5 ms·
I am running a website builder with > 20K sites. I use open contact forms without captcha. What worked for me is to use a one line javascript that places curren
by JimWestergren 4y ago
I am running a website builder with > 20K sites. I use open contact forms without captcha. What worked for me is to use a one line javascript that places current timestamp in a hidden input field that is default 0. Then I check on the backend and if the value is either 0 or time to fill out and send the form is less than 4 seconds I block as spam. This blocks more than 99% of spam and also takes care of most human copy paste spam as well.
- naillo 4y agoI like this solution because spammers are unlikely to try to get around it. A delay eats into their time budget and they can't introduce a human-like waiting time on every site they try to spam, better to just move on to find cheaper targets.
- walls 4y agoYou could just decrease the timestamp instead of actually waiting.
- naillo 4y agoI meant for general spammers who goes after tons of sites mostly blind. I agree it would not help for a targeted attack.
- JZerf 4y agoI'm already using this timestamp technique on my website and so far no bot operator has bothered trying to work around this. However even if some bot operator were to specifically target a website using this technique and try to decrease the timestamp, I believe you could still force a bot to wait by just changing the website to use something like a cryptographic nonce that includes a timestamp instead of just a simple timestamp that can be understood easily.
- robalni 4y agoIf you don't want to require users to run javascript you should be able to make the server generate the timestamp.
- mariusor 4y agoHow do you do that, without bots being able to circumvent the feature?
- sschueller 4y agoYou could generate a CSRF token or something similar in a hidden filed based on a JWT token (yes I know) on the server side. The JWT token can either contain some timestamp after which it's valid or the time it was created.
- robalni 4y agoPeople will be able to write programs that circumvent the feature but that's also true for the javascript solution. The point of it was that it gets rid of most spam because most bots fill in the form faster than 4 seconds and are not made to circumvent this feature.
- Aachen 4y agoBots can also circumvent this JS thing, so it's the same either way. <?php echo '<input type=hidden name=starttime value='.time().'>'; On submit: <?php if (time() - $_POST['starttime'] < 4) die('2fast4me'); Revealing the error condition (that it was submitted too fast) is nice for users and bots alike, of course. Up to you. I've had websites where I was too fast in submitting a form before. Not any kind of anti-spam, just their server was so fricking slow that I had input the date (iirc it was a reservation system) and clicked next before the JS blobs had finished triggering each other and fully loaded. It would break the page somehow with no visual indication. I found out by looking in the dev console and noticing stuff was still loading in the background. How normal people are able to use the Internet with how often I need the dev console to do entirely ordinary things is a mystery to me.
- JimWestergren 4y ago
- JZerf 4y agoI also use essentially the same technique (although I have the server generate the timestamp instead of using JavaScript) on my website and concur that this is a highly effective technique for blocking bot submissions.