SSL Labs ScoreSecurityHeaders.io ScoreHSTS Preloaded

Log in to participate

There is no cost to join RicheyWeb, and membership is a requirement to submit bug reports and participate in the support forums.

× Welcome to the Kunena forum!

Tell us and our members who you are, what you like and why you became a member of this site.
We welcome all new members and hope to see you around a lot!

Hash Cash

More
3 months 3 weeks ago #34177 by Sharon
Replied by Sharon on topic Hash Cash
I just completed a whole setup that you are asking Richey about.

It was simple to do, and as as far as I know, HashCash is doing it's job.

For my client it helps the visually impaired Submit forms without the need to play click the 'thing' games.

Myself, I have several sites that use Form add-ons but prefer to use Joomla's own Contact - because I think Joomla will improve it believe I'm not shackled to a subscription for updates (sometimes AKA bug fixes).

~s~

Please Log in or Create an account to join the conversation.

More
3 months 3 weeks ago #34179 by Hawkeye4
Replied by Hawkeye4 on topic Hash Cash
Richey thanks for the update. Sharon equally thank you for the vote of confidence re the solution.
Have put it on tomorrow's agenda.
Cheers.... Rod

Please Log in or Create an account to join the conversation.

More
3 months 3 weeks ago #34180 by Hawkeye4
Replied by Hawkeye4 on topic Hash Cash
Implemented using the Joomla contact form.
Worth a mention ... one small problem with the Joomla contact form is that it does allow an additional field for a BCC etc. addressee which can be handy if you are monitoring a
site's forms. Cheers..... Rod

Please Log in or Create an account to join the conversation.

More
2 months 3 weeks ago #34263 by Hawkeye4
Replied by Hawkeye4 on topic Hash Cash
In response to your request for details re a possible bug Have just disabled the Hash Cash plugin for possible replacement. The host for the third party web site took it down earlier today due to an unacceptable amount of spam
courtest of the site's contact form which in turn implies that HC was not doing its job.

Screen dump attached..... Cheers... Rod
Attachments:

Please Log in or Create an account to join the conversation.

More
2 months 3 weeks ago #34264 by Sharon
Replied by Sharon on topic Hash Cash
@Hawkeye4

Wow. I feel for you. I have questions. Does your contact form provide the visitor the option or default of receiving a confirmation response after they hit Submit? If Yes, I've been told that a contact form that does this, sends back to the recipient in the response, a map of how to ab-use the form now to send spam. So a manual use of the Form is needed and then they just wait for a copy or confirmation.

I can't read your screen cap - too small, but what I could see from the tech's language is "appear to have been" and "likely" when filing blame. About as close as our nearest galaxy.

If your answer would still be yes on the email confirmation, I would stop sending anything back to visitor's via the form. Instead, we send them to a confirmation page. That way they can't use the contents as their map to spamming.

I chose HC because my clients ban all kinds of tracking, stalking and SMIRCing. Yes - even Google'ware and the likes are banned.

I'd appreciate any updates on your situation.
~s~

Please Log in or Create an account to join the conversation.

More
2 months 3 weeks ago #34265 by michael
Replied by michael on topic Hash Cash
HashCash only operates on forms where it's been enabled. By default, in Joomla, it's the registration form. Once a user has registered, they won't (generally) see the HC plugin again. I have that problem with this forum. HC isn't implemented in the forum, so when a user manually registers, they can turn their bot loose with valid credentials and off they go. It requires manual intervention on behalf of the spammer. If you want HC to protect your forum, you could add it to the forum post form. That's beyond the scope of my support though.

TLDR, HC doesn't protect forms that it doesn't exist on, if a user is already registered - HC doesn't help you unless the extension developer included the ability to enable captcha on their forms.

Please Log in or Create an account to join the conversation.

  • Not Allowed: to create new topic.
  • Not Allowed: to reply.
  • Not Allowed: to edit your message.
Powered by Kunena Forum