Honeypots, captchas and spam bots

You do still get naive users, and even as you say 'power users'. They exist, they could potentially be a client that fills in the form. As I said, that is where the administrator needs to draw the line on what technology is mandatory and what not.

But from a paying client's point of view, if you go to them and say I can make this system work in 'x' manner, but disrupting 'y' users they might not find it appealing.

A naive user almost certainly wouldn't turn JS off. My bet is not even Captcha would work without JS.

Assuming your users have JS enabled is a 99.999% certainty.
 
Ok, this is a statement to both below quotes. Please don't take it up wrong, but as constructive.

Of course - that was the intention of the OP - I want to get as much info and input as possible

Ok, so with your code you have given me right here I can break your method just by hitting F5 and submitting it immediately.

I think you have misunderstood my form or I have misunderstood your statement but my thinking is a bot will "fill" the form in 0 seconds flat. The bot's SPAM value will be a second less than the the processor's epoch value. This means that the form was completed in a time TOO FAST for a human. Refreshing (F5) empties all form values so the form would have to be completed again.

MY idea is to quarantine any submissions that take place within 3 seconds of the form being accessed. If it takes 20 seconds, send the form to the client. If it takes 1 second, the form comes to me to review first - so the user has no interaction with the spam logic.
 
The timestamp method has been used many times before, and adapting a bot to delay a submission is possible. Most likely not a "feature" of your average bot, but it will still be there.

I will keep an eye out for that and report once I have enough data

Secondly, depending on your browser, F5 wont clear all the fields and only certain ones such as the password type. Ctrl+F5 would clear them completely.

Which browser retains this info? I have tested - and not succeeded in keeping form data - on IE 10, 11 Chrome Safari. I see FireFox keeps it. I'll comment on this shortly...

I have many times before filled in a form, closed my browser either by force closing it (when I am too lazy to close everything) or using windows hibernating. Now, when I open my browser again, those pages will load up automatically with the content filled in, but because you are setting the value of your timestamp

...these are exceptions and rather unusual ones at that and I am quite happy to discard them - or at least quarantine them, as is happening.

Again, using your example, did you test out what would happen if the bot changes the spam value to a string? It would actually succeed as with the following as an example:

Ja - I put that simplified code in for a reason - did not want to go through integer tests etc so unusual submissions would be caught. But as it stands, the spambot would firstly have to know what is happening on the processing side. Without that knowledge, changing the value of a hidden form from integer to text has no logical reason. If it did, then I could easily filter all spam out by making the responder reject all text - cos, you know, the spam bot made some integer text. For the spam bot to make such fundamental changes, it would need to have a reason - right now, it does not. Think of the code logic that the spam bot is using. Is there anything in its logic that suggests it must change an integer value to a text value?

But this concept as a filter method in my opinion is flawed. Yes, you can do many checks before the code to ensure that there are checks for the right values, such as is "spam" an integer, etc., but again, the system should be developed keeping in mind that there various types of people, using various type of equipment out there.

But where is the flaw? If I am gonna kill the once in a billion submission where the guy force-quit Firefox, I am not going to lose sleep over that.
 
On the contrary, a naive user who was told by his super user buddy that JavaScript is bad is more likely to turn it off and never enable it compared to a an average Joe who read that it could be dangerous.

The matter of fact stays, don't use JavaScript to build your system/application/website. JavaScript should be used to enhance your solution.

Wtf are you on about? Are you insane or just behind the times? The web as we know it today is built on JavaScript. AJAX, jQuery, and everything else that makes your browsing experience better runs off JavaScript.

Find a popular website for me which does not run on JavaScript, please.

Your naive user will quickly run back to his power user buddy because Facebook won't work properly and neither will Gmail, Youtube, or any other modern site. Turning JS off almost always results in a warning telling you the site is dependent on it.
 
Typical - since coding it this morning, not a single spambot visitor. Don't these spammers know I have work to do :p
 
Google, Gmail, Yahoo and even on MyBroadband I can work the site fine without JavaScript enabled. Oh and Facebook, does also work. So, make sure about your facts before posting. Yes, there is a warning, yes there is functionality that's not working as intended, yes they rely on JavaScript for some thing, but their system works. THUS they are using JavaScript to enhance their user experience, not DICTATE it.

If you want to use systems with dated functionality, be my guest. I used to work for a company doing web application development (not web design) with ASP.NET and a lot of functionality included jQuery like dialog boxes and gridviews to display and manipulate data, with AJAX and JSON.

With Gmail you'd need to return to Gmail's basic view/functionality which is only fine if you're on dialup connection, otherwise it's a pain in the arse. I would assume the same is true for Yahoo.
vBulletin without JavaScript/AJAX is a mess of continuous postbacks. I used to run a vB forum for many years and know this.
You cannot use Facebook chat without JS.
Twitter is viewable, but you cannot tweet.
 
Use CloudFlare :whistle: reduces 95% spam bots and since they have a database that will be updated with new threats it's a good option.

Not much we can do on spam :(
 
Exactly my initial point. They use it to enhance their experience. It is not built upon it. Facebook does work, yes some functionality isn't there like chat, etc. but Facebook as it core what is was developed for works.
Twitter doesn't, yet millions all over the world still use it.

