We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 29181
    • 480 Posts
    A past client has reported receiving an awful lot of spam recently.
    The previous webspace provider where it was hosted was unable to get the captcha support enabled because of freetype support (if I remember correctly). Since then we have moved so that will be one of the things I will sort out today to combat it.

    An email or 2 a day wouldn’t be so bad, but whoever is sending it is somehow managing to send it to everyone (I am using a rather large mail selector dropdown). Any ideas how they are doing this, and how I could combat it?

    Cheers,
    Taff
      Adrian Lawley: www.adrianlawley.com
      • 10449
      • 956 Posts
      Sadly, there’s no 100% guarantee you can avoid spam, with or without captchas.

      Personally, I’ve resorted to either:

      a) Flash forms with captchas (safe, even if you hack the SWF) - has obvious disadvantages for a tiny percentage of users without flash plugin installed.

      b) HTML forms with random questions that only humans are supposed to answer. The question and answer pairs are only defined / stored in PHP (no cookies, no sessions, no JS, no hidden form fields).
      e.g. "is fire hot or cold?" / "capital of France =" / "2 plus 5 ="

      Obviously, these methods require addtl. work to setup and test, so I only really use it when the budget allows it.



      whoever is sending it is somehow managing to send it to everyone (I am using a rather large mail selector dropdown). Any ideas how they are doing this, and how I could combat it?

      Well, you have to validate / check EVERY user input. Not just the email-field (sender), but every single input field. PHP introduced a new set of tools for this with version 5: filters
      http://uk.php.net/filter

      It’s sad that even today you’ll find many forms where email-recipients are stored in hidden form fields, or all the checking is done client-side only (JS). That’s stupid and completely useless.
        • 29181
        • 480 Posts
        Thanks for the reply Ganesh!

        <option value = "1">General Information</option>
        <option value = "2">President & CEO</option>
        <option value = "3">Finance & Business</option>
        <option value = "4">Restoration & Preservation</option>
        <option value = "5">John Caramia, Education & Interpretation</option>
        <option value = "6">Development & External Relations</option>
        <option value = "7">Publications</option>
        <option value = "8">Collections & Research</option>


        My dropdown looks like this and the selected value is submitted to the eForm snippet. Using eForms &mailselector parameter defines who gets the mail. So, as you can see no email addresses are stored where the client can view them.

        I was just curious as to how someone can submit a form with eForm to everybody in the dropdown.

        All the best,
        Taff
          Adrian Lawley: www.adrianlawley.com
          • 25663 MODX Staff
          • 12,272 Posts
          I wonder if it would be possible to create a hidden form field that eForm should always see as empty in order to successfully submit the form with a name that should be a spam-spider honeypot like name="firstname". If there is a value in it, you’d simply fail the form with zero validation message or some faux message like, "Can’t instantiate mail() function" with the implied part of the error message being "because you’re a spammer!".
            Ryan Thrash, MODX Co-Founder
            Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
            • 29181
            • 480 Posts
            That would be a great idea.
            On second thoughts though...how would a screenreader work with that?

            I suppose that Spam is one of the pitfalls of getting 2 million hits a month, with 18k unique visitors (according to awstats).

            They probably need someone to keep updating that contact form on a regular basis just to change the names of the input fields monthly.

            What would happen if someone copied my form details precisely and posted them into an HTML page somewhere and changed the select form to multiple select, but kept everything else the same...would it eForm send it?
            I still can’t work out how they are sending it to everyone in a single mail...if it was looping, then I could have.

            Cheers,
            Taff
              Adrian Lawley: www.adrianlawley.com
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              Quote from: rthrash at May 06, 2008, 10:16 AM

              I wonder if it would be possible to create a hidden form field that eForm should always see as empty in order to successfully submit the form with a name that should be a spam-spider honeypot like name="firstname". If there is a value in it, you’d simply fail the form with zero validation message or some faux message like, "Can’t instantiate mail() function" with the implied part of the error message being "because you’re a spammer!".
              I’ve done this, I actually ripped that field and its styling off from SPForm and made a validation snippet to check it and return "false" if it’s not empty, and for a long time I didn’t get any spam. Last week I got one, then yesterday I got four in a row, and I just now saw three more. So I guess some script somewhere has figure it out. Maybe if I just change the name of the field...
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 3749
                • 24,544 Posts
                With SPForm, it’s easy to ban an IP address (or family of IP addresses). I still have yet to receive a single spam at the site in my sig but it has the "solve the math problem" captcha turned on.

                With some other sites that don’t have that option on, I do get a very occasional spam message through SPForm, and sometimes they’re repeated enough that I ban the user’s IP. If I also have the "require mouse or keyboard" option on, though, it cuts the spam way down.

                @sottwell, I wonder if some spammer visited your site, manually filled in the contact form, and created some kind of macro that would duplicate their actions.

                @taff, re: screenreaders. With SPForm, in addition to the hidden field, there’s a hidden message telling people with screenreaders not to fill it in.
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 25663 MODX Staff
                  • 12,272 Posts
                  It’d be really awesome to adapt Bob’s anti-spam measures into eForm ... hint, hint ... tongue
                    Ryan Thrash, MODX Co-Founder
                    Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
                    • 28042 ☆ A M B ☆
                    • 24,524 Posts
                    embarrassed I just realized that I’d put the no-spam "hidden" input field in all my other sites except sottwell.com. So I added it; we’ll see if it works.

                    I have this eForm call:
                    [!eForm? &formid=`ContactForm` &tpl=`ContactForm` &report=`ContactReport` &subject=`sottwell.com Contact` &thankyou=`ThankYou` &replyto=`email` &debug=`1` &eformOnBeforeMailSent=`getServer` &eformOnValidate=`checkField`!]
                    

                    The checkField snippet (called before the eForm snippet call)
                    <?php
                    function checkField(&$fields,&$vMsg,&$rMsg) {
                        if(!empty($fields['Last__Name'])) {
                            return false;
                        } else {
                        return true;
                        }
                    }
                    ?>

                    and the CSS to hide the input field
                    #LastName{
                        position:absolute;
                        text-decoration:underline;
                        background-color:#CC0000;
                        left:0px;
                        top:-500px;
                        width:1px;
                        height:1px;
                        overflow:hidden;
                    }
                    

                      Studying MODX in the desert - http://sottwell.com
                      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                      Join the Slack Community - http://modx.org
                      • 25663 MODX Staff
                      • 12,272 Posts
                      Thanks for sharing Susan. smiley
                        Ryan Thrash, MODX Co-Founder
                        Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me