32
I've read through all the messages in this thread and still have a couple of questions.
First, an observation. It shows me the importance of monitoring xoops.org and it makes me wonder if we need an alert system that people can sign up for. Perhaps a special forum topic to which only admins can post but to which users like me can check the appropriate notify box.
The general consensus seems to be that the XOOPS captcha has been cracked using OCR techniques. A couple of things still bother me. Normally I should get a notification email telling me of any registration on my site. I definitely did not get the notification for the two "google.com" registrations I've received. Do we know how that was by-passed? It makes me wonder whether setting the requirement for admin approval of registrations (which I have done) will be effective. Time will tell, but I will have to occasionally for for these registrations to check.
I also have a couple of required fields that appear on the second page of the registration process. Those were not filled in but all the fields in the first registration page were filled with random characters. I know that if one aborts the registration process after accepting only the first form, a user is still created. Presumably that happened here. Is there a way to require that second page be filled in? I suppose it wouldn't take much for a bot programmer to accommodate that need. I also wonder about the hidden field idea that was mentioned in the thread that ghia pointed us to. That would have to appear on the first registration form and, if completed, the registration attempt would be rejected. It was said that it would not defeat massive attacks but it might defeat random bots trying to register on any and all XOOPS sites.
That raises another question. Are these registrations aimed specifically at XOOPS sites or sites with registration procedures in general? Maybe it's an unfortunate testimony to the growing popularity of xoops.
Finally, I hope someone can let us know how the process of adding reCaptcha, as outlined by ghia, works for them. I do plan to try to implement it on my test site, which is a copy of my live site on a different domain. I'll report back, hopefully later today, if someone doesn't beat me to it.
barryC