- Issue created by @amit.sharma.aust
- πͺπΈSpain tolivera
We have the same problem.
More than 3.000 submissions from a bot in 4 hours.
Antibot: 2.0.3
Drupal: 10.2.5
PHP: 8.2.20 - π·πΊRussia Psi-fact0r
I agree, few time ago my sites has multiple spam attack on webforms. This is sad. Try to find a solution...
- π¨π¦Canada vladt
I've created a patch which seems to resolve the issue for me - I've seen 0 spam submissions over the last 24 hours, down from 2/minute before applying it. This patch changes how the antibot_key is processed and passed to the client, so bots can't get to it without multiple processing steps.
I've seen a few bug reports where the fix has been to make the
antibot_key
scrambling more elaborate.I wonder: is it known why the existing
input[name="form_token"]
XSRF token doesn't accomplish the needed anti-forgery goal? Excuse me if this is a dumb question.- πΊπΈUnited States gallegosj
Is this issue still active? Our forms have been getting bombarded in the last 24 hours.