captcha bypassaed

every day we receive about a dozen of spam comments by Anonymous user on our documentation website, that is powered by Confluence.

Our website settings require captcha before submitting a comment as Anonymous. Is it possible that the spammer is exploiting a bug that bypasses the captcha?

This problem is very annoying because it forces us to frequently remove unwanted comments. Is there a way to add a moderator or some sort of approval workflow on comments that are edited by an anonymous user?

Thank you in advance

3 answers

1 vote

I'm afraid it's not a bug in Confluence, it's a general problem with the "Captcha" process. First, Captcha is easily bypassed by brute force - you can hire teams of people who will read captchas for you for fractions of a penny, and I know several sites that are constantly being hit by these. Secondly, last year, a security team demonstrated an AI that was capable of passing most schemes nearly as well as a human (but thousands of times faster).

So, your instinct to go for comment approval is probably the right one, but I'm not aware of any plugin that would do that for you. (Atlassian have said they won't do it inside Confluence - https://jira.atlassian.com/browse/CONF-13202)


We have just started going through the same thing. It started out slowly only getting 1 or 2 spam comments so we had our hosting company blacklist the IP addresses, but each new spam comment had a different IP address. It then exploded over night and we had like 30 new spam comments. It's very time consuming to go through and blacklist the IP address of every new comment since they are all different. We had to disable anonymous commenting for now but this is not a solution for us since we want legitamate comments from real users. I hope confluence comes up with some solution or replaces their captcha system for a better one.

Alex, I am totally with you.

IMHO, Atlassian should:
1- Implement comment moderation (it exist since a long time... why you don't have implemented?)
2- Implement a series of different captchas (based on words, images), or better again, let developers write plugins to use wathever captcha verifications available on the net (recaptcha, mollom, identipic...)

Suggest an answer

Log in or Sign up to answer
Atlassian Community Anniversary

Happy Anniversary, Atlassian Community!

This community is celebrating its one-year anniversary and Atlassian co-founder Mike Cannon-Brookes has all the feels.

Read more
Community showcase
Published 8 hours ago in Confluence

Think you know shares vs. @mentions in Confluence? Take this collab quiz.

To anyone who doubts that Atlassians are a little too obsessed with collaboration, and tools related thereto, let me describe a recent discussion we had (which took place on our internal Confluence, ...

85 views 2 4
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you