Captcha in GOLD to Prevent Scripts
Posted: Tue Sep 12, 2017 2:26 pm
We recently underwent an attack in which 20 fraudulent orders (about 4,500 dollars worth) were placed in a span of 2 days. They used the correct billing address and shipped them to random people across the US. They were placing orders via a script because of the speed that the accounts were created and the orders placed. The attacks continued even after captcha was turned on. The attacks used different ip addresses and we found a pattern and were able to manually watch for that pattern thus preventing any more orders being shipped. The attack has since stopped, but we am working on security measures to prevent it if it does happen.
Does anyone know how to make captcha stronger? Seems like reCAPTCHA is the way to go but I am sure how much time and trouble it would be to implement that. This attack was very vicious for the fact they had all the billing information correct on the card and we got lucky to notice it after day 2.
Any other suggestions would be welcomed. I've had this happen before, but not to this scale and which was done by a rogue affiliate, but I am unable to find any motive other than to make us accumulate as many chargebacks as possible.
Does anyone know how to make captcha stronger? Seems like reCAPTCHA is the way to go but I am sure how much time and trouble it would be to implement that. This attack was very vicious for the fact they had all the billing information correct on the card and we got lucky to notice it after day 2.
Any other suggestions would be welcomed. I've had this happen before, but not to this scale and which was done by a rogue affiliate, but I am unable to find any motive other than to make us accumulate as many chargebacks as possible.