Quote:
Originally Posted by cmd19872002
Humm there is a huge flaw that has been in this since v1.
Ok, basicly the bot goes to the page, detects its this style of auth and instead of trying to guess the correct image, it just does them all. What i mean is... it loads this page /register.php?clicked=1 increasing the clicked number each time using the same cookies. Once it guesses the correct number, it can continue to register.
~Cmd
|
The above still seems to be an issue. You do not need to even look at the images. Just go to a forum running this mod and click on the first image you see. If you are wrong it will tell you to go back. Instead of going back, change where it says "/register.php?clicked=1" in the address bar to "/register.php?clicked=2". If 2 isn't the right image, enter 3 and so forth. Once you get to the number where the correct image is located, you are allowed to register. If you have a total of 8 images, it only takes 7 attempts max to get through.
It would be nice to combine this with image captcha so that each time you guess a wrong image, you have to re-enter a word in an image. That would really bullet-proof this mod.