in reply to Re: Code to Block Scripts/Harwesters (GD based?)
in thread Code to Block Scripts/Harwesters (GD based?)
Instead of putting your visitors through the hassle, you might put some time in it yourself, by snooping through logfiles (or create a script that does it for you) and find the ip addresses of the "users" that filled out the form more than once in a certain time span. (And yes, that wouldn't mean for certain that you're dealing with a bot, but when the form was filled out 20 times in under a minute, the chances are, you are dealing with a bot.)You can't go by ip. There are a lot of proxies out there, like those used by AOL. Even so, 30 bots each submitting 1 request a day for 30 days is 900 junk registrations. Maybe I'll accumulate 60 bots and do one every other day. Now you have to sit down and analze logs for hidden patterns, since a proxy will totally through your ip anlaysis off. :)
Come up with another one, I'll try and defeat it for you. :) (FINISH HIM!)
A tiny disclaimer claiming site security will give the users the "why". And if they ask why and threaten to go away, well. you can only extend your reach so far :) The question is "do you value your customers or not"? If not, then there is no argument against using visual or audio tricks to make sure you're handling a real human. But why not step it up a notch and require users to come see you in person with a valid passport? This would surely ban the "evil" scripts.If it's a free site like slashdot, with no customer support, I see no problem with a small disclaimer and someone eventually getting to the why questions if ever. I run an internal site that uses pre-generated, overly random passwords. The user can reset his password whenever he wants to another new pre-generated password. People hate it since they are hard to remember, but they put up with it since it's understood that I won't change it for security reasons. I tell them right out, I'm more likely to trust my random junk than someone typing in a really bad password later.
It's a matter of perspective on who gets to do what and why.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Code to Block Scripts/Harwesters (GD based?)
by b10m (Vicar) on Dec 30, 2003 at 20:21 UTC | |
by exussum0 (Vicar) on Dec 31, 2003 at 04:29 UTC |