Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

PHP Forum


You are currently viewing our PHP Forum as a guest. Please register to participate.
Login



Freelance Jobs

Reply
Contact form security
Old 11-04-2008, 09:49 AM Contact form security
dartiss's Avatar
Experienced Talker

Latest Blog Post:
November
Posts: 32
Name: David Artiss
Location: Nottingham, UK
Trades: 0
Hi everyone,

I'm planning on a major overhaul of the code I use for my contact forms. At the moment I use reCaptcha for security purposes but would prefer something of my own, rather than rely on a third party product.

What do people think of mathematical captchas? (e.g. What is 4+7?). I was wondering whether I should combine these with other types of questions. Is this likely to be a reliable method or should I stick with what I already have?

Cheers,
David.
dartiss is offline
Reply With Quote
View Public Profile Visit dartiss's homepage!
 
 
Register now for full access!
Old 11-04-2008, 09:59 AM Re: Contact form security
Junior Talker

Posts: 3
Name: torontolimo
Trades: 0
May be the right idea...

it is so simple and good .....using combo box is always good for the user too
__________________

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
torontolimo is offline
Reply With Quote
View Public Profile
 
Old 11-04-2008, 10:09 AM Re: Contact form security
dartiss's Avatar
Experienced Talker

Latest Blog Post:
November
Posts: 32
Name: David Artiss
Location: Nottingham, UK
Trades: 0
That's what I thought - reCaptcha has an audio option but there's nothing more accessible than a simple form box!

But I'll have to think up lots of questions to make it reasonably secure

David.
dartiss is offline
Reply With Quote
View Public Profile Visit dartiss's homepage!
 
Old 11-04-2008, 10:58 PM Re: Contact form security
Registered User

Posts: 78
Name: Joseph
Location: Texas
Trades: 0
Quote:
Originally Posted by dartiss View Post
That's what I thought - reCaptcha has an audio option but there's nothing more accessible than a simple form box!

But I'll have to think up lots of questions to make it reasonably secure

David.
I think if you did a simple math sum a computer might be able to hack that or figure out how to put the right answer.

I would just out a picture of some letters and numbers.
josephcohen is offline
Reply With Quote
View Public Profile
 
Old 11-04-2008, 11:26 PM Re: Contact form security
JohnDiamond's Avatar
Extreme Talker

Posts: 171
Name: John Diamond
Trades: 0
Hi Dartiss, I just found one idea that is quite interested. I looked up "recaptcha alternatives" on Google and found this: http://citalan.blogspot.com/2007/12/...ernatives.html

One of them offers to simple put 6 images of animals and have the user click on the right animal (click on the cat)... That is highly original! Or you can simply ask a question such as: "The color of snow is? (5 letters)"

What do you think? :-)
__________________
John

Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
JohnDiamond is offline
Reply With Quote
View Public Profile
 
Old 11-05-2008, 01:29 AM Re: Contact form security
mtishetsky's Avatar
King Spam Talker

Posts: 1,226
Name: Mike
Location: Mataro, Spain
Trades: 0
I suppose all these exotic methods of bot protection too user unfriendly. If you only need a captcha that does not use external sources try captcha from http://captchas.net/. It is free, it uses own server to generate images but validation is processed on your side.
__________________

Please login or register to view this content. Registration is FREE
-
Please login or register to view this content. Registration is FREE
-
Please login or register to view this content. Registration is FREE

And don't forget to give me talkupation!
mtishetsky is offline
Reply With Quote
View Public Profile Visit mtishetsky's homepage!
 
Old 11-05-2008, 02:15 AM Re: Contact form security
dartiss's Avatar
Experienced Talker

Latest Blog Post:
November
Posts: 32
Name: David Artiss
Location: Nottingham, UK
Trades: 0
Thanks for all the responses. However, all those recommended, including captchas.net (which I've used before), have accessibility issues.

Instead of just simple sums my plan is to have my code generate all sorts of random questions, and all randomly worded in different ways.

e.g.

Name the month that comes after August
Which month is 2 months before September
What day comes after Tuesday
What is eleven added to three
What is 2 x 3

The above is hardly unfriendly, it's accessible and, I hope, quite secure. What do you think?

David.
dartiss is offline
Reply With Quote
View Public Profile Visit dartiss's homepage!
 
Old 11-05-2008, 03:22 AM Re: Contact form security
chrishirst's Avatar
Missing! presumed drunk.

Posts: 42,385
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
I find a hidden field with a name that sounds important, then left empty works remarkably well.
Real users can't see the field to put anything in it, bots will have something in the field.

non-empty field? dump the form data!
__________________
Chris. ->>
Please login or register to view this content. Registration is FREE
<<-

A foolish consistency is the hobgoblin of little minds
Thought for today:- Is SEO the only industry where all the cowboys are Indians?
chrishirst is online now
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 11-05-2008, 03:37 AM Re: Contact form security
dartiss's Avatar
Experienced Talker

Latest Blog Post:
November
Posts: 32
Name: David Artiss
Location: Nottingham, UK
Trades: 0
Chris - thanks for that. I've already implemented that but find that if I remove the captcha I still get spammed

Never-the-less, I'm planning on improving it and having the captcha switable, so I can remove it if I want to later.

David.
dartiss is offline
Reply With Quote
View Public Profile Visit dartiss's homepage!
 
Old 11-05-2008, 11:52 AM Re: Contact form security
JohnDiamond's Avatar
Extreme Talker

Posts: 171
Name: John Diamond
Trades: 0
What kind of accessibility problems are you getting with the current captcha?
__________________
John

Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
JohnDiamond is offline
Reply With Quote
View Public Profile
 
Old 11-05-2008, 12:16 PM Re: Contact form security
dartiss's Avatar
Experienced Talker

Latest Blog Post:
November
Posts: 32
Name: David Artiss
Location: Nottingham, UK
Trades: 0
None. reCaptcha is okay - however, a good quality form field is going to be better than an audio option on a graphics-based Captcha.

My reason for change is merely to have more control over the product - hence writing my own.

David.
dartiss is offline
Reply With Quote
View Public Profile Visit dartiss's homepage!
 
Reply     « Reply to Contact form security
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.35257 seconds with 12 queries