand that lowly paid cheap labor could be in the mix here, but the repetition does not suggest live bots vs. automation.

Suggestions welcome... -Bob

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.959 seconds

Facebook Twitter LinkedIn