We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 28042 ☆ A M B ☆
    • 24,524 Posts
    So far so good, not a single spam message, and for the last few days I was getting six or eight a day.

    In case anyone gets confused by the debug setting, I have a modified version of the debug function for display on my sottwell.com site, since it’s a MODx demo site. I modified it to not display any sensitive information, other than that it’s the same eForm that everybody else uses.

    If anybody’s interested, the getServer snippet:
    <?php
    function getServer( &$fields ){
    	        // remote_addr
    		$fields['remote_addr']=$_SERVER['REMOTE_ADDR'];
                    $fields['remote_host']=$_SERVER['REMOTE_HOST'];
                    $fields['user_agent']=$_SERVER['HTTP_USER_AGENT'];
    		//return succes
    		return true;
    	}
    ?>
    

    The form chunk:
    <span style="color:red">[+validationmessage+]</span>
    <form method="post" action="[~[*id*]~]" enctype="multipart/form-data">
    <fieldset id="cfSet">
    <input name="formid" type="hidden" value="ContactForm"/>
    <label for="cfName">Name: 
    <input name="name" id="cfName" class="text" type="text" eform="Your Name::1:" />
    </label>
    <input type="text" name="Last__Name" id="LastName" size=30 autocomplete="off" eform="LastName::0" />
    <label for="cfEmail">Email: 
    <input name="email" id="cfEmail" class="text" type="text" eform="Email Address:email:1" />
    </label>
    <label for="cfMessage">Message: <br />
    <textarea name="message" id="cfMessage" rows="4" cols="20" eform="Message::1"></textarea>
    </label>
    <input type="submit" name="contact" id="cfContact" class="button" value="Send Message" />
    </fieldset>
    <p><br />Debugging has been left on deliberately so you can see how it works. </p>
    </form>
    

    And the report chunk:
    <h3>Contact Input</h3>
    <strong>Name:</strong> [+name+]<br />
    <strong>Email:</strong> [+email+]<br />
    <strong>Message:</strong> [+message+]<br />
    <strong>IP:</strong> [+remote_addr+]<br />
    <strong>Host:</strong> [+remote_host+]<br />
    <strong>User Agent:</strong> [+user_agent+]
    
      Studying MODX in the desert - http://sottwell.com
      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
      Join the Slack Community - http://modx.org
      • 7455
      • 2,204 Posts
      Maybe this is an nice option:
      ASCII CAPTCHA
      http://www.phpclasses.org/browse/package/4544.html

      no need for fonts etc and I think its harder to read for bots.
        follow me on twitter: @dimmy01
        • 29181
        • 480 Posts
        This is some great input thanks!

        I think I’ll wait for feedback from the client as to how it is standing up with the hidden field and the normal captcha. The ASCII captcha is pretty cool, I always worried about the default one with MODx, whether or not a bot could read it anyway.

        I’m definitely going to add Susan’s get Server snippet too...if they play nasty, I’ll just ban their IP

        Cheers,
        Taff
          Adrian Lawley: www.adrianlawley.com
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          The only problem with banning an IP is that the spams I was getting for several days were from all sorts of different IP addresses; fairly obviously it was coming from a botnet.
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org
            • 3749
            • 24,544 Posts
            Quote from: Taff at May 07, 2008, 04:43 PM

            This is some great input thanks!

            I think I’ll wait for feedback from the client as to how it is standing up with the hidden field and the normal captcha. The ASCII captcha is pretty cool, I always worried about the default one with MODx, whether or not a bot could read it anyway.

            I’m definitely going to add Susan’s get Server snippet too...if they play nasty, I’ll just ban their IP

            Cheers,
            Taff

            The trouble is that the harder you make it for bots, the harder you make it for humans. I’ve visited sites where it took me two or three tries to decode the image and it wouldn’t surprise me if there were now bots that could do a better job than me.

            The mathstring option is the cat’s pajamas IMHO (see the contact form at the site in my sig). It was very easy to implement with a little tweaking of the veriword code that comes with MODx. Even if a bot decodes it, entering the string they see will do them no good.

            OTOH, any kind of CAPTCA at all causes serious problems for vision impaired visitors unless you also have audio presentation. I haven’t been up to tackling that one although I’ve seen it done.

