<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Londonvasion Part VII: phpBB Versus Spam Presentation</title>
	<atom:link href="http://www.phpbbdoctor.com/blog/2008/07/23/londonvasion-part-vii-phpbb-versus-spam-presentation/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.phpbbdoctor.com/blog/2008/07/23/londonvasion-part-vii-phpbb-versus-spam-presentation/</link>
	<description>Your premium source for custom modification services for phpBB</description>
	<lastBuildDate>Wed, 11 Jan 2012 20:39:04 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Dog Cow</title>
		<link>http://www.phpbbdoctor.com/blog/2008/07/23/londonvasion-part-vii-phpbb-versus-spam-presentation/comment-page-1/#comment-2695</link>
		<dc:creator>Dog Cow</dc:creator>
		<pubDate>Wed, 30 Jul 2008 22:22:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.phpbbdoctor.com/blog/?p=221#comment-2695</guid>
		<description>Hey Ganon_Master, I want to say BIG THANKS to you for giving me that link. Seriously. That was great. That guy not only showed the captchas in before/and after form, but he told &lt;i&gt;how&lt;/i&gt; to break them. And he was totally right about how people make them who don&#039;t know how to break them. I&#039;m using the advanced vc mod and I tried his techniques, where you set the threshhold. .... My gosh, any OCR could have read it like a book.

So I spent some time tweaking the settings, so now each letter gets about 6  or so shadows behind it of different colors and rotational angles. Colors are all the same intensity so the result is that trying to threshhold it to remove all the bg colors and garbage makes the letters look awful. I don&#039;t have it running live yet, but it makes me happy to know I increased the toughness of my captcha (and still make it solvable by humans) in an hour or two.

Still probably not unbreakable, but hopefully more difficult now.

I recommend others do the same, or at least open a paint program ( I used Photoshop 5) and try his methods on your own captcha, if you are using one.</description>
		<content:encoded><![CDATA[<p>Hey Ganon_Master, I want to say BIG THANKS to you for giving me that link. Seriously. That was great. That guy not only showed the captchas in before/and after form, but he told <i>how</i> to break them. And he was totally right about how people make them who don&#8217;t know how to break them. I&#8217;m using the advanced vc mod and I tried his techniques, where you set the threshhold. &#8230;. My gosh, any OCR could have read it like a book.</p>
<p>So I spent some time tweaking the settings, so now each letter gets about 6  or so shadows behind it of different colors and rotational angles. Colors are all the same intensity so the result is that trying to threshhold it to remove all the bg colors and garbage makes the letters look awful. I don&#8217;t have it running live yet, but it makes me happy to know I increased the toughness of my captcha (and still make it solvable by humans) in an hour or two.</p>
<p>Still probably not unbreakable, but hopefully more difficult now.</p>
<p>I recommend others do the same, or at least open a paint program ( I used Photoshop 5) and try his methods on your own captcha, if you are using one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ganon_Master</title>
		<link>http://www.phpbbdoctor.com/blog/2008/07/23/londonvasion-part-vii-phpbb-versus-spam-presentation/comment-page-1/#comment-2681</link>
		<dc:creator>Ganon_Master</dc:creator>
		<pubDate>Thu, 24 Jul 2008 23:39:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.phpbbdoctor.com/blog/?p=221#comment-2681</guid>
		<description>I did some searching on the phpBB3 CAPTCHA being broken topic, and I found this website: http://www.apathysketchpad.com/blog/2007/06/05/how-to-crack-captchas/ I haven&#039;t read the entire thing yet, but it seems that this guy found a possible way to break the phpBB3 CAPTCHA.

Some guys who also experiment with CAPTCHA&#039;s are the guys at Rapidshare.com. Unregistered users have to complete a CAPTCHA every time before they can download. They did quite a lot of things, similar to the &quot;marked checkbox&quot; method here.

Sounds like it was a good presentation. :) I should&#039;ve been there, but couldn&#039;t make it.</description>
		<content:encoded><![CDATA[<p>I did some searching on the phpBB3 CAPTCHA being broken topic, and I found this website: <a href="http://www.apathysketchpad.com/blog/2007/06/05/how-to-crack-captchas/" rel="nofollow">http://www.apathysketchpad.com/blog/2007/06/05/how-to-crack-captchas/</a> I haven&#8217;t read the entire thing yet, but it seems that this guy found a possible way to break the phpBB3 CAPTCHA.</p>
<p>Some guys who also experiment with CAPTCHA&#8217;s are the guys at Rapidshare.com. Unregistered users have to complete a CAPTCHA every time before they can download. They did quite a lot of things, similar to the &#8220;marked checkbox&#8221; method here.</p>
<p>Sounds like it was a good presentation. <img src='http://www.phpbbdoctor.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I should&#8217;ve been there, but couldn&#8217;t make it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Rathbun</title>
		<link>http://www.phpbbdoctor.com/blog/2008/07/23/londonvasion-part-vii-phpbb-versus-spam-presentation/comment-page-1/#comment-2680</link>
		<dc:creator>Dave Rathbun</dc:creator>
		<pubDate>Thu, 24 Jul 2008 04:02:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.phpbbdoctor.com/blog/?p=221#comment-2680</guid>
		<description>From what I understand, the phpBB3 CAPTCHA has reportedly been broken. I don&#039;t think it&#039;s in widespread use yet, but it will be. We have seen spam on phpbb.com but so far most of it appears to be manual (human) stuff.

I mentioned in the presentation that it&#039;s only a matter of time, in my opinion, before phpBB3 becomes a major target. At that point, we&#039;ll need new defenses against reg-bots and post-bots and all the rest.

Logging posted data would be an interesting exercise, just make sure you sanitize the data before you log it. ;)</description>
		<content:encoded><![CDATA[<p>From what I understand, the phpBB3 CAPTCHA has reportedly been broken. I don&#8217;t think it&#8217;s in widespread use yet, but it will be. We have seen spam on phpbb.com but so far most of it appears to be manual (human) stuff.</p>
<p>I mentioned in the presentation that it&#8217;s only a matter of time, in my opinion, before phpBB3 becomes a major target. At that point, we&#8217;ll need new defenses against reg-bots and post-bots and all the rest.</p>
<p>Logging posted data would be an interesting exercise, just make sure you sanitize the data before you log it. <img src='http://www.phpbbdoctor.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dog Cow</title>
		<link>http://www.phpbbdoctor.com/blog/2008/07/23/londonvasion-part-vii-phpbb-versus-spam-presentation/comment-page-1/#comment-2679</link>
		<dc:creator>Dog Cow</dc:creator>
		<pubDate>Wed, 23 Jul 2008 23:45:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.phpbbdoctor.com/blog/?p=221#comment-2679</guid>
		<description>One more comment. I just remembered that one of my projects for the next week is to start recording all $_POST data, as well as the $_SERVER data in order to take a look to see if any non-standard values or bizarre user-agents are involved. The contents of $_GET are easy to see since they are part of the URL and can be looked up in server logs but I have a feeling since POST data is often over-looked, there may be some interesting tidbits left behind. :)</description>
		<content:encoded><![CDATA[<p>One more comment. I just remembered that one of my projects for the next week is to start recording all $_POST data, as well as the $_SERVER data in order to take a look to see if any non-standard values or bizarre user-agents are involved. The contents of $_GET are easy to see since they are part of the URL and can be looked up in server logs but I have a feeling since POST data is often over-looked, there may be some interesting tidbits left behind. <img src='http://www.phpbbdoctor.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dog Cow</title>
		<link>http://www.phpbbdoctor.com/blog/2008/07/23/londonvasion-part-vii-phpbb-versus-spam-presentation/comment-page-1/#comment-2678</link>
		<dc:creator>Dog Cow</dc:creator>
		<pubDate>Wed, 23 Jul 2008 23:39:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.phpbbdoctor.com/blog/?p=221#comment-2678</guid>
		<description>I haven&#039;t heard of any cases of phpBB 3 spam. Have there been any reported?</description>
		<content:encoded><![CDATA[<p>I haven&#8217;t heard of any cases of phpBB 3 spam. Have there been any reported?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