Saying fine, if you want to use outdated technology to be your guest. I tell you want, your next client you have, tell them about all this awesome things you can do, but tough luck for the 'x' amount of clients they loose, take it or leave. They will tell you, there's the door, be my guest.

Most of them are like a bunch of monkeys. If it's shiny, they couldn't give a **** about the 1% of customers who are still running Netscape 1.0.
 
That's good to hear. Just as a scenario. What if one of those bots cache your form with default values. This time around they might be stopped, but if the hidden field is cached and reads the default value back into the form it will post the form with a timestamp of x amount of seconds ago (could be hours, days, etc.), when it was cached.

Those darling, darling spammers. Today, they had their go again.

One genuine hit: took 326 seconds from loading contact form to submitting. 5 Spammers. Taking 0 to 4 seconds each. I am delighted with this result. One small thing that these dears taught me however is that I can add just another small thing to my detection on the other side. Here's an example submission:
Code:
The following was posted: 
spamkiller::84897
email::steep777@yahoo
mailinglist::1
firstname::Ricky
surname::Ricky
message::No, I'm not particularly sporty <a href=" http://www.blah ">800 mg ibuprofen</a>  To request an emergency prior authorization during any day of the week between  <a href=" http://www.blah ">price minoxidil india</a>  Page 96 of 111  <a href=" http://www.blah ">purchase levlen</a>  licensed pharmacy or a dispensing physician, in accordance with Virginia State Board of  <a href=" http://www.blah">where to buy generic propecia online</a>  708 Exceeds NY Allowable Refill Maximum
 
address1::WkajDUALyQdSfZd
address2::IjLmWZguxSMDFQT
address3::BOeetKXmplAw
zipcode::15418
magazinelist::1
country::USA

I killed the web addresses to prevent google picking the links up here. Do you see that opportunity they gave me? My php will now be modified ever so slightly to kill messages that:

(a) Fail the time limit AND
(b) Contain http:// as a substring
 
Great. I do presume you wouldn't have a normal poster that would potentially enter a link? Maybe use the that with collaboration to the post time?

It is possible - on the very incredibly rare occasion - that a user may enter a link. Hence, the rule will be fail on (a) and (b) not (a) or (b).

Or maybe, have the front-end inform the user that http:// linking isn't accepted and their application wont go through.

I'd never do that for a simple enough reason: rejecting the user is like declining the business. I'd far rather receive the spam than send a buyer elsewhere. I will see how it goes the next day or two with just the time trap. Then, I will add the HTTP trap. I think I may have the best case scenario here: the flagged messages are not deleted, they merely quarantined. In almost every instance of this kind of spam, at three or four messages end up being sent. So, if I see a batch of 4 mails all quarantined, chances I good I can just delete the whole lot.

Time will tell...

EDIT: One thing I would love to do but cannot because it effectively kills the idea is to tell the spammer that their BS failed. Run their noses in it. Small price to pay, I suppose.
 
More hits this morning - 5 again.
Code:
From	Subject	Received	Size	Categories	
[email protected]	[SPAM] (2): Website Feedback	1:51 AM	6 KB		
[email protected]	[SPAM] (3): Website Feedback	1:51 AM	6 KB		
[email protected]	[SPAM] (2): Website Feedback	1:51 AM	6 KB		
[email protected]	[SPAM] (1): Website Feedback	1:51 AM	6 KB		
[email protected]	[SPAM] (0): Website Feedback	1:51 AM	6 KB
Number in brackets is the seconds between form and submit. This is an excellent method for me. If they never wise up to it, it work. If customers manage to submit in 3 or less seconds, then they're gonna fall into the spam hole.
 
More hits this morning - 5 again.
Code:
From	Subject	Received	Size	Categories	
[email protected]	[SPAM] (2): Website Feedback	1:51 AM	6 KB		
[email protected]	[SPAM] (3): Website Feedback	1:51 AM	6 KB		
[email protected]	[SPAM] (2): Website Feedback	1:51 AM	6 KB		
[email protected]	[SPAM] (1): Website Feedback	1:51 AM	6 KB		
[email protected]	[SPAM] (0): Website Feedback	1:51 AM	6 KB
Number in brackets is the seconds between form and submit. This is an excellent method for me. If they never wise up to it, it work. If customers manage to submit in 3 or less seconds, then they're gonna fall into the spam hole.

Check this blog post out (http://nedbatchelder.com/text/stopbots.html). I'm going to be implementing these techniques in the new year. The one addition is that I'll be using a CAPTCHA as a honeypot...so users don't see it, but spam bots will fill it out.
 
a VERY nice Wordpress plugin that has helped my company prevent these types of visits and comment / register spam
"Stop Spammers"
Stop Spammers has stopped 2326 spammers since 2013/11/27.
 
UPDATE

Over the last 6 months, this method has been used to flag potential spam. So far it has been highly effective as it has not flagged a single bona fide message as definite spam (some of them as maybe-spam). So now, it has been implemented permanently.

SPAM that has gotten through in 6 months without being flagged = < 10 messages, btw, when I was used to 10 per day.
 
Top
Sign up to the MyBroadband newsletter
X