            Bob
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 29181
              • 480 Posts
              That Maths idea is great, have you documented how you did it anywhere?
                Adrian Lawley: www.adrianlawley.com
                • 3749
                • 24,544 Posts
                Quote from: Taff at May 08, 2008, 04:41 AM

                That Maths idea is great, have you documented how you did it anywhere?

                I did it a while ago but here’s the gist of it. I abstracted the veriword class from manager/includes and put it in a separate file. Then I modified it to accept an argument. If the argument is "mathstring" it uses the following mathstring class. If the argument is null, it picks from the default words. If the argument is anything else, it uses the argument for the display string.

                Here’s the code that actually creates the math string and calculates the correct answer:

                 class MathString {
                      var $_displayString="";
                      var $_value; 
                  	  function MathString($s1="34",$s2="312") {  // Constructor creates the math expression as a string
                   	  	  $i1 = rand(0,1);
                  	  	  $i2 = rand(0,2);
                  	  	  $operators = "+-x";
                  	  	  $this->_displayString = substr($s1,$i1,1).' '.substr($operators,rand(0,2),1).' '.substr($s2,$i2,1);
                	  }
                   	  function getDisplayString() {  // returns the math expression as a string
                  	  	  return($this->_displayString);
                  	  }
                  	  function getValue() {   // returns the solution as an integer
                  	  	  $ds=$this->_displayString;
                  	  	  $v1 = intval(substr($ds,0,1));
                  	  	  $v2 = intval(substr($ds,4,1));
                  	  	  $op = substr($ds,2,1);
                  	  	  switch ($op) {
                  	  	     case "+":
                  	  	     	return($v1 + $v2);
                  	  	  
                  	  	       	break;
                  	  	     case "-":
                  	  	     	return($v1 - $v2);
                  	  	  
                  	  	       break;
                  	  	     case "x":
                  	  	     	return($v1 * $v2);
                  	  	  
                  	  	       break;
                  	  	  }
                	  }
                  	  
                  } 	  


                Then I added this function to the veriword class:

                function set_veriword($useWord="") {		/* create session variable for verification, 
                                                                		   you may change the session variable name */ 
                		   
                     if ($useWord == "") { // no word sent, use random word
                	$this->word = $this->pick_word();	
                	$_SESSION['veriword'] = $this->word;   	   
                		   	   
                     } elseif ($useWord == "MathString") {  // use math string for veriword
                  	require "mathstringclass.inc.php";
                	$ms = new MathString();
                	$this->word = $ms->getDisplayString();
                	$_SESSION['veriword'] = $ms->getValue(); 
                     } else {    // word sent as argument - use it.
                	$this->word = $useWord;
                	$_SESSION['veriword'] = $this->word;   	   
                    }    
                		
                }


                The only files involved are:

                mathstringclass.inc.php
                spfveriword.php
                spfvericlass.php

                They’re in the assets/snippets/spform directory.

                Bob
                  Did I help you? Buy me a beer
                  Get my Book: MODX:The Official Guide
                  MODX info for everyone: http://bobsguides.com/modx.html
                  My MODX Extras
                  Bob's Guides is now hosted at A2 MODX Hosting
                  • 29181
                  • 480 Posts
                  Thanks for sharing that Bob. I think this is probably the best way to go.

                  Taff
                    Adrian Lawley: www.adrianlawley.com
                    • 3749
                    • 24,544 Posts
                    Quote from: Taff at May 08, 2008, 03:37 PM

                    Thanks for sharing that Bob. I think this is probably the best way to go.

                    Taff

                    If you don’t need the full power of eForm and eForm2db, it’s often a lot easier to just modify the output of SPForm to do what you want. It’s very easy to install and configure.
                      Did I help you? Buy me a beer
                      Get my Book: MODX:The Official Guide
                      MODX info for everyone: http://bobsguides.com/modx.html
                      My MODX Extras
                      Bob's Guides is now hosted at A2 MODX Hosting
                      • 2214
                      • 33 Posts
                      Is there any chance that eForm will be able to use the Akismet (http://akismet.com/) api? I think "crowdsourcing" is the only true answer to spam, and they seem to be doing a very good job with the Wordpress plugins.