Quote:
Originally Posted by ozzy47
They are probably using a program such as XRumer, which the program is able to bypass security techniques commonly used by many forums and blogs to deter automated spam, such as account registration, client detection, CAPTCHAs, and e-mail activation before posting.
|
You may be right. We've checked our logs and have no strange/un-humane activity for FunCaptcha solves themselves, however our javascript fallback alternative may not offer the same protection.
We've been using a strong text CAPTCHA as a fallback if Javascript is disabled. We've just disabled that feature for now (done remotely, no update to plugins required) as we know XRumer is known to be able to crack that, and we'll look at a better way to provide javascript fallback that remains secure.
We may update the plugin giving admins the option to enable it, with it disabled by default, based on some further research into the issue.
Regards,
FunCaptcha team