<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Captcha is failing! Is there another way</title>
	<atom:link href="http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/</link>
	<description>Start-ups, Maps and Local Search in New Zealand</description>
	<pubDate>Wed, 19 Nov 2008 16:17:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Shoaib</title>
		<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1033</link>
		<dc:creator>Shoaib</dc:creator>
		<pubDate>Sat, 24 Nov 2007 12:07:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1033</guid>
		<description>hxxp://shoaib.no-ip.org/iptables.sh


that should cover pretty much all of new zealand :)</description>
		<content:encoded><![CDATA[<p>hxxp://shoaib.no-ip.org/iptables.sh</p>
<p>that should cover pretty much all of new zealand <img src='http://blog.projectxtech.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john</title>
		<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1030</link>
		<dc:creator>john</dc:creator>
		<pubDate>Sat, 24 Nov 2007 06:42:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1030</guid>
		<description>Iptables is too much work. I've done that before to stop spammers hammering my box. Regarded too much work.

We have a email validation, its still not stopping registrations.

The new captcha seems to be working as I've had no spam registrations since. fingers crossed.

John</description>
		<content:encoded><![CDATA[<p>Iptables is too much work. I&#8217;ve done that before to stop spammers hammering my box. Regarded too much work.</p>
<p>We have a email validation, its still not stopping registrations.</p>
<p>The new captcha seems to be working as I&#8217;ve had no spam registrations since. fingers crossed.</p>
<p>John</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shoaib</title>
		<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1029</link>
		<dc:creator>Shoaib</dc:creator>
		<pubDate>Fri, 23 Nov 2007 21:04:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1029</guid>
		<description>iptables ftw!</description>
		<content:encoded><![CDATA[<p>iptables ftw!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john</title>
		<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1028</link>
		<dc:creator>john</dc:creator>
		<pubDate>Thu, 22 Nov 2007 23:53:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1028</guid>
		<description>Hmmm Google groups is sounding appealing...

I installed a more advanced captcha and hopefully that will offset the default actions to stop the scripts from doing their thing...</description>
		<content:encoded><![CDATA[<p>Hmmm Google groups is sounding appealing&#8230;</p>
<p>I installed a more advanced captcha and hopefully that will offset the default actions to stop the scripts from doing their thing&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: M Freitas</title>
		<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1027</link>
		<dc:creator>M Freitas</dc:creator>
		<pubDate>Thu, 22 Nov 2007 23:52:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1027</guid>
		<description>In addition to hidden form (which should be discarded if filled because humans wouldn't do it), try doing a different thing: people should enter their email addresses requesting to join... Send an encoded URL containing the email address. Whe the actual registration comes in check that the e-mail used matches the one in the encoded URL. This is what I do on Geekzone and simply reduces spammers a lot...</description>
		<content:encoded><![CDATA[<p>In addition to hidden form (which should be discarded if filled because humans wouldn&#8217;t do it), try doing a different thing: people should enter their email addresses requesting to join&#8230; Send an encoded URL containing the email address. Whe the actual registration comes in check that the e-mail used matches the one in the encoded URL. This is what I do on Geekzone and simply reduces spammers a lot&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen Judd</title>
		<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1026</link>
		<dc:creator>Stephen Judd</dc:creator>
		<pubDate>Thu, 22 Nov 2007 22:05:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1026</guid>
		<description>Another angle: just set up a Google Group, and let them deal with it...</description>
		<content:encoded><![CDATA[<p>Another angle: just set up a Google Group, and let them deal with it&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen Judd</title>
		<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1025</link>
		<dc:creator>Stephen Judd</dc:creator>
		<pubDate>Thu, 22 Nov 2007 21:17:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1025</guid>
		<description>This may be useful to you:

http://www.codinghorror.com/blog/archives/001001.html

Basically, some captchas simply suck and are susceptible to automated OCR - others don't and aren't.

FWIW, other strategies include:
- multiple forms hidden by Javascript/CSS (don't allow users that post to the hidden form)
- change default variable names
- charge default posting URLs
- add extra steps, eg mandatory preview
- queue the first comment from a new user for moderation

There's no solution that doesn't involve customisation - automated attackers focus their efforts on "out of the box" configurations.</description>
		<content:encoded><![CDATA[<p>This may be useful to you:</p>
<p><a href="http://www.codinghorror.com/blog/archives/001001.html" rel="nofollow">http://www.codinghorror.com/blog/archives/001001.html</a></p>
<p>Basically, some captchas simply suck and are susceptible to automated OCR - others don&#8217;t and aren&#8217;t.</p>
<p>FWIW, other strategies include:<br />
- multiple forms hidden by Javascript/CSS (don&#8217;t allow users that post to the hidden form)<br />
- change default variable names<br />
- charge default posting URLs<br />
- add extra steps, eg mandatory preview<br />
- queue the first comment from a new user for moderation</p>
<p>There&#8217;s no solution that doesn&#8217;t involve customisation - automated attackers focus their efforts on &#8220;out of the box&#8221; configurations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john</title>
		<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1024</link>
		<dc:creator>john</dc:creator>
		<pubDate>Thu, 22 Nov 2007 20:16:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1024</guid>
		<description>We're using the defualt captcha as installed by phpBB. I'm note sure if we can overload it with something else.</description>
		<content:encoded><![CDATA[<p>We&#8217;re using the defualt captcha as installed by phpBB. I&#8217;m note sure if we can overload it with something else.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kirill volkov</title>
		<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1023</link>
		<dc:creator>kirill volkov</dc:creator>
		<pubDate>Thu, 22 Nov 2007 20:15:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1023</guid>
		<description>Have you seen this article (Has CAPTCHA Been "Broken"?): http://www.codinghorror.com/blog/archives/001001.html
It gives good comparison of different captchas.</description>
		<content:encoded><![CDATA[<p>Have you seen this article (Has CAPTCHA Been &#8220;Broken&#8221;?): <a href="http://www.codinghorror.com/blog/archives/001001.html" rel="nofollow">http://www.codinghorror.com/blog/archives/001001.html</a><br />
It gives good comparison of different captchas.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Glen Barnes</title>
		<link>http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1020</link>
		<dc:creator>Glen Barnes</dc:creator>
		<pubDate>Thu, 22 Nov 2007 19:43:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.projectxtech.com/2007/11/23/captcha-is-failing-is-there-another-way/#comment-1020</guid>
		<description>What type of CAPTCHA are you using? I was wondering if you have tried the RE-CAPTCHA as I wanted to see if this was any better (digitise books AND hopefully stop SPAM).</description>
		<content:encoded><![CDATA[<p>What type of CAPTCHA are you using? I was wondering if you have tried the RE-CAPTCHA as I wanted to see if this was any better (digitise books AND hopefully stop SPAM).</p>
]]></content:encoded>
	</item>
</channel>
</rss>
