Author

Topic: 0 (Read 486 times)

sr. member
Activity: 854
Merit: 277
liife threw a tempest at you? be a coconut !
0
June 03, 2019, 05:15:30 AM
#24
This is just the most awesome feature added ! Thanks again.
hero member
Activity: 2268
Merit: 579
DGbet.fun - Crypto Sportsbook
June 01, 2019, 04:39:05 PM
#22
They can...? What's the issue?

The first time you log in with the captcha, grab your bypass captcha code and can use that link to log in (to your account) anywhere without having to fill the captcha ever again.
Yeah get that, im talking about quoted msg from posi. and i try to open then link profided. i just though since no capthca there i can login, turn out its show as invalid code when im using my username and password.
I provided the xxxxxxxxxxxxx one as an example how the code will look like but you're to go to https://bitcointalk.org/captcha_code.php to log in after log in open a new tab to the same link which will see your own unique code which we can then bookmark for future or save somewhere safe for future use.
legendary
Activity: 2758
Merit: 6830
June 01, 2019, 02:18:33 PM
#21
Yeah get that, im talking about quoted msg from posi. and i try to open then link profided. i just though since no capthca there i can login, turn out its show as invalid code when im using my username and password.
If the code "xxxxxxxxxxxxxccxcxxxx" in his example was someone's bypass-captcha code, you would be able to log in with (and only) that account w/o a captcha.
sr. member
Activity: 645
Merit: 266
June 01, 2019, 02:16:03 PM
#20
They can...? What's the issue?

The first time you log in with the captcha, grab your bypass captcha code and can use that link to log in (to your account) anywhere without having to fill the captcha ever again.
Yeah get that, im talking about quoted msg from posi. and i try to open then link profided. i just though since no capthca there i can login, turn out its show as invalid code when im using my username and password.
legendary
Activity: 2758
Merit: 6830
June 01, 2019, 02:12:58 PM
#19
well, look like everyone can login without captcha then. i try to open this at incognito and i dont see any captcha.
They can...? What's the issue?

The first time you log in with the captcha, grab your bypass captcha code and can use that link to log in (to your account) anywhere without having to fill the captcha ever again.

This only works if you're logging with your account's bypass-captcha code.
sr. member
Activity: 645
Merit: 266
June 01, 2019, 02:08:57 PM
#18
Suchmoon understand the vulnerability I'm talking about and the same thing still applied after the code was created. Go to the link provided by OP this is what you'll get
Quote
You can bypass the CAPTCHA on the login page by bookmarking this link and using it to login:
https://bitcointalk.org/index.php?action=login;ccode=xxxxxxxxxxxxxccxcxxxx

This link is unique to your account. You cannot use it with other accounts. It only works on the login page.

If someone else gains access to your unique captcha-bypass link, then they could try to brute-force your password. In that case, you should reset it:
well, look like everyone can login without captcha then. i try to open this at incognito and i dont see any captcha.
edit: oh fuck silly me, just try to login and it says invalid code
hero member
Activity: 2268
Merit: 579
DGbet.fun - Crypto Sportsbook
June 01, 2019, 01:39:27 PM
#17
but you need to be aware of the vulnerability involve if the code leak out.

What vulnerability?

Someone could bruteforce your password.

As they could before the code was created.   The code does not decrease security in any way. 
Suchmoon understand the vulnerability I'm talking about and the same thing still applied after the code was created. Go to the link provided by OP this is what you'll get
Quote
You can bypass the CAPTCHA on the login page by bookmarking this link and using it to login:
https://bitcointalk.org/index.php?action=login;ccode=xxxxxxxxxxxxxccxcxxxx

This link is unique to your account. You cannot use it with other accounts. It only works on the login page.

If someone else gains access to your unique captcha-bypass link, then they could try to brute-force your password. In that case, you should reset it:
legendary
Activity: 3654
Merit: 8909
https://bpip.org
May 31, 2019, 11:07:06 PM
#16
Am I stupid or something? What’s stopping them from using their own code to brute force an account?

Codes are unique to each account. If you use your code on a different account you get "Invalid ccode" even if you enter the correct password.
jr. member
Activity: 67
Merit: 3
May 31, 2019, 10:27:15 PM
#15
As they could before the code was created.   The code does not decrease security in any way.  
But there is a captcha on every attempt. Imagine bruteforcing an password and having to fill Google’s reCAPTCHA every single time. Impossible.

