Spammers Getting Around Form Captcha
Permalink
I am getting racked with spam recently on a couple of my sites. Captcha is in place on all of the forms, but they are getting through pretty consistently, and its beginning to really pick up - has anyone else experienced this issue?
I have checked the logs and while the emails all look the same (junk characters and a URL) they are being submitted from a different IP each time.
I am wondering if there is a way of adding additional letters/numbers to the captcha, or another solution (short of removing the contact form and blog commenting forms).
Anyone else seeing this issue? I haven't had an issue with this until quite recently, and it seems to have really picked up across a couple of sites in the last 2 weeks or so.
(sample spam submission - for what its worth)
There has been a submission of the form Contact on through your Concrete5 website.
Your Question, Comments Etc...
s0RExJ cvwpkalgesww, [url=http://spauatppqbxl.com/]spauatppqbxl[/url], [link=http://kcxrifipfglh.com/]kcxrifipfglh[/link],http://opkgmyqcmktf.com/
Your Name:
zOKLrwRD
Your Email Address:
mtzkcjhyhWUeYkjDGgz
Where did you hear about the Rogue Gourmet? (Optional)
s0RExJ cvwpkalgesww, [url=http://spauatppqbxl.com/]spauatppqbxl[/url], [link=http://kcxrifipfglh.com/]kcxrifipfglh[/link],http://opkgmyqcmktf.com/
To view all of this form's submissions, visithttp://www.theroguegouremet.com/index.php/dashboard/reports/forms/?...
I have checked the logs and while the emails all look the same (junk characters and a URL) they are being submitted from a different IP each time.
I am wondering if there is a way of adding additional letters/numbers to the captcha, or another solution (short of removing the contact form and blog commenting forms).
Anyone else seeing this issue? I haven't had an issue with this until quite recently, and it seems to have really picked up across a couple of sites in the last 2 weeks or so.
(sample spam submission - for what its worth)
There has been a submission of the form Contact on through your Concrete5 website.
Your Question, Comments Etc...
s0RExJ cvwpkalgesww, [url=http://spauatppqbxl.com/]spauatppqbxl[/url], [link=http://kcxrifipfglh.com/]kcxrifipfglh[/link],http://opkgmyqcmktf.com/
Your Name:
zOKLrwRD
Your Email Address:
mtzkcjhyhWUeYkjDGgz
Where did you hear about the Rogue Gourmet? (Optional)
s0RExJ cvwpkalgesww, [url=http://spauatppqbxl.com/]spauatppqbxl[/url], [link=http://kcxrifipfglh.com/]kcxrifipfglh[/link],http://opkgmyqcmktf.com/
To view all of this form's submissions, visithttp://www.theroguegouremet.com/index.php/dashboard/reports/forms/?...
Thanks for the response,
Though I am running into something a bit odd.
I made some edits to the file, and saw no reaction in the actual form. so I edited the original file to test it out, thinking maybe I misspelled a directory or something - again, no change. my site isn't cashed, though I tried clearing that as well, - again no change. I renamed the original secureimage folder on the server side, refreshed the page - again the Captcha is showing up, without any changes - which I was not expecting.
any idea on what I might be missing? I am a bit confused as to what might be going on here.
Though I am running into something a bit odd.
I made some edits to the file, and saw no reaction in the actual form. so I edited the original file to test it out, thinking maybe I misspelled a directory or something - again, no change. my site isn't cashed, though I tried clearing that as well, - again no change. I renamed the original secureimage folder on the server side, refreshed the page - again the Captcha is showing up, without any changes - which I was not expecting.
any idea on what I might be missing? I am a bit confused as to what might be going on here.
Make sure your site is not pointing to updates/concrete/...
Many of my sites after running the latest update to C5 started pointing to updates/concrete instead of concrete. I have no idea why, but I have 6 sites that did that and know of at least 50 others of fellow friends of mine.
Many of my sites after running the latest update to C5 started pointing to updates/concrete instead of concrete. I have no idea why, but I have 6 sites that did that and know of at least 50 others of fellow friends of mine.
Recaptcha is a nicer Captcha solution (& it's accessable, owned by google):
http://www.google.com/recaptcha...
http://www.google.com/recaptcha...
/concrete/libraries/3rdparty/securimage
to
/libraries/3rdparty/securimage
(all files) then edit secureimage.php