3 ms·
A good old Honey Pot helped us at All Quiet "a lot" with those attacks. Basically all attacks are remediated by this. No need for Cloudflare etc.
by mads_quist 6mo ago
A good old Honey Pot helped us at All Quiet "a lot" with those attacks. Basically all attacks are remediated by this. No need for Cloudflare etc.
- grey-area 6mo agoCan you expand on that? A separate honey pot sign up page invisible to real users, or something else?
- mads_quist 6mo agoYou add "hidden" inputs to your HTML form that are named like "First Name" or "Family Name". Bots will fill them out. You will either expect them to be empty or you fill by JavaScript with sth you expect. It's of course reverse-engineerable, but does the trick.
- grey-area 6mo agoThanks, I’ve seen scripted attacks bypass this sort of hidden input unfortunately (perhaps human assisted or perhaps just ignoring hidden fields).
- mads_quist 6mo agoSure, it's really basic of course.
- jaggederest 6mo agoThey often do actually ignore truly hidden fields (input type=hidden) but if you put them "behind" an element with css, or extremely small but still rendered, many get caught. It's similar to the cheeky prompt injection attacks people did/do against LLMs.
- grey-area 6mo agoThanks.
- alexjurkiewicz 6mo agoDoesn't that break password manager autofill?
- bevr1337 6mo agoDo you test this against password managers? Seems like this approach could generate false positives
- imhoguy 6mo agoWatch out, it may break accessibility of your service. If somebody fills these fields I would add extra verification e.g. accessible CAPTCHA.
- hrmtst93837 6mo ago[flagged]