I'm just aware that all we do is police actions, so full porn images get posted, and a spammer could do some damage post wise to the forum before an admin came along to stop the user
Upgrading to phpBB3
Forum rules
Please read the Forum rules and policies before posting. You may
to help finance the hosting costs of this forum.
Please read the Forum rules and policies before posting. You may
to help finance the hosting costs of this forum.
- Sophia
- Concise and Honest
- Posts: 4308
- Joined: Thu Sep 12, 2002 9:50 pm
- Location: Nowhere in particular
- Contact:
Perhaps the best option is, especially if we want to eschew image-based security, to go for our own security based around some easy-to-follow directions, but is something that isn't usually done so isn't easy for spam systems to just automatically circumvent. For example, something like typing the first letter of every word in a given sentence, or answering a very easy trivia question about DM... or text-based things along those lines. I'd be happy to contribute by writing up a bunch of tests/expected answers if we want to go with this, and I'm sure others could too, that way the only work for Gambit would really be adding the Q&A to the registration form.
- Sophia
- Concise and Honest
- Posts: 4308
- Joined: Thu Sep 12, 2002 9:50 pm
- Location: Nowhere in particular
- Contact:
I don't know about using a monster image. That makes it image-based again, and there's no need to introduce that.
In addition, that introduces further technical complications, requiring more assets (graphics of the monsters), a link to the proper place, and it inconveniences the user by having to look something up if the trivia is too tricky-- who's going to remember a word like "Oitu" if they haven't played this game in 15 years?
In addition, that introduces further technical complications, requiring more assets (graphics of the monsters), a link to the proper place, and it inconveniences the user by having to look something up if the trivia is too tricky-- who's going to remember a word like "Oitu" if they haven't played this game in 15 years?
- Parallax
- DMwiki contributor
- Posts: 424
- Joined: Mon Aug 28, 2006 7:56 pm
- Location: Back in New Jersey
No well-designed system is going to block human spammers, since the point is to distinguish between humans and bots and, as much as it pains me to admit it, human spammers still qualify as 'humans' for the purpose of the test.
But if simple text questions are enough to fool bots then I'd say go for that instead. Is it possible to randomly generate the question as:
"What is {field1} {field2} {field3}?" with field1 taken from a list of numerals (in plain letters), field2 being either '+" or '-' and field3 being a numeral smaller than field1? I guess, more generally, how easy is it to add this type of question to the registration process currently? How easy would it be with phpBB3?
But if simple text questions are enough to fool bots then I'd say go for that instead. Is it possible to randomly generate the question as:
"What is {field1} {field2} {field3}?" with field1 taken from a list of numerals (in plain letters), field2 being either '+" or '-' and field3 being a numeral smaller than field1? I guess, more generally, how easy is it to add this type of question to the registration process currently? How easy would it be with phpBB3?
- cowsmanaut
- Moo Master
- Posts: 4380
- Joined: Fri Jun 30, 2000 12:53 am
- Location: canada
This has alternating information in it, and can not be desaturated as the whole image turns solid grey.
I imagine replacing the ones existing with things like this.. or perhaps with images (even though you mention hating them) of easily recognisable items. like an orange, spoon, mouse, cat, etc.. things that people can look at and immediately have the response
I imagine replacing the ones existing with things like this.. or perhaps with images (even though you mention hating them) of easily recognisable items. like an orange, spoon, mouse, cat, etc.. things that people can look at and immediately have the response
Last edited by cowsmanaut on Sat Jan 05, 2008 5:50 am, edited 1 time in total.
- Sophia
- Concise and Honest
- Posts: 4308
- Joined: Thu Sep 12, 2002 9:50 pm
- Location: Nowhere in particular
- Contact:
That one is awful.
I can barely decipher it, and my eyesight is just fine.
I dare say this one is harder for humans than computers, too: The protection against "desaturation" is worthless since the image is a bitmap with two and only two distinct colors. That's ideal input for OCR. As for that horrible animation, it can be defeated by simply adding the frames together.
I can barely decipher it, and my eyesight is just fine.
I dare say this one is harder for humans than computers, too: The protection against "desaturation" is worthless since the image is a bitmap with two and only two distinct colors. That's ideal input for OCR. As for that horrible animation, it can be defeated by simply adding the frames together.
- Gambit37
- Should eat more pies
- Posts: 13788
- Joined: Wed May 31, 2000 1:57 pm
- Location: Location, Location
- Contact:
As I said, I'm against image based captchas on principal -- they are inaccesible to anyone with poor or failed eyesight for a start. While we might not have anyone with that problem in our audience, I'd rather not make the assumption.
Anyway, the upshot is that I am going to do the following for now:
1) Upgrade to latest v2 security patch
2) Install some of the mods outlined above
3) Sit back and watch the spammers vanish.
Don't know when I'll have time to do this, and depending on how far out of date the patch is, I might just have to ditch all our mods and themes are revert to subsilver to save time as I've edited many, many core files for the new custom themes. An inevitable downside I'm afraid.
Anyway, when it's in progress you'll know as I'll take the forums off line and you won't be able to post anything. Note that if you are an admin with a cookie saved, you'll still be able to login though. I'll post a note on the forums when it's going to go ahead.
