Captcha

faragopeter

Avatar: faragopeter

2012-04-01 17:48

Hi!

I have QC 3.5 and I have a problem with my captcha plugin. I made my site with the securimage captcha code and it worked for a long time, but now robots have found a solution to this code and they send me a lot of images on the comment form at the products.

Now the comment form is disabled, because of the robots.

You can see my code on my site for example here: http://www.fogashorgaszbolt.hu/?4474,ozzie-napszemüveg-oz46-78

If anybody has solutions, please answer me.

» Quick.Cart v3.x

fp

beholder

Avatar: beholder

2012-04-01 18:42

when you remove submit button on the form, do the form still work for bots? please try and report back.
If they are still able to exploit your system even with submit button off, then they are using their own form to submit the trash. The solution would be to tokenize the form, although I am not sure.

The most intriguing thing is that they were able to breach the Captcha. I think it's because it's just 3 letters, so it's easy to submit a multitude of tries of which one would be sucessfull. But this is for an in-depth analysis.

http://cicmanec.sk/easyplugins/

faragopeter

Avatar: faragopeter

2012-04-01 19:18

Yes they use their own form because the button disabling didn't help. Former I used 6 letters and I tried numbers also, but it wasn't enough.

Can you tell me what does "tokenize the form" mean?

fp

faragopeter

Avatar: faragopeter

2012-04-01 19:21

This Captcha code I bought fro mak-web.pl and I modified it a little bit. I made an upgrade on secureimage.

fp

beholder

Avatar: beholder

2012-04-02 19:33

hmm.. you should go to him with a claim. This [bots breaching captcha] is not normal and should be investigated by a professional.

In the worst case I have my own captcha code for this which should be fine from hackers, it's based on longer words and is not as much known as this secureimage technology. If you can do your own coding/transfering code I can give it to you, no problem.

http://cicmanec.sk/easyplugins/

faragopeter

Avatar: faragopeter

2012-04-02 20:14

It could be fine, I think I can make the coding on my site, after you send your code to me. You can contact me on fogas@t-online.hu .

Thanks for your help in advance.

fp

Back to top
about us | contact