Captcha in GOLD to Prevent Scripts

For general questions and discussions specific to the AbleCommerce GOLD ASP.Net shopping cart software.
Post Reply
User avatar
calvis
Rear Admiral (RADM)
Rear Admiral (RADM)
Posts: 710
Joined: Tue Jan 27, 2004 3:57 pm
Location: Redmond, WA

Captcha in GOLD to Prevent Scripts

Post by calvis » Tue Sep 12, 2017 2:26 pm

We recently underwent an attack in which 20 fraudulent orders (about 4,500 dollars worth) were placed in a span of 2 days. They used the correct billing address and shipped them to random people across the US. They were placing orders via a script because of the speed that the accounts were created and the orders placed. The attacks continued even after captcha was turned on. The attacks used different ip addresses and we found a pattern and were able to manually watch for that pattern thus preventing any more orders being shipped. The attack has since stopped, but we am working on security measures to prevent it if it does happen.

Does anyone know how to make captcha stronger? Seems like reCAPTCHA is the way to go but I am sure how much time and trouble it would be to implement that. This attack was very vicious for the fact they had all the billing information correct on the card and we got lucky to notice it after day 2.

Any other suggestions would be welcomed. I've had this happen before, but not to this scale and which was done by a rogue affiliate, but I am unable to find any motive other than to make us accumulate as many chargebacks as possible.
Able Customer Since 1999 Currently Running on GOLD R12 SR1 and PCI Certified.

sfeher
Captain (CAPT)
Captain (CAPT)
Posts: 220
Joined: Fri Jun 04, 2004 1:58 pm
Location: Steubenville, Ohio

Re: Captcha in GOLD to Prevent Scripts

Post by sfeher » Thu Sep 14, 2017 3:18 am

We leverage our gateway account (Authorize.net) to ensure that the "Order Velocity" is in check. We run several stores where orders are consistent, but NOT typically that quick.
We usually leave our speed in the range that matches the rolling 12-month average..... Sure helps.

User avatar
Shopping Cart Admin
AbleCommerce Admin
AbleCommerce Admin
Posts: 3055
Joined: Mon Dec 01, 2003 8:41 pm
Location: Vancouver, WA
Contact:

Re: Captcha in GOLD to Prevent Scripts

Post by Shopping Cart Admin » Thu Sep 14, 2017 1:34 pm

Hi Charles,

While scripts are easy to create to fill in forms, there isn't a benefit to creating one for twenty orders or twenty of any actions on the internet. It would be days of work. You'd need to add captcha to the user registration page to stop a script, where by default it's only on the returning login of an existing user. Since I don't believe it was a script the captcha wouldn't of accomplished anything in this case as they would of just typed it in. It's super easy to use proxi servers on the internet from a single location to have multiple ip addresses. You don't really sell gifts and I'm guessing your liable to get a pretty high degree of fraud, I'd consider only shipping to the billing address.
Thanks for your support

Shopping Cart Guru
AbleCommerce.com
Follow us on Facebook

User avatar
calvis
Rear Admiral (RADM)
Rear Admiral (RADM)
Posts: 710
Joined: Tue Jan 27, 2004 3:57 pm
Location: Redmond, WA

Re: Captcha in GOLD to Prevent Scripts

Post by calvis » Thu Oct 05, 2017 11:40 am

Some updates.

After careful review we determined it was not a script but rather a real human being. We were able to catch the orders, but it has started back up again with much more sophistication which has made detection very difficult. in the meantime our fraud rate has skyrocketed. We are looking to to ship orders only to the billing address, but I am not sure how to do that. In the older version of Able there was a setting to prevent shipping to a different address.

Where is the setting in GOLD?
Able Customer Since 1999 Currently Running on GOLD R12 SR1 and PCI Certified.

Post Reply