Anyway, the upshot is that I am going to do the following for now:
1) Upgrade to latest v2 security patch
2) Install some of the mods outlined above
3) Sit back and watch the spammers vanish.
Don't know when I'll have time to do this, and depending on how far out of date the patch is, I might just have to ditch all our mods and themes are revert to subsilver to save time as I've edited many, many core files for the new custom themes. An inevitable downside I'm afraid.
Anyway, when it's in progress you'll know as I'll take the forums off line and you won't be able to post anything. Note that if you are an admin with a cookie saved, you'll still be able to login though. I'll post a note on the forums when it's going to go ahead.
- ChristopheF
- Encyclopedist
- Posts: 1630
- Joined: Sun Oct 24, 1999 2:36 pm
- Location: France
- Contact:
I agree about not using an image captcha (they are slowly getting harder and harder to decipher even for human beings) and see if a simple text captcha would be enough to make the spammers vanish.
Christophe - Dungeon Master Encyclopaedia
- cowsmanaut
- Moo Master
- Posts: 4380
- Joined: Fri Jun 30, 2000 12:53 am
- Location: canada
you know what would be easy to do an a kind of fun addition 
insert a multiple choice questionaire that only asks one question
Show a picture of "you know who" then have the following check boxes
1. Darth vader
2. Dark Helmut
3. Betty Crocker
4. Lord Chaos
it's simple to answer for any DM fan, and is something that would stump any bot, or non DM fan
insert a multiple choice questionaire that only asks one question
Show a picture of "you know who" then have the following check boxes
1. Darth vader
2. Dark Helmut
3. Betty Crocker
4. Lord Chaos
it's simple to answer for any DM fan, and is something that would stump any bot, or non DM fan
- cowsmanaut
- Moo Master
- Posts: 4380
- Joined: Fri Jun 30, 2000 12:53 am
- Location: canada
Multiple choice with images or verbal questions wouldn't be anything special in my mind. It would be fairly easy to teach a bot which questions/images and answers go together and it could even automatically try the combinations to find out. There would have to be a ton of different questions or they would have to be dynamically generated to reduce the possibility of the same question appearing again.
Of course, if the questions and answers would be printed to a bitmap, the bot would first require text/image recognition to find out what it needs to know. To counter that the text would again have to be ciphered somehow to make it harder to read.. This is a difficult problem indeed..
Of course, if the questions and answers would be printed to a bitmap, the bot would first require text/image recognition to find out what it needs to know. To counter that the text would again have to be ciphered somehow to make it harder to read.. This is a difficult problem indeed..
Well, most spammers probably don't build any bots but use the ones that other people have created. That kind of takes away the extra effort.
I haven't really studied what usual spam bots are capable of, but if one needs those stupid barely readable captcha images to keep them away, I'd say simple text matching isn't a big task.
Of course, anything is worth trying to see whether it really works or not. I'm not saying that the multiple choice check would absolutely suck. I'm just worried that it wouldn't be that effective.
I haven't really studied what usual spam bots are capable of, but if one needs those stupid barely readable captcha images to keep them away, I'd say simple text matching isn't a big task.
Of course, anything is worth trying to see whether it really works or not. I'm not saying that the multiple choice check would absolutely suck. I'm just worried that it wouldn't be that effective.
Yes, but I think that if the possible answers are displayed and you only have to choose the correct one, a bot can easily try them all and remember whether the answer was correct or not. And every time it tries to do that it knows more and becomes more effective.. That is why I think they should not be multiple choice questions where the possible answers are displayed on the same page. It's very easily hackable by trial and error.
- cowsmanaut
- Moo Master
- Posts: 4380
- Joined: Fri Jun 30, 2000 12:53 am
- Location: canada
site been hacked again! Please make a forum backup, Gambit.. in case someone delete all the stuff, shit like that may happen 
Spoiler
(\__/) (\__/) (\__/) (\__/) (\__/) (\__/) (\__/) (\__/) (\__/) (\__/) (\__/) (\__/)
Spoiler
(@.@) (@.@) (@.@) (@.@) (@.@) (@.@) (@.@) (@.@) (@.@) (@.@) (@.@) (@.@)
Spoiler
(>s<) (>s<) (>s<) (>s<) (>s<) (>s<) (>s<) (>s<) (>s<) (>s<) (>s<) (>s<)
- Paul Stevens
- CSBwin Guru
- Posts: 4322
- Joined: Sun Apr 08, 2001 6:00 pm
- Location: Madison, Wisconsin, USA
I don't know anything about this but
I just received the following EMail:
from: pat_e_johnson@yahoo.com
You're one of the few people whose email I have. Each time I go to the forums I get this screen that says I've been hacked. I don't know what all that means but I think someone might have access to my account information. If there ends up being spam posted my by user name:Christopher, can you pass this email along to one of the webmasters there please? Thanks in advance.
Christopher
I just received the following EMail:
from: pat_e_johnson@yahoo.com
You're one of the few people whose email I have. Each time I go to the forums I get this screen that says I've been hacked. I don't know what all that means but I think someone might have access to my account information. If there ends up being spam posted my by user name:Christopher, can you pass this email along to one of the webmasters there please? Thanks in advance.
Christopher

