3 ms·
It only worked for so long. I had spammers post with the hidden field after being targeted. I then switched the field to a hashed simple time-based value, to w
by wakeupcall 3y ago
It only worked for so long. I had spammers post with the hidden field after being targeted.
I then switched the field to a hashed simple time-based value, to which they responded to by just fetching the page to get the value, and posting it back.
The posted content was often in two categories: links with stuffed keywords, or some common framework exploit (generally fetching a remote resource to test for exploitability).
While marginally entertaining in the beginning, it's just a waste of time unless you want to create some form of engagement within a blog..
- layer8 3y ago> I had spammers post with the hidden field after being targeted. Don’t they usually set a value on the hidden field? One approach is to check that no value is submitted for the field.
- wakeupcall 3y agoI checked for a specific default value (server-generated), so having no-value or a random value both wouldn't work. It is pretty effective in most cases at evading most bots and dumb attempts, but it's also trivial to defeat if you're being targeted.