Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - blank form submission with captcha
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Forum Lockedblank form submission with captcha

 Post Reply Post Reply
Author
weblake View Drop Down
Newbie
Newbie


Joined: 04 April 2008
Status: Offline
Points: 3
Post Options Post Options   Thanks (0) Thanks(0)   Quote weblake Quote  Post ReplyReply Direct Link To This Post Topic: blank form submission with captcha
    Posted: 04 April 2008 at 3:44pm
Hi, I hope someone may be able to shed some light on an issue we are having. We are using captcha (have been for about six months) on our site after being hit by spammers through our contact form.
 
The form uses captcha and if the captcha is completed the contents of the form are emailed to the client. Also we have form validation so if a human is submitting the form even with the correct captcha the form cannot be submitted.
 
For the past month though our client has been getting blank emails from the site. This suggests that something is managing to bypass the captcha - but not filling in the form - which has validation.
 
Has anyone else experienced this problem? I noticed that Bruce has mentioned elsewhere that if the images are noted then a bypass can be created - but we cant understand how the captcha and form validation can both be bypassed. I need to find a solution to this problem for my client.
 
Any feedback would be greatly appreciated.
 
Many thanks in advance.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 04 April 2008 at 9:34pm
You should test file that sends the email to see if it can be directly submitted to and if it can are their stops to prevent the code that sends the email from running.

A new version of Web Wiz CAPTCHA is also being developed and is only weeks away from release. The new version, instead of displays one of the 200+ images in it's library will create bitmap images on the fly.

The added bonus to this method is not only will it be more secure with randomly created images on the fly, but you will be able to configure the colours, distortion level, type of distortion, etc. yourself in a setup file.
Back to Top
weblake View Drop Down
Newbie
Newbie


Joined: 04 April 2008
Status: Offline
Points: 3
Post Options Post Options   Thanks (0) Thanks(0)   Quote weblake Quote  Post ReplyReply Direct Link To This Post Posted: 05 April 2008 at 11:39am
Many thanks for your reply Bruce. I understand your response and will look into it.
 
I look forward to the new release and will inform my client that this will be the way to go when it's available.
 
Kind Regards
Back to Top
Scotty32 View Drop Down
Moderator Group
Moderator Group


Joined: 30 November 2002
Location: Manchester, UK
Status: Offline
Points: 1682
Post Options Post Options   Thanks (0) Thanks(0)   Quote Scotty32 Quote  Post ReplyReply Direct Link To This Post Posted: 05 April 2008 at 11:40am
Originally posted by weblake weblake wrote:

For the past month though our client has been getting blank emails from the site. This suggests that something is managing to bypass the captcha - but not filling in the form - which has validation.


This maybe a silly question, but is the validation done by Javascript or ASP?

As if its javascript - it will be extremely easy to bypass, and would need ASP validation added as well.

S2H.co.uk - WebWiz Mods and Skins

For support on my mods + skins, please use my forum.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.