OT and FYI: Article on security logons

The place for discussions and decisions about the forum
Post Reply
User avatar
RoryOF
Moderator
Posts: 34611
Joined: Sat Jan 31, 2009 9:30 pm
Location: Ireland

OT and FYI: Article on security logons

Post by RoryOF »

Apache OpenOffice 4.1.15 on Xubuntu 22.04.4 LTS
User avatar
Hagar Delest
Moderator
Posts: 32655
Joined: Sun Oct 07, 2007 9:07 pm
Location: France

Re: OT and FYI: Article on security logons

Post by Hagar Delest »

Another recent solution (perhaps more accessible): http://blog.nothingbutsoftware.com/2012 ... ut-captcha and http://areyouahuman.com/demo
LibreOffice 7.6.2.1 on Xubuntu 23.10 and 7.6.4.1 portable on Windows 10
User avatar
kingfisher
Volunteer
Posts: 2123
Joined: Tue Nov 20, 2007 10:53 am

Re: OT and FYI: Article on security logons

Post by kingfisher »

There are some captchas that require many attempts to get right. I found a novel approach on the Chakra registration page. Unfortunately I forgot to copy the url of that page after logging out but you should be able to see a link to it by loading the bbs page.

I am attaching a snapshot. I was fooled and I'm not a bot. :(
captcha.jpeg
Apache OpenOffice 4.1.9 on Linux
TerryE
Volunteer
Posts: 1402
Joined: Sat Oct 06, 2007 10:13 pm
Location: UK

Re: OT and FYI: Article on security logons

Post by TerryE »

Once we require the users to enter their OpenOffice version and check that the response contains "office" and "2." or "3." we have eliminated all generic phpBB registration attack bots. Yes, it is easily susceptible to specific-to-this-forum coded attack, but I very much doubt that any attacker will go to this effort for a single forum with our usage patterns and volumetrics.

So most of our successful registration attacks employ cheap sweat-shop labour. This type of human attach will easily defeat this type of security measure.
Ubuntu 11.04-x64 + LibreOffice 3 and MS free except the boss's Notebook which runs XP + OOo 3.3.
Post Reply