Skip navigation
Sidebar -

Advanced search options →

Welcome

Welcome to CEMB forum.
Please login or register. Did you miss your activation email?

Donations

Help keep the Forum going!
Click on Kitty to donate:

Kitty is lost

Recent Posts


اضواء على الطريق ....... ...
by akay
Today at 12:50 PM

Do humans have needed kno...
Today at 04:17 AM

Qur'anic studies today
by zeca
Yesterday at 07:11 PM

What's happened to the fo...
by zeca
Yesterday at 06:39 PM

New Britain
Yesterday at 05:41 PM

Do humans have needed kno...
Yesterday at 05:47 AM

Iran launches drones
April 13, 2024, 09:56 PM

عيد مبارك للجميع! ^_^
by akay
April 12, 2024, 04:01 PM

Eid-Al-Fitr
by akay
April 12, 2024, 12:06 PM

Lights on the way
by akay
February 01, 2024, 12:10 PM

Mock Them and Move on., ...
January 30, 2024, 10:44 AM

Pro Israel or Pro Palesti...
January 29, 2024, 01:53 PM

Theme Changer

 Topic: Spambot attacks (read it: this means you)

 (Read 11806 times)
  • Previous page 1 2« Previous thread | Next thread »
  • Re: Spambot attacks (read it: this means you)
     Reply #30 - February 19, 2011, 11:51 AM

    Depends on which captacha software you use, some are very easy to crack. Also bots CAN crack any captaha a human can, they use a new spamming method, where they get a human to enter the captha via some kind of spam link or fake offers of free stuff.

    I know this, since I have a mate who works in the spamming business, he makes software to get around these securities. His had his computer equipment confiscated by the police once lol.   
  • Re: Spambot attacks (read it: this means you)
     Reply #31 - February 19, 2011, 02:17 PM

    Cheesy And what makes you think catpcha is any use against bots these days? It isn't. In the war against spambots captcha is obsolete. Just about any bot can read any captcha a human can manage to read, and for the bots it isn't annoying. I have deliberately left the captcha turned down to a low level on this site and have even thought seriously about removing it entirely.

    not really
    ocr has still a limited success rate against modern forms of captcha

    as an alternative, add a huge delay before authentication (like 20 seconds?) when logging in
    that will slow down the number of attempts per hour and make any dictionary attack unfeasible

    Do not look directly at the operational end of the device.
  • Re: Spambot attacks (read it: this means you)
     Reply #32 - February 19, 2011, 02:20 PM

    But in case you add a delay, add a huge warning about it, or users will think their connection hanged.
    Like "please wait x seconds while you are being authenticated..."

    Do not look directly at the operational end of the device.
  • Re: Spambot attacks (read it: this means you)
     Reply #33 - February 19, 2011, 02:30 PM

    Another good thing would be to log in the users using a "secret" that is known only to them (like, their email address, if it's kept secret), instead of something that can be farmed by bots (like usernames).

    In simple words: require people to login using their email+password instead of user+password.
    And enforce email hiding on all accounts.

    Do not look directly at the operational end of the device.
  • Re: Spambot attacks (read it: this means you)
     Reply #34 - February 19, 2011, 02:31 PM

    If you need other ideas I have some complex genius ones that require recoding the session system from scratch ^_^

    Do not look directly at the operational end of the device.
  • Re: Spambot attacks (read it: this means you)
     Reply #35 - February 20, 2011, 12:08 AM

    Just threw in a patch which seems to have nobbled them.  Afro

    ETA: Also disabled captcha, just to see what happens. My bet is it wont make a damned bit of difference.

     grin12

    Devious, treacherous, murderous, neanderthal, sub-human of the West. bunny
  • Previous page 1 2« Previous thread | Next thread »