Submitted by drawk on Tue, 2007-01-30 22:56.

As it turns out, there was an exploit with the captcha module by which it could be easily defeated by spammers.

See security notice Captcha - response validation bypass.

I ended up in a discussion with Heine about a bypass that is fairly trivial to use. Captcha has been updated to prevent the exploit.

New versions:

Captcha 4.7.x-1.2
Captcha 5.x-1.1

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote>
  • Lines and paragraphs break automatically.
  • You may post code using <code>...</code> (generic) or <?php ... ?> (highlighted PHP) tags.
More information about formatting options

Hosted By Dreamhost.com


Did you know?

You don't need to register at WWDD to post comments.

Isn't it annoying when you want to comment on an article, but don't want to go through the hassle of creating yet-another-user account at yet-another-website?

Feel free to comment anonymously, or log in with your username@drupal.org account.

We won't mind a bit.