School Assignment? Project Due Tomorrow? Chat LIVE With A Programming Expert!

Welcome to Dream.In.Code
Become an Expert!

Join 300,441 Programmers for FREE! Get instant access to thousands of experts, tutorials, code snippets, and more! There are 1,481 people online right now. Registration is fast and FREE... Join Now!




Welcome to Live CAPTCHA!

 

Welcome to Live CAPTCHA!, New anti-bot service.

danykey

11 Jun, 2009 - 01:45 AM
Post #1

New D.I.C Head
*

Joined: 10 Jun, 2009
Posts: 4

Hi to all, I had made a new anti-bot service with the Adobe Flash panel.
I think that the flash panel more convenient and quicker than the approach with distorted text.
Also service enough secure. I'm ready to reply to the questions.
Live CAPTCHA is an alternative to reCAPTCHA.

Yes, the design of site is very plain because I'm not a designer. Sorry. smile.gif

Service is free.

www.livecaptcha.net

Welcome! smile.gif

This post has been edited by danykey: 11 Jun, 2009 - 01:47 AM

User is offlineProfile CardPM
+Quote Post


RudiVisser

RE: Welcome To Live CAPTCHA!

11 Jun, 2009 - 02:28 AM
Post #2

.. does not guess solutions
Group Icon

Joined: 5 Jun, 2009
Posts: 1,872



Thanked: 137 times
Dream Kudos: 125
Expert In: PHP, MySQL, HTML, CSS, C#

My Contributions
Hmm

Interesting concept but it just won't work for the fact that you can just Ctrl-U and remove the disabled="disabled" attribute of the submit button.

CAPTCHA is server side for a reason, so that it can be validated *server side*, you're validating everything client side, which can very easily be spoofed.

To make it work, you could quite easily store no *solved* data client side, store it all client side, and submit the "tiles" that they selected as a form attribute, then validate them server side. Apart from that I don't see how it would work.
User is offlineProfile CardPM
+Quote Post

danykey

RE: Welcome To Live CAPTCHA!

11 Jun, 2009 - 02:35 AM
Post #3

New D.I.C Head
*

Joined: 10 Jun, 2009
Posts: 4

MageUK, did you read page: Info->How it works?
User is offlineProfile CardPM
+Quote Post

RudiVisser

RE: Welcome To Live CAPTCHA!

11 Jun, 2009 - 02:39 AM
Post #4

.. does not guess solutions
Group Icon

Joined: 5 Jun, 2009
Posts: 1,872



Thanked: 137 times
Dream Kudos: 125
Expert In: PHP, MySQL, HTML, CSS, C#

My Contributions
Yeah, but I was able to just remove the disabled="true" flag and it let me submit the form just fine, maybe it's a bug?

Or maybe my cookie got stored, or somethin.

Either way you could just modify the flash to always return a successful value, couldn't you?

EDIT: I'll make a proof of concept for you shortly..

This post has been edited by MageUK: 11 Jun, 2009 - 02:41 AM
User is offlineProfile CardPM
+Quote Post

danykey

RE: Welcome To Live CAPTCHA!

11 Jun, 2009 - 02:50 AM
Post #5

New D.I.C Head
*

Joined: 10 Jun, 2009
Posts: 4

MageUK, you are right, the page contain wrong logic, thanks a lot!
But it is not error of the concept, I think.. )
You can made submit, but DECISION is empty and you can't to confirm DECISION.

Ok, I will fix this bug. )

What do you think else?

PS. Also I suggest to read Info->Security page.

This post has been edited by danykey: 11 Jun, 2009 - 02:55 AM
User is offlineProfile CardPM
+Quote Post

RudiVisser

RE: Welcome To Live CAPTCHA!

11 Jun, 2009 - 02:56 AM
Post #6

.. does not guess solutions
Group Icon

Joined: 5 Jun, 2009
Posts: 1,872



Thanked: 137 times
Dream Kudos: 125
Expert In: PHP, MySQL, HTML, CSS, C#

My Contributions
Glad I could help smile.gif

Apart from that I like the idea! I'm still worried about the overall security of it though due to the packets it sends.

You can easily parse the data that's coming through and send it back in order to get the hash you're returning:
CODE
.+mxcontrols.MxCheckBox..744.

..724.

..618.

..493.

..155.

..794...'...'.........
............Please select all checkboxes which contain number: 6

User is offlineProfile CardPM
+Quote Post

danykey

RE: Welcome To Live CAPTCHA!

11 Jun, 2009 - 03:14 AM
Post #7

New D.I.C Head
*

Joined: 10 Jun, 2009
Posts: 4

Yes, it's the serialization data.

As a solution I can obfuscate(add 'noise') tranfering data and I have some other ideas.
I think it's not a big problem.
And I wont to see that my service is good and users will be use by him.

MageUK, thanks again. )

This post has been edited by danykey: 11 Jun, 2009 - 03:39 AM
User is offlineProfile CardPM
+Quote Post

Fast ReplyReply to this topicStart new topic

Time is now: 11/8/09 01:18AM

Live Help!

Be Social

Dream.In.Code RSS Feed Dream.In.Code LinkedIn Group Follow Us On Twitter Fan Us On Facebook

Tutorials

Programming

Web Development

Reference Sheets

Code Snippets

DIC Chatroom

Bye Bye Ads

Monthly Drawing

Thumb Drive

Top Contributors

Top 10 Kudos This Month