Post by Sokonomi » Wed Apr 18, 2018 2:09 pm

I was wondering if there is a better alternative to the pre installed reCAPTCHA, since bots still seem to be getting through those, even on highest settings.

OC 3.0.2.0

Active Member

Posts

Joined
Sun Sep 30, 2012 4:52 am

Post by straightlight » Wed Apr 18, 2018 8:01 pm


Dedication and passion goes to those who are able to push and merge a project.

Regards,
Straightlight
Programmer / Opencart Tester


Legendary Member

Posts

Joined
Mon Nov 14, 2011 11:38 pm
Location - Canada, ON

Post by Johnathan » Thu Apr 19, 2018 4:46 am

I don't believe bots can break recaptcha, so I'd suspect that you have another exploit somewhere. The CSRF protection may help, or you may want to hire someone to look at your installation for you, to see what's really going on and if it is indeed the captcha. If you need to find a developer, you should post a request in the OpenCart "Commercial Support" forum, which is checked by a number of OpenCart developers. You can also try checking out the OpenCart "Partners" area.

Image Image Image Image Image


User avatar
Administrator

Posts

Joined
Fri Dec 18, 2009 3:08 am


Post by Sokonomi » Thu Apr 19, 2018 5:00 am

Ive got spam mail coming in with the default contact form subject title, so it has to be through that somehow. My 3.0.2.0 build has been live only 3 weeks and its been doing it since pretty much the start. So either the contact form comes with a hole in the code, or bots are managing to crack through recaptcha now. :(

Active Member

Posts

Joined
Sun Sep 30, 2012 4:52 am

Post by straightlight » Thu Apr 19, 2018 8:20 am

The two solutions above have been provided. Depending on those specifically should not be a problem against CSRF attackers.

Dedication and passion goes to those who are able to push and merge a project.

Regards,
Straightlight
Programmer / Opencart Tester


Legendary Member

Posts

Joined
Mon Nov 14, 2011 11:38 pm
Location - Canada, ON

Post by paulfeakins » Thu Apr 19, 2018 6:20 pm

Johnathan wrote:
Thu Apr 19, 2018 4:46 am
I don't believe bots can break recaptcha, so I'd suspect that you have another exploit somewhere.
Possibly but I wouldn't be surprised if it gets broken soon, OCR is very good and getting better all the time. We're seeing more hacks and hack attempts than ever these days too!

UK OpenCart Hosting | OpenCart Audits | OpenCart Support - please email info@antropy.co.uk


User avatar
Guru Member
Online

Posts

Joined
Mon Aug 22, 2011 11:01 pm
Location - London Gatwick, United Kingdom

Post by straightlight » Thu Apr 19, 2018 8:12 pm

While this is true, Google or other related providers will probably be ready for it. It is only about awaiting for their next solutions.

Dedication and passion goes to those who are able to push and merge a project.

Regards,
Straightlight
Programmer / Opencart Tester


Legendary Member

Posts

Joined
Mon Nov 14, 2011 11:38 pm
Location - Canada, ON

Post by straightlight » Thu Apr 19, 2018 8:34 pm

I have just received words over PM that by following what I have suggested above: viewtopic.php?f=202&t=203733#p721255 still works accordingly even from yesterday night's installation. These extensions are still bullet proof.

Dedication and passion goes to those who are able to push and merge a project.

Regards,
Straightlight
Programmer / Opencart Tester


Legendary Member

Posts

Joined
Mon Nov 14, 2011 11:38 pm
Location - Canada, ON

Post by frank79 » Tue May 01, 2018 6:16 pm

Alternative solution to reCaptcha (it's a commercial extension):
https://www.opencart.com/index.php?rout ... n_id=13097
Features
- Invisible to users
- 5 levels of protection;
- Support for the most popular third party extensions and themes.
Free Customer Support

Our new Opencart Extension:
AI Assistant - automatic product and category text generator


User avatar
New member

Posts

Joined
Thu Apr 26, 2012 12:01 am
Who is online

Users browsing this forum: DigitCart and 108 guests