If someone finds your code, they can try thousands of combinations in seconds.
Am I stupid or something? What’s stopping them from using their own code to brute force an account?
legendary
Activity: 2758
Merit: 6830
May 31, 2019, 07:04:48 PM
#14
I checked the stay logged in option during login to avoid re-logging in and completing captcha everytime
is there also a security risk having my account always stay logged in? I think it's been over a year+
If someone manages to log in to your wallet, they will be able to stay logged in forever (until you log in with a specific expire time, which will log out everyone).

Also, if someone gets your browser cookies, they can spoof your session and stay logged.

That’s all I’ve noticed.
hero member
Activity: 1232
Merit: 738
Mixing reinvented for your privacy | chipmixer.com
May 31, 2019, 06:56:57 PM
#13
If someone finds your code, they can try thousands of combinations in seconds.
I checked the stay logged in option during login to avoid re-logging in and completing captcha everytime
is there also a security risk having my account always stay logged in? I think it's been over a year+
legendary
Activity: 2758
Merit: 6830
May 31, 2019, 06:16:23 PM
#12
Without a comprised database, wouldn't the forum firewall limit you to one attempt per second on average?
Maybe... but in that case, wouldn’t you be able to use multiples IPs to make multiple consecutive tries.
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
May 31, 2019, 06:14:47 PM
#11
As they could before the code was created.   The code does not decrease security in any way. 
But there is a captcha on every attempt. Imagine bruteforcing an password and having to fill Google’s reCAPTCHA every single time. Impossible.

If someone finds your code, they can try thousands of combinations in seconds.

Without a comprised database, wouldn't the forum firewall limit you to one attempt per second on average?
legendary
Activity: 3472
Merit: 3217
Happy New year 🤗
May 31, 2019, 05:27:44 PM
#10
but you need to be aware of the vulnerability involve if the code leak out.

What vulnerability?

Someone could bruteforce your password.

As they could before the code was created.   The code does not decrease security in any way. 

As TryNinja said, it allows to do it much cheaper and quicker. However, with a strong password the chance of that happening is still much lower than the chance of buses and chimneys making me go insane, so I don't hesitate to use it.

Don't forget the reset button as it helps to generate a new bypass link and disable/remove the old one.

So if you don't want your account to be compromised use the reset button whenever you log out and it's a good practice to keep your account safe.
legendary
Activity: 3654
Merit: 8909
https://bpip.org
May 31, 2019, 04:32:52 PM
#9
but you need to be aware of the vulnerability involve if the code leak out.

What vulnerability?

Someone could bruteforce your password.

As they could before the code was created.   The code does not decrease security in any way. 

As TryNinja said, it allows to do it much cheaper and quicker. However, with a strong password the chance of that happening is still much lower than the chance of buses and chimneys making me go insane, so I don't hesitate to use it.
legendary
Activity: 2758
Merit: 6830
May 31, 2019, 03:45:19 PM
#8
As they could before the code was created.   The code does not decrease security in any way. 
But there is a captcha on every attempt. Imagine bruteforcing an password and having to fill Google’s reCAPTCHA every single time. Impossible.

If someone finds your code, they can try thousands of combinations in seconds.
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
May 31, 2019, 03:42:33 PM
#7
but you need to be aware of the vulnerability involve if the code leak out.

What vulnerability?

Someone could bruteforce your password.

As they could before the code was created.   The code does not decrease security in any way. 
legendary
Activity: 3654
Merit: 8909
https://bpip.org
May 31, 2019, 03:34:48 PM
#6
but you need to be aware of the vulnerability involve if the code leak out.

What vulnerability?

Someone could bruteforce your password.
copper member
Activity: 2940
Merit: 4101
Top Crypto Casino
May 31, 2019, 03:07:02 PM
#5
He should have installed a breathalyzer for alcohol level check instead to install a Captcha Cheesy
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
May 31, 2019, 03:04:38 PM
#4
but you need to be aware of the vulnerability involve if the code leak out.

What vulnerability?
hero member
Activity: 2268
Merit: 579
DGbet.fun - Crypto Sportsbook
May 31, 2019, 03:03:35 PM
#3
The Captcha bypass code have been in existence for more than 8months if I cab remember correctly and like you said it super great but you need to be aware of the vulnerability involve if the code leak out.
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
May 31, 2019, 03:01:10 PM
#2
I mean it's super great system. Thank you for making it !!!
https://bitcointalk.org/captcha_code.php
Since it's activated? And maybe the only one who didn't knew that this necessary option existed... Smiley.

My BPIP scraper has been using it since it was introduced.   A very nice feature indeed.  Smiley
sr. member
Activity: 854
Merit: 277
liife threw a tempest at you? be a coconut !
May 31, 2019, 02:56:22 PM
#1
0
Jump to: