Members: 16,996
Threads: 38,845
Posts: 159,389
Online: 22

Newest Member: Kl_broka@rediffmail.com


Odoo.tv - Outdoor Television


Sedo - Domains kaufen und verkaufen das Projekt mambers.com steht zum Verkauf Besucherstatistiken von mambers.com etracker® Web-Controlling statt Logfile-Analyse
Old 24.02.2005, 23:56   #1 (permalink)
Junior Mamber
 
elta68's Avatar
 
Join Date: Sep 2004
Posts: 40
elta68 is on a distinguished road
Send a message via ICQ to elta68
Default Hashcash challenge: a way to stop spamming now in com_akocomment

Hashcash challenge in com_akocomment

So I have just finished and tested the integration of a hashcash challenge into the com_akocomment component...using the code of this page (http://dev.wp-plugins.org/browser/wp-hashcash/trunk/), only an extract but all credit to original authors:

C.S. - www.cimmanon.org
Gene Shepherd - www.imporium.org
John F - www.stonegauge.com
Magenson - http://blog.magenson.de/
Matt Mullenweg - photomatt.net
Matt Warden - www.mattwarden.com
Paul Andrew Johnston - pajhome.org.uk

and to Arthur Konze : webmaster@mamboportal.com

I must also pack everything into a new version of the component or better say refactored the code a little bit, because it is still full of debug statements...

principle:
robot wo want to submit spam comment must pay the prize (cpu time) of computing manually (can not be automated by submitting directly to the form) a Hashcash (Hashcash.org)

extract form the document of wp-hashcash:
"Wordpress Hashcash
Introduction:
Taking Matt’s stopgap spam solution, which sends precomputed hashes to be echoed back by the user-agent’s form, I’ve added dynamic generation of the md5 hash. Rather than write it to a hidden field, we wait until the form is submitted to compute the hash. This prevents spammers from automatically scraping the form, because anyone wanting to submit a comment *must* execute the javascript md5.
This plugin used to be called “Spam Stopgap Extreme.” Now it’s been moved to the WP plugins repository under the new name “Wordpress Hashcash.” All future development will take place through the plugins repository.
New Features:
· Log and emailing of spam, for your records
· Client-side hash required.
· The “Key” is hashed once before output to the html form–so spammers can’t make sense of it, and then hashed on the client side, again.
· The “Key” is now a time-dependent, visitor dependent hash, for more variability. You can’t just compute the right md5 once, because it’s always changing.
· Failure to compute the md5 hash results in a 1 minute timeout penalty. "

expect a release before ween end...I must also inform Arthur Konze for a feedback

then I will add the same code in login page, to avoid brute forcing password in admin login page....and in guestbook (because I was spammed many times last week)


cedric
www.waltercedric.com

Last edited by elta68; 25.02.2005 at 00:58.
elta68 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 16.06.2005, 05:08   #2 (permalink)
Baby Mamber
 
Join Date: Jan 2005
Posts: 6
Savage702 is on a distinguished road
Default Re: Hashcash challenge in com_akocomment

How do you get this to work? I have downloaded both of your components and see nothing to configure?!?! Can you tell me how I can get hashcode to work for my comments. Being spammed to death over here.
Savage702 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 16.08.2005, 00:35   #3 (permalink)
Junior Mamber
 
elta68's Avatar
 
Join Date: Sep 2004
Posts: 40
elta68 is on a distinguished road
Send a message via ICQ to elta68
Default Re: Hashcash challenge in com_akocomment

take the latest version...it has an admin panel now
__________________
Written with recycled electrons, because I care....
www.waltercedric.com
elta68 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +2. The time now is 08:53.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
A vBSkinworks Design
© Copyright 2004-2008 by Arthur Konze Webdesign.