• Resolved shoofar

    (@shoofar)


    Hi,

    I have created simple form that stores 2 hidden fields (IP and agent of the attacker)

    And then it checks for captcha and opens another page when one presses the button and sends me an email containing the IP and agent of the user.

    My site is under constant bot attack for 2 days now.

    It looks like the captcha is not preventing from attacks – the minute I publish the form it starts sending filled forms few/minute- until the server’s usage limits kick in.

    (tried all options in forminator: google v2, invisible, v3, hCaptcha) all get passed by.

    I cannot pass it without filling the captcha but bots somehow can.

    The link to the test form is in field above

    Is there anything that you can check to see if there is a problem with my form maybe or with forminator?

    here are some of IPs and agents that were grabbed from emails that I receive.

    I cannot block those IPs because they are from my country.

    5.173.136.181|Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0?Mobile Safari/537.36

    83.15.141.97|Mozilla/5.0 (Linux; Android 11; SAMSUNG SM-A405FN) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/23.0 Chrome/115.0.0.0?Mobile Safari/537.36

    5.173.184.103|Mozilla/5.0 (Linux; Android 13; SM-A546B Build/TP1A.220624.014; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/117.0.0.0?Mobile Safari/537.36 Instagram 307.0.0.34.111 Android (33/13; 450dpi; 1080×2125; samsung; SM-A546B; a54x; s5e8835; pl_PL; 532277880)

    31.42.6.99|Mozilla/5.0 (Linux; Android 12; SM-A415F Build/SP1A.210812.016; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/118.0.0.0?Mobile Safari/537.36 Instagram 307.0.0.34.111 Android (31/12; 420dpi; 1080×2184; samsung; SM-A415F; a41; mt6768; pl_PL; 532277538)

    Here is the exported form:

    just copy/paste it

    {“type”:”form”,”data”:{“fields”:[{“id”:”hidden-1″,”element_id”:”hidden-1″,”form_id”:”wrapper-2177-9600″,”parent_group”:””,”type”:”hidden”,”options”:[],”cols”:”12″,”conditions”:[],”wrapper_id”:”wrapper-2177-9600″,”field_label”:””,”default_value”:”user_ip”},{“id”:”hidden-2″,”element_id”:”hidden-2″,”form_id”:”wrapper-3849-3603″,”parent_group”:””,”type”:”hidden”,”options”:[],”cols”:”12″,”conditions”:[],”wrapper_id”:”wrapper-3849-3603″,”field_label”:””,”default_value”:”user_agent”},{“id”:”captcha-1″,”element_id”:”captcha-1″,”form_id”:”wrapper-8182-9917″,”parent_group”:””,”type”:”captcha”,”options”:[],”cols”:”12″,”conditions”:[],”wrapper_id”:”wrapper-8182-9917″,”captcha_provider”:”hcaptcha”,”captcha_type”:”v3_recaptcha”,”hcaptcha_type”:”hc_checkbox”,”score_threshold”:”0.5″,”captcha_badge”:”bottomright”,”hc_invisible_notice”:”This site is protected by hCaptcha and its Privacy Policy and Terms of Service apply.”,”recaptcha_error_message”:”Weryfikacja reCAPTCHA nie powiod?a si?. Prosz? spróbowa? ponownie.”,”hcaptcha_error_message”:”Weryfikacja Captcha nieudana. Spróbuj ponownie.”}],”settings”:{“pagination-header”:”nav”,”paginationData”:{“pagination-header-design”:”show”,”pagination-header”:”nav”},”formName”:”Start ECRR”,”version”:”1.27.0″,”form-border-style”:”none”,”form-padding”:””,”form-border”:””,”fields-style”:”open”,”field-image-size”:”custom”,”validation”:”server”,”akismet-protection”:”1″,”form-style”:”default”,”enable-ajax”:”false”,”autoclose”:”true”,”submission-indicator”:””,”indicator-label”:”Wysy?anie…”,”form-type”:”default”,”submission-behaviour”:”behaviour-thankyou”,”thankyou-message”:”Dzi?kujemy za skontaktowanie si? z nami, wkrótce si? z Tob? skontaktujemy.”,”submitData”:{“custom-submit-text”:”Start Testu”,”custom-invalid-form-message”:”B??d: Twój formularz nie jest prawid?owy, napraw b??dy!”,”conditions”:[],”custom-class”:”#start-test”},”validation-inline”:””,”form-expire”:”no_expire”,”form-padding-top”:”0″,”form-padding-right”:”0″,”form-padding-bottom”:”0″,”form-padding-left”:”0″,”form-border-width”:”0″,”form-border-radius”:”0″,”cform-label-font-family”:”Roboto”,”cform-label-custom-family”:””,”cform-label-font-size”:”12″,”cform-label-font-weight”:”bold”,”cform-title-font-family”:”Roboto”,”cform-title-custom-family”:””,”cform-title-font-size”:”45″,”cform-title-font-weight”:”normal”,”cform-title-text-align”:”left”,”cform-subtitle-font-family”:”Roboto”,”cform-subtitle-custom-font”:””,”cform-subtitle-font-size”:”18″,”cform-subtitle-font-weight”:”normal”,”cform-subtitle-text-align”:”left”,”cform-input-font-family”:”Roboto”,”cform-input-custom-font”:””,”cform-input-font-size”:”16″,”cform-input-font-weight”:”normal”,”cform-radio-font-family”:”Roboto”,”cform-radio-custom-font”:””,”cform-radio-font-size”:”14″,”cform-radio-font-weight”:”normal”,”cform-select-font-family”:”Roboto”,”cform-select-custom-family”:””,”cform-select-font-size”:”16″,”cform-select-font-weight”:”normal”,”cform-multiselect-font-family”:”Roboto”,”cform-multiselect-custom-font”:””,”cform-multiselect-font-size”:”16″,”cform-multiselect-font-weight”:”normal”,”cform-dropdown-font-family”:”Roboto”,”cform-dropdown-custom-font”:””,”cform-dropdown-font-size”:”16″,”cform-dropdown-font-weight”:”normal”,”cform-calendar-font-family”:”Roboto”,”cform-calendar-custom-font”:””,”cform-calendar-font-size”:”13″,”cform-calendar-font-weight”:”normal”,”cform-button-font-family”:”Roboto”,”cform-button-custom-font”:””,”cform-button-font-size”:”14″,”cform-button-font-weight”:”500″,”cform-timeline-font-family”:”Roboto”,”cform-timeline-custom-font”:””,”cform-timeline-font-size”:”12″,”cform-timeline-font-weight”:”normal”,”cform-pagination-font-family”:””,”cform-pagination-custom-font”:””,”cform-pagination-font-size”:”16″,”cform-pagination-font-weight”:”normal”,”payment_require_ssl”:””,”submission-file”:”delete”,”store_submissions”:””,”form_name”:”start-ecrr”,”form_status”:”draft”,”sc_email_link”:”1″,”sc_message”:”
    Your form has been saved as draft and a resume link has been generated so you can return to the form anytime within {retention_period} days from today. Copy and save the link or enter your email address below to have the link sent to your mail.
    These fields weren’t saved to your submission draft: Paypal, Stripe, Signature, Password, Captcha, and Upload. Kindly fill them out before submitting the form.
    “,”notification_count”:1,”previous_status”:”draft”,”honeypot”:”1″,”use_donotcachepage”:”1″},”client_id”:null,”integration_conditions”:[],”behaviors”:[{“slug”:”behavior-1234-4567″,”label”:””,”autoclose-time”:”5″,”autoclose”:”true”,”newtab”:”newtab_hide”,”thankyou-message”:”Dzi?kujemy za skontaktowanie si? z nami, wkrótce si? z Tob? skontaktujemy.”,”email-thankyou-message”:””,”manual-thankyou-message”:””,”submission-behaviour”:”behaviour-redirect”,”redirect-url”:”https://relacjapelnapara.pl/test-styl-przywiazania-ecrr”}],”notifications”:[{“slug”:”notification-1234-4567″,”label”:”Adres e-mail administratora”,”email-recipients”:”default”,”recipients”:”[email protected]”,”email-subject”:”Nowe zg?oszenie formularza #{submission_id} dla {form_name}”,”email-editor”:”You have a new website form submission:
    {all_fields}

    This message was sent from {site_url}.”,”email-attachment”:”true”,”type”:”default”}]},”status”:”publish”,”version”:”1.27.0″}

    The page I need help with: [log in to see the link]

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Support Laura – WPMU DEV Support

    (@wpmudevsupport3)

    Hi @shoofar,

    Hope this message finds you well.

    I did check the link you shared but I was not able to bypass the captcha test:

    https://prnt.sc/yuU438KKTl4W

    I never was able to check any captcha and I waited for a couple of seconds before checking the button. That form seems to be a Ninja Form, is that correct?

    I also tried to import the form but is returning an error, could you export it again and use a Drive service like Google Drive or https://pastebin.pl/? Thanks.

    Best regards,
    Laura

    Plugin Support Kris – WPMU DEV Support

    (@wpmudevsupport13)

    Hi @shoofar

    We haven’t heard from you in a while, I’ll go and mark this thread as resolved. If you have any additional questions or require further help, please let us know!

    Kind Regards,
    Kris

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘Forminator captcha doesn’t prevent bots’ is closed to new replies.