Post details: Captchas Engaged

02/05/06

Permalink 02:32:59 pm, Categories: Website, 256 words   English (US)

Captchas Engaged

Today I decided to implement captchas on my blog. I dug around and found a neat PHP captcha class called hn_captcha. After a few hours of hacking on the b2evolution code I think I have it integrated pretty well.

It defaulted to using some Microsoft Word fonts which I didn't have (I don't remember when I last used a PC). As a replacement, I used Gentium, the free open source font recently released.

I've removed some restrictions on comments now, and now it's just wait and see how much spam I get. Judging from the previous spams, I cannot tell for sure if they are bot-based. Or at least they are trying to hide this. I have been logging the user agent for the spam posts and the last time 8 spams came in at about the same time, but their user agents looked like:

Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Opera/6.01 (Windows 98; U) [en]
Opera/6.04 (Windows XP; U) [en]
Opera/7.02 Bork-edition (Windows NT 5.0; U) [en]
Mozilla/4.0 (compatible; MSIE 5.01; Windows 98; QXW0332q)
Mozilla/4.0 (compatible; MSIE 5.01; Windows 95; USA On-Site)
Mozilla/4.0 (compatible; MSIE 4.0; MSN 2.6; Windows 95; Gateway2000)

The first 5 spams came in at the exact same time (to the second). The next 2 came within 2 minutes later. Are these botnets? If so, why the different user agents? The fact that they all came in within a small time frame says to me they are botnets. The spams that came in are pretty much useless since I was blocking URLs in comments. It's like they are testing botnets on my blog.

Comments, Pingbacks:

Comment from: George Jaros [Visitor] · http://www.georgejaros.com
While searching for some information about bas user agents I came across your blog. Just thought I'd mention that most of the malicious bots out there are able to dynamically change their user agents. This isn't too hard to do (see the User Agent Switcher extension for Firefox) and it makes blocking them that much more difficult.

I've been working on incorporating somb bot blocking scripts and abuse scripts (in ColdFusion) on my site. I've been keeping track of spiders, bots, and suspected bots/spiders as well as legitimate agents. I've also been keeping track of IP addresses that try to post SPAM messages to my guestbook. Most of the guestbook abusers have seemingly harmless user agents.

Check it out on my site at /Agents.cfm

You can also get a copy of my spider agents list at /includes/SpiderList.txt
Permalink 03/02/06 @ 09:08

Leave a comment:

 
 

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

Oh no, I cannot read this. Please, generate a

Viraj's Weblog

Donate to keep this site going!

Amount USD $

June 2011
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30      

Search

Categories


Misc

Syndicate this blog XML

What is RSS?

powered by
b2evolution