Spam comments now getting through?

brashquido - September 29, 2007 - 23:39
Project:reCAPTCHA
Version:6.x-1.x-dev
Component:reCAPTCHA Captcha
Category:support request
Priority:normal
Assigned:Unassigned
Status:active
Description

Hi All,

I've been using the Captcha module with my Drupal 4.7 install and the Textimage module and recently decided to give reCaptcha a try. Everything seems to work fine, however since migrating to reCaptcha I have had several spam comments that have seemed to have found a way through the captcha process. This never happened using the Textimage module and was wondering if anyone else had experienced this?

#1

Rob Loach - October 1, 2007 - 06:14

Hmmm, I haven't been experiencing this. Try updating to the 4.7.x-1.x-dev version?

#2

brashquido - October 1, 2007 - 07:26

ok, I'll give that a shot. If the problem continues I'll post back.

#3

brashquido - October 2, 2007 - 10:22
Version:4.7.x-1.0» 4.7.x-1.x-dev

Ok, I've upgraded to the 4.7.x-1.x-dev version as requested, but these spam comments still seem to be getting through. I haven't deleted the comments this time, so if you would like any details on them I can get them for you. All comments were made on the same node from the same IP address from the Ukraine with about 2 hours between each of them. Don't know why these bots are getting through reCaptcha where they are not getting through the standard Textimage module, but I've been seeing this with other captcha tasks as well such as with the Gallery2 photo album software.

#4

Rob Loach - October 2, 2007 - 21:23
Status:active» postponed (maintainer needs more info)

You might want to bring up the issue on the reCAPTCHA Google Group as they might be able to help you. If the spam is coming from a computer, then it's something that they might have to fix. Worse comes to worse, they can add the IP to the reCAPTCHA IP block list.

#5

brashquido - October 2, 2007 - 22:20

Ok, posting there now. Hopefully I don't get the same outcome as the Wordpress user did...

#6

brashquido - October 3, 2007 - 14:45

Got a reply from reCaptcha support who think it is a problem with the Drupal module. The IP address that all this spam is coming from does not show up in their logs, yet all the other IP addresses of successful attempts do. Would seem this bot has found a way to circumvent the captcha process with this module?

#7

Rob Loach - October 3, 2007 - 19:02

Hmm, I had a look at the code and the 4.7 branch is using the API correctly, the best guess I have is that the Captcha API of the 4.7 branch is acting up. Considering 4.7 is going to be deprecated once Drupal 6 is released, have you considering making the update to 5?

#8

brashquido - October 3, 2007 - 21:53

An upgrade to Drupal 5 is on the cards, but not in the short term. I might go back and look at the Akismet or Spam modules as they do a fair job of spam detection without requiring any special user input.

#9

Rob Loach - October 3, 2007 - 22:08

A combination of both reCAPTCHA and Akismet would do well, as reCAPTCHA would keep the bot spammers out, while Akismet would keep the human spammers out.

#10

brashquido - October 3, 2007 - 23:09

Ok, I'll give this a shot. Would it be possible that this bot has actually found a captcha work around similar to the one described for the Captcha module here;

http://drupal.org/node/114364

#11

fgm - August 11, 2009 - 13:02
Version:4.7.x-1.x-dev» 5.x-2.5
Status:postponed (maintainer needs more info)» active

It looks like they're getting through again, since at least june 2009. Strangely enough, most commenters getting through have their email address pointing to "http://recaptcha.net" or "http://wordpress.org/extend/plugins/wp-recaptcha/" . Looks like a new exploit.

#12

fgm - August 11, 2009 - 13:08
Version:5.x-2.5» 6.x-1.x-dev

Actually, this is with 6.x-2.0-rc2, not 5.x, but strangely enough it is not suggested in the list of versions for issues.

#13

Rob Loach - August 11, 2009 - 15:36

Could you please try out the lastest dev snapshot? I committed a patch yesterday that brought it back to play more nicely with the CAPTCHA API.

#14

fgm - August 11, 2009 - 16:07

Updated and reactivated instead of the Math captcha (to which I had returned in the meantime). I'm usually spammed every day, so we should know whether this fixes the problem in a few days.

#15

fgm - August 11, 2009 - 23:47

Four new intrusions. I can't but think the problem lies in reCaptcha itself. Maybe the problem popularized by the TIME exploit hasn't been fixed? http://musicmachinery.com/2009/04/27/moot-wins-time-inc-loses/

#16

fgm - August 16, 2009 - 07:33

After a few days back with Math, it appears the problem is not with reCaptcha, but with captcha itself. Spammers go through whatever the captcha used. Recreating issue in Captcha.

#17

nicpottier - October 15, 2009 - 17:33

We are seeing the same problems on our site using reCaptcha...

Running Drupal 6.9, Captcha 6.x-2.0 and reCAPTHCA 6.x-1.3.

Comments are coming through.. I have a hard time believing it is reCAPTCHA failing, though I suppose it is possible.

 
 

Drupal is a registered trademark of Dries Buytaert.