University Web Developers

University Web Developers

Recently we have begun to experience an increase in spam generated from some of our web (HTML) forms. How do you deal with this? I'm concerned that some solutions may be inaccessible (I.e. CAPTCHA).

Views: 143

Reply to This

Replies to This Discussion

Try this out:

The trick is to add something to the filling out of the form that requires human level cognition, or give the bot a field that it will fill in that a human can't see.
I remember reading a few weeks ago that there is some body that says they can beat Yahoo's CAPTCHA...

Also there was the report about the Stripper software that was a creative way to beat CAPTCHA...

Personally we just delete the messages. It hasn't really gotten out of control, though. Maybe I'll get one a week.
I use a double pronged approach on some of my forms.

I have a field that must remain blank (or else it returns a message saying that we suspect you may be a machine). You have to be careful what you name those remain blank fields for a couple of reasons: 1) Google Toolbar autofill - it might stick a value in there unbeknownst to you and 2) It has to make sense to someone who might be seeing the field with a screen reader (maybe that's not an issue if you set the visibility off).

Secondarily I put a hidden field in my form that is populated when the onclick event fires on the submit button. I then check for that form value on the server side to make sure it's populated with the correct value. This should prevent bots from posting to my page. It basically requires the human interaction of clicking on the button to pass validation.

I'm not sure what the second option does to accessibility. I do not know how screen readers handle onclick events in JavaScript. I guess my assumption is that when you click enter on a button it fires that event so it should work just fine. Its also right in line with the kind of client-side validation that most people have on their forms anyways (like checking that required fields are filled in).

If you're interested in some code let me know.. I was going to blog about this, but have not gotten around to it.
Wouldn't the alternative of checking the referring script on the post page be better than your second technique since it doesn't rely on Javascript? Is there some reason why you wouldn't do it that way?
Checking the referrer is probably a better way. I wasn't really familiar with that approach until I started reading this thread. Thanks for suggesting it.
Oh, cool. Glad I said something.
If you are using at all, you could try the NoBot control that comes with their free ajax extender control toolkit. Here is a link to a demo:

If you are not using or some form of server side code, I'm not sure how you would stop spamming.
I have been using reCAPTCHA ( on some of our forms with success. I am sure it will only be a period of time before this is useless as well. It has an audio CAPTCHA built in for accessibility, and is fairly easy to implement.
Seconded. I have had great results on our blogs with reCAPTCHA. The only spam comments that have come through are obviously human. Before that they were getting hit so much I have to have registration on, which meant no one went through the effort required to comment.
I'm in the minority, but I refuse to put the onus on the user in any way. Instead, I do all the spam prevention on the backend. I use Akismet whenever possible, like this form.
The forms we were having problems with did not ask for any urls. So, I wrote a script that checks each item in the object. If any of them contain "http://" then the script stops and returns to the form page.

We haven't had any spam on those forms since.



Latest Activity

Sara Arnold commented on Lynn Zawie's group OmniUpdate
"Can’t afford the time and money to launch a comprehensive guided pathways model? Register for our FREE webcast to learn tricks for simulating a digital guided pathways experience."
41 minutes ago
Sara Arnold commented on Lynn Zawie's group OmniUpdate
"With college enrollment decreasing for the 8th year in a row, boosting your college or university marketing efforts is more important than ever. Here's how to get started."
23 hours ago
Christine Boehler posted a discussion

HighEdWeb 2020 Annual Conference

October 18-21, 2020 in Little Rock, Arkansas, USA     Join us for HighEdWeb 2020, the conference created by and for higher education professionals across all departments and divisions. Together we explore and find solutions for the unique issues facing digital teams at colleges and universities. With 100+ diverse sessions, an outstanding keynote presentation, intensive workshops, and engaging networking events,…See More
Christine Boehler posted a discussion

HighEdWeb 2020 Call for Proposals is Open!

The 2020 Annual Conference of the Higher Education Web Professionals Association (HighEdWeb) will travel to Little Rock, Arkansas, this October 18-21 — and the call for proposals is now open! As a digital professional in higher education, we know you have great ideas and experiences to share. From developers, marketers and programmers to managers, designers, writers and all team members in-between, HighEdWeb provides valuable professional development for all who want to explore the unique…See More
Feb 14
Christine Boehler shared Sara Clark's discussion on Facebook
Feb 14
Christine Boehler is now a member of University Web Developers
Feb 14
Brian Bell joined Kevin Daum's group
Feb 14
Brian Bell joined Mark Greenfield's group
Feb 14
Kenneth George is now a member of University Web Developers
Feb 13
John Sterni is now a member of University Web Developers
Feb 6
Sara Arnold commented on Lynn Zawie's group OmniUpdate
"The early-bird discount for OUTC20 ends today! Don't wait... register NOW and save $100!"
Jan 24
Linda Faciana commented on Lynn Zawie's group OmniUpdate
"Join our next webcast with Maxwell Rowe from @mackeycreativelab as he discusses ways to help students reach their educational goals using the guided pathways model on your website."
Jan 22
Sara Arnold commented on Lynn Zawie's group OmniUpdate
"Frustrated with student retention efforts and low graduation rates? Maybe it’s time to consider the guided pathways model for your institution's website. Check out our latest white paper for all the details!"
Jan 21
Sara Arnold commented on Lynn Zawie's group OmniUpdate
"OmniUpdate is excited to be in the running for a People’s Choice Stevie Award for Favorite Customer Service! If you’d like to show your support, cast your vote now! You can vote as many times as you’d like."
Jan 16
Linda Faciana commented on Lynn Zawie's group OmniUpdate
"Take a ½ hour out of your day to learn 4 important tips on keeping your website accessible! Join Ryan from Paskill Stapleton & Lord @PSandL as he shares the accessibility guidelines for your university website."
Jan 7
Sara Arnold commented on Lynn Zawie's group OmniUpdate
"Get up to speed on GDPR and how it affects your higher ed institution and student recruitment."
Jan 7
Sara Arnold commented on Lynn Zawie's group OmniUpdate
"Web governance should not be an afterthought; when it’s done right, it can actually enhance your workflow and make your job easier."
Nov 8, 2019
Sara Arnold commented on Lynn Zawie's group OmniUpdate
"Exciting news... OmniUpdate has merged with Destiny Solutions! Learn more on our blog."
Oct 30, 2019
Linda Faciana commented on Lynn Zawie's group OmniUpdate
"Switching to a new CMS? Join our next webcast with Briana Johnson from @OSUIT to learn how to convince decentralized web content authors to tolerate the switch, actively participate, and enjoy it!"
Oct 29, 2019
Sara Arnold commented on Lynn Zawie's group OmniUpdate
"Your website is the front door to your college or university. Your website design has to accommodate for the way that students interact with and use the information your institution provides."
Oct 24, 2019

UWEBD has been in existence for more than 10 years and is the very best email discussion list on the Internet, in any industry, on any topic


© 2020   Created by Mark Greenfield.   Powered by

Badges  |  Report an Issue  |  Terms of Service