1
deka87
Need help to hack xoops captcha
  • 2010/3/15 12:31

  • deka87

  • Friend of XOOPS

  • Posts: 1125

  • Since: 2007/10/5


hi guys,

well im totally pissed and anxious about those fing bots that keep registering at my website. manual activation is not an option cos i get over 50 activation emails a day and i get my mailbox spammed instead. as i used to use recaptcha and it didn't work against those dang spammers, i think they are using a kind of an allsubmitter software to type the captcha in and let the rest to the bots. this software retrieves the captcha pic on the screen and all you have to do to give the bot a way is to type what you see in the form.

since my website is trasnlation related and i expect my users to be prominent in translation matters, i want to replace the original captcha with a set of pics with spanish/german/french words on them and make users to type the english translation of the words instead of the words themselves. i really hope it's gonna work out but now i need a hand to help me figure out how to do it. as i understand everything is done in class/captcha so all i need is to replace the original word mess on the pic sith several words defined by me and make the comparation according to their translation defined.


any help?

2
Peekay
Re: Need help to hack xoops captcha
  • 2010/3/15 15:17

  • Peekay

  • XOOPS is my life!

  • Posts: 2335

  • Since: 2004/11/20


Against bots, why don't you try this simple hack?

This is for XOOPS 2.4. Read my earlier post in the thread if you are using XOOPS 2.3 or earlier.

3
deka87
Re: Need help to hack xoops captcha
  • 2010/3/15 15:24

  • deka87

  • Friend of XOOPS

  • Posts: 1125

  • Since: 2007/10/5


oh crap how did i miss such a huge discussion on the same thread. thanks Peekay I'll take a very close look now.

--edit--

ok i've put the code in both register.php files. hope together with recaptcha they will keep me from bots. i'll report later

4
deka87
Re: Need help to hack xoops captcha
  • 2010/3/16 7:05

  • deka87

  • Friend of XOOPS

  • Posts: 1125

  • Since: 2007/10/5


Quote:
Against bots, why don't you try this simple hack?


i have tried it now. the hack itsef works alright, but it doesn't stop spammers. it hasn't even reduce the number of fake registrations. maybe any other ideas?

5
deka87
Re: Need help to hack xoops captcha
  • 2010/3/16 7:26

  • deka87

  • Friend of XOOPS

  • Posts: 1125

  • Since: 2007/10/5


OK I have tracked the ip of one of the spammers and here is the logs I have found:

112.201.101.60 - - [15/Mar/2010:19:59:39 +0300"GET http://www.freelancersupport.com/modules/profile/register.php?op=actv&id=6102&actkey=e91955de" 302 5 "http://co112w.col112.mail.live.com/mail/InboxLight.aspx?FolderID=00000000-0000-0000-0000-000000000005&InboxSortAscending=False&InboxSortBy=Date&n=1837638665" "Opera/9.80 (Windows NT 6.0; U; en) Presto/2.2.15 Version/10.10" 127.0.0.2
112.201.101.60 
- - [15/Mar/2010:19:59:47 +0300"GET http://www.freelancersupport.com/modules/profile/user.php" 200 30301 "http://www.freelancersupport.com/modules/profile/activate.php?op=actv&id=6102&actkey=e91955de" "Opera/9.80 (Windows NT 6.0; U; en) Presto/2.2.15 Version/10.10" 127.0.0.2
112.201.101.60 
- - [15/Mar/2010:19:59:38 +0300"GET http://www.freelancersupport.com/register.php?op=actv&id=6102&actkey=e91955de" 301 399 "http://co112w.col112.mail.live.com/mail/InboxLight.aspx?FolderID=00000000-0000-0000-0000-000000000005&InboxSortAscending=False&InboxSortBy=Date&n=1837638665" "Opera/9.80 (Windows NT 6.0; U; en) Presto/2.2.15 Version/10.10" 127.0.0.2
112.201.101.60 
- - [15/Mar/2010:19:59:40 +0300"GET http://www.freelancersupport.com/modules/profile/activate.php?op=actv&id=6102&actkey=e91955de" 200 1075 "http://co112w.col112.mail.live.com/mail/InboxLight.aspx?FolderID=00000000-0000-0000-0000-000000000005&InboxSortAscending=False&InboxSortBy=Date&n=1837638665" "Opera/9.80 (Windows NT 6.0; U; en) Presto/2.2.15 Version/10.10" 127.0.0.2
112.201.101.60 
- - [15/Mar/2010:19:59:46 +0300"GET http://www.freelancersupport.com/user.php" 302 5 "http://www.freelancersupport.com/modules/profile/activate.php?op=actv&id=6102&actkey=e91955de" "Opera/9.80 (Windows NT 6.0; U; en) Presto/2.2.15 Version/10.10" 127.0.0.2


maybe it can help.

i also wonder if this issue caused a 7 pages long discussion and there were notes that even reCaptcha can't stop them (my case as well) and it's the ussue of the register.php itself why don't we have a security patch yet?!

6
Peekay
Re: Need help to hack xoops captcha
  • 2010/3/16 11:24

  • Peekay

  • XOOPS is my life!

  • Posts: 2335

  • Since: 2004/11/20


Hmmm... sorry to hear it didn't work. I confess I don't use XOOPS with profile module and that seems to be the target.

In the log from barryc (who was using XOOPS 2.3) the bot was using activation keys that were constant and bogus, e.g.

Quote:
activate.php?op=actv&id=99999&actkey=9999999


I must admit I can't see how that would work as I assume XOOPS has some protection against duplicate activation values?

If you can post the log of two successful bot registrations at different times from different referers it would be helpful. I will need to see the full GET and POST strings (some of the above are truncated)

7
deka87
Re: Need help to hack xoops captcha
  • 2010/3/16 17:06

  • deka87

  • Friend of XOOPS

  • Posts: 1125

  • Since: 2007/10/5


I wll enable the registration and check with the logs later today, Peekay. Just a quick suggestion: can we use so called honeypots to prevent our registration from spamming? I'd want to try it, though im not sure how to make a XOOPS profile field invisible via css.

8
Peekay
Re: Need help to hack xoops captcha
  • 2010/3/16 17:36

  • Peekay

  • XOOPS is my life!

  • Posts: 2335

  • Since: 2004/11/20


Honey-pots will often trap the bot... but if you block the IP address it will simply return with a different IP next week. Any IP bans are a bit of a waste of time really.

You can PM me the log if you think it's a bit large to post in the forum. If I can spot a solution I'll obviously post back here.

Login

Who's Online

464 user(s) are online (182 user(s) are browsing Support Forums)


Members: 0


Guests: 464


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Jun 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits