Welcome, Guest
Username: Password: Remember me

TOPIC: [SOLVED] Security Problem - CAPTCHA

[SOLVED] Security Problem - CAPTCHA 12 years 7 months ago #14808

  • dthadmin
  • dthadmin's Avatar
  • Offline
  • Administrator
  • Administrator
  • Posts: 5470
  • Thank you received: 3
Guys, we've been working on this. Will have another update out very shortly. Seems the last update helped the vast majority of users with the script fraud donations... but you can never stop someone from sitting at their computer and manually filling out your form over and over again.

The change we have just implemented in the last day is to send the IP address to Authorize.net for all attempts. The last update would store the IP for successful donation records. Now, all attempts will send the IP to authorize.net. Then of course you can get the IP and block them.

We would also recommend of course that you check your authorize.net security settings and improve them. Make sure you have CVV code as required. Have at least the address and/or zip code match to be required.

Be watching for an update very shortly.

Please Log in or Create an account to join the conversation.

[SOLVED] Security Problem - CAPTCHA 12 years 7 months ago #14810

  • Bruce
  • Bruce's Avatar
  • Offline
  • Junior Boarder
  • Junior Boarder
  • Posts: 33
  • Thank you received: 0
As part of the fix can you log all unsuccessful credit card transactions. Authorize.net deletes all unsuccessful attempts when it accepts a batch. Logging the failures will also allow us to respond to legitimate customers who's credit cards failed for one reason or other.

Thanks

Please Log in or Create an account to join the conversation.

[SOLVED] Security Problem - CAPTCHA 12 years 7 months ago #14815

  • belaus
  • belaus's Avatar
  • Offline
  • Fresh Boarder
  • Fresh Boarder
  • Posts: 4
  • Thank you received: 0
Having the same problems here. Updated to the latest plugin but got hit again a number of times. This is costing real $ because each failed transaction is $.10 . These are adding up, well into the hundreds of $'s already. Have temporary taken down our donation page and put the authorize.net account in test mode.

Greg Belaus
[email protected]

Please Log in or Create an account to join the conversation.

[SOLVED] Security Problem - CAPTCHA 12 years 7 months ago #14853

  • Bruce
  • Bruce's Avatar
  • Offline
  • Junior Boarder
  • Junior Boarder
  • Posts: 33
  • Thank you received: 0

belaus wrote: This is costing real $ because each failed transaction is $.10 . These are adding up, well into the hundreds of $'s already.

I am paying $.15 each. Now the hits are from US.

If they are doing this manually I don't know how to stop it.

Please Log in or Create an account to join the conversation.

[SOLVED] Security Problem - CAPTCHA 12 years 7 months ago #14854

  • thepiston
  • thepiston's Avatar
  • Offline
  • Expert Boarder
  • Expert Boarder
  • Posts: 151
  • Thank you received: 0
would it help to put component behind password or are they accessing the files directly?

Please Log in or Create an account to join the conversation.

[SOLVED] Security Problem - CAPTCHA 12 years 7 months ago #14910

  • Bruce
  • Bruce's Avatar
  • Offline
  • Junior Boarder
  • Junior Boarder
  • Posts: 33
  • Thank you received: 0

thepiston wrote: would it help to put component behind password or are they accessing the files directly?


I think the biggest help is tightening up on Authorize.net. Make sure your transactions are validated with as much information as possible. In addition If you add Fraud Protection Suite make sure you set the filter to hold for approval. You won't be charged unless you approve the transaction.

I tried a bogus transaction which was stopped by the Fraud Protection suite, it responded to the user with "Try Again". If you were a hacker and got no information you would eventually give up. I just hope I don't turn off my regular donors.

Please Log in or Create an account to join the conversation.

Time to create page: 0.106 seconds