Is this captcha easy to hack?

Discussion in 'PHP' started by clades, Feb 13, 2011.

  1. #1
    I have a captcha that has 4 digits, they can be numbers or letters.
    The background is made by random lines that change for every request.
    The address of the captcha image is like: index.php?load=captcha.

    I get lots of spam despite having this captcha.
    Do the spammers use scripts to discard the background? Or i'm i making something wrong?

    I think captchas are quite useless and i'm starting to think its better to put approval requirement instead of captcha.
     
    clades, Feb 13, 2011 IP
  2. ThomasTwen

    ThomasTwen Peon

    Messages:
    113
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #2
    How do you check if the user entered the right digits?
     
    ThomasTwen, Feb 13, 2011 IP
  3. clades

    clades Peon

    Messages:
    579
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #3
    I use PHP $_SESSION...every request stores the answer in session, then it just check if it matches...
     
    Last edited: Feb 13, 2011
    clades, Feb 13, 2011 IP
  4. ThePHPMaster

    ThePHPMaster Well-Known Member

    Messages:
    737
    Likes Received:
    52
    Best Answers:
    33
    Trophy Points:
    150
    #4
    How are you passing the session ID? If you are like most websites, the sessions are stored in cookies (as opposed to being passed via the URL).

    Probably the spammers are just reading your cookies for the answer.
     
    ThePHPMaster, Feb 13, 2011 IP
  5. clades

    clades Peon

    Messages:
    579
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Hmm...what session id has to do with session contents?
    Aren't session' contents stored in server?
     
    clades, Feb 13, 2011 IP
  6. jazzcho

    jazzcho Peon

    Messages:
    326
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Use ReCAPTCHA.

    And yes, simple captcha is easily broken by spamming tools.
     
    jazzcho, Feb 13, 2011 IP
  7. clades

    clades Peon

    Messages:
    579
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #7
    recaptcha? i can type invalid words in recaptcha and it stills says its correct, bleh...
    I do it all the time in this forum...
     
    clades, Feb 13, 2011 IP
  8. jazzcho

    jazzcho Peon

    Messages:
    326
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #8
    I guess, that 's why Google paid big $$ to buy it. Because it 's worthless, huh? ;)
     
    jazzcho, Feb 13, 2011 IP
  9. clades

    clades Peon

    Messages:
    579
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Recaptcha Its not a true captcha, its main goal is to scan books...preventing spam is the least of their concerns...

    Anyways, is there any place where i can test my captchas? like a crazy spammer club? :D
     
    Last edited: Feb 13, 2011
    clades, Feb 13, 2011 IP
  10. jazzcho

    jazzcho Peon

    Messages:
    326
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Your own site. Since you are already getting lots of spam, simply test a few captcha services and see what makes the difference.
     
    jazzcho, Feb 13, 2011 IP
  11. clades

    clades Peon

    Messages:
    579
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #11
    That was a while ago, i no longer have that site that got spammed...
    Funny enough, nobody would say one day i would need spammers :D
     
    clades, Feb 13, 2011 IP