Skip navigation
Sidebar -

Advanced search options →

Welcome

Welcome to CEMB forum.
Please login or register. Did you miss your activation email?

Donations

Help keep the Forum going!
Click on Kitty to donate:

Kitty is lost

Recent Posts


Do humans have needed kno...
Today at 12:56 AM

Random Islamic History Po...
by zeca
October 07, 2025, 09:50 AM

What's happened to the fo...
October 06, 2025, 11:58 AM

New Britain
October 05, 2025, 08:07 AM

Qur'anic studies today
by zeca
October 05, 2025, 07:55 AM

Kashmir endgame
October 04, 2025, 10:05 PM

Lights on the way
by akay
October 04, 2025, 09:23 AM

اضواء على الطريق ....... ...
by akay
October 02, 2025, 12:03 PM

الحبيب من يشبه اكثر؟؟؟
by akay
September 24, 2025, 11:55 AM

Muslim grooming gangs sti...
September 20, 2025, 07:39 PM

Jesus mythicism
by zeca
September 13, 2025, 10:59 PM

Orientalism - Edward Said
by zeca
August 22, 2025, 07:41 AM

Theme Changer

 Topic: Spambot attacks (read it: this means you)

 (Read 13316 times)
  • Previous page 1 2« Previous thread | Next thread »
  • Re: Spambot attacks (read it: this means you)
     Reply #30 - February 19, 2011, 11:51 AM

    Depends on which captacha software you use, some are very easy to crack. Also bots CAN crack any captaha a human can, they use a new spamming method, where they get a human to enter the captha via some kind of spam link or fake offers of free stuff.

    I know this, since I have a mate who works in the spamming business, he makes software to get around these securities. His had his computer equipment confiscated by the police once lol.   
  • Re: Spambot attacks (read it: this means you)
     Reply #31 - February 19, 2011, 02:17 PM

    Cheesy And what makes you think catpcha is any use against bots these days? It isn't. In the war against spambots captcha is obsolete. Just about any bot can read any captcha a human can manage to read, and for the bots it isn't annoying. I have deliberately left the captcha turned down to a low level on this site and have even thought seriously about removing it entirely.

    not really
    ocr has still a limited success rate against modern forms of captcha

    as an alternative, add a huge delay before authentication (like 20 seconds?) when logging in
    that will slow down the number of attempts per hour and make any dictionary attack unfeasible

    Do not look directly at the operational end of the device.
  • Re: Spambot attacks (read it: this means you)
     Reply #32 - February 19, 2011, 02:20 PM

    But in case you add a delay, add a huge warning about it, or users will think their connection hanged.
    Like "please wait x seconds while you are being authenticated..."

    Do not look directly at the operational end of the device.
  • Re: Spambot attacks (read it: this means you)
     Reply #33 - February 19, 2011, 02:30 PM

    Another good thing would be to log in the users using a "secret" that is known only to them (like, their email address, if it's kept secret), instead of something that can be farmed by bots (like usernames).

    In simple words: require people to login using their email+password instead of user+password.
    And enforce email hiding on all accounts.

    Do not look directly at the operational end of the device.
  • Re: Spambot attacks (read it: this means you)
     Reply #34 - February 19, 2011, 02:31 PM

    If you need other ideas I have some complex genius ones that require recoding the session system from scratch ^_^

    Do not look directly at the operational end of the device.
  • Re: Spambot attacks (read it: this means you)
     Reply #35 - February 20, 2011, 12:08 AM

    Just threw in a patch which seems to have nobbled them.  Afro

    ETA: Also disabled captcha, just to see what happens. My bet is it wont make a damned bit of difference.

     grin12

    Devious, treacherous, murderous, neanderthal, sub-human of the West. bunny
  • Previous page 1 2« Previous thread | Next thread »