LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > LinuxQuestions.org > LQ Suggestions & Feedback
User Name
Password
LQ Suggestions & Feedback Do you have a suggestion for this site or an idea that will make the site better? This forum is for you.
PLEASE READ THIS FORUM - Information and status updates will also be posted here.

Notices


Reply
  Search this Thread
Old 01-06-2022, 12:50 PM   #16
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,607

Rep: Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106

The issue dugan was running into should be resolved (and nothing related to this would ever result in a perma-ban).

--jeremy
 
Old 01-20-2022, 03:05 AM   #17
cynwulf
Senior Member
 
Registered: Apr 2005
Posts: 2,727

Rep: Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367
I am seeing the attached whenever I try to edit a blog entry. As I am logged in, I'm not sure why I'm seeing this captcha? (disregard the error, that's not the issue)
Attached Thumbnails
Click image for larger version

Name:	screenshot.png
Views:	42
Size:	114.1 KB
ID:	38160  
 
Old 01-20-2022, 10:31 AM   #18
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,607

Rep: Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106
Based on a variety of factors this will happen for a very small number of requests (0.00002% over the last 24 hours).

--jeremy
 
Old 01-21-2022, 06:52 AM   #19
cynwulf
Senior Member
 
Registered: Apr 2005
Posts: 2,727

Rep: Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367
Ok, thanks... let me check it over for any "keywords"...
 
Old 01-24-2022, 05:45 AM   #20
cynwulf
Senior Member
 
Registered: Apr 2005
Posts: 2,727

Rep: Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367
Managed to edit without triggering the captcha - had to copy and paste and reconstruct in bits. I had to delete the word "like" from three places in double quotes and the word "having" without the double quotes from one particular sentence. If I added back "having" on a line on it's own in the same entry, the captcha is triggered again.

Is it not possible to turn that kind of invasive and annoying crap off for members who have been registered for a few years / made a certain number of posts?
 
Old 01-24-2022, 09:01 AM   #21
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,607

Rep: Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106Reputation: 4106
We skip the vast majority of checks for long time members, but a few happen before we have enough information to make that determination.

--jeremy
 
Old 02-04-2022, 04:31 AM   #22
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 22,041

Rep: Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348
Quote:
Originally Posted by jeremy View Post
We skip the vast majority of checks for long time members, but a few happen before we have enough information to make that determination.

--jeremy
I was blocked today too (an hour before). Does (can) it depend on the subforum? Or can it depend on the proxy server I have to use?
And I still blocked, but looks like I can post here.

Last edited by pan64; 02-04-2022 at 05:45 AM.
 
Old 02-12-2022, 07:13 AM   #23
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
https://www.linuxquestions.org/quest...0&d=1642669384
^ I have seen this today when replying to a post.
Strangely, it happened only on that 1 tab and only with that 1 reply. I could close & reopen the tab all I wanted, whenever I posted the reply I got that again.
While I had ~10 more LQ tabs open where that didn't happen, I could continue posting there.
I had to disable uBlock completely to even get to the captcha - apparently google-analytics needed its pound of flesh, even though the captcha itself isn't google's.
It makes me sad that this is considered normal nowadays - if I were using a service that does that sort of stuff, my trust in it would be lost.


This is what I posted:
Quote:
Originally Posted by ondoho View Post
deleted because that's what's triggering the captcha, please see here instead
Is there something that triggered the captcha in there? Looks normal to me.

Last edited by ondoho; 02-12-2022 at 07:17 AM.
 
Old 02-12-2022, 09:08 AM   #24
boughtonp
Senior Member
 
Registered: Feb 2007
Location: UK
Distribution: Debian
Posts: 3,628

Rep: Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557

This is ridiculous - the "security check" screen can be triggered with nothing more than "ls -l", when placed at the start of a line!

ls -x
ll -l
#ls -l

^ the first two are fine, but remove the hash from the third line and it requires a captcha.

 
2 members found this post helpful.
Old 02-14-2022, 03:10 AM   #25
cynwulf
Senior Member
 
Registered: Apr 2005
Posts: 2,727

Rep: Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367
It's a cloudflare issue. I don't think their switching to a new captcha provider is related.

It should not be triggering on words or commands like those regardless.
 
Old 02-16-2022, 12:14 PM   #26
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
i have to solve CAPTCHA's for 2 times per 10 site reload's.

i posted one site link at Security forum, after that came the CAPTCHA's.
 
Old 02-16-2022, 01:41 PM   #27
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 22,041

Rep: Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348Reputation: 7348
Quote:
Originally Posted by cynwulf View Post
It's a cloudflare issue. I don't think their switching to a new captcha provider is related.

It should not be triggering on words or commands like those regardless.
I don't know how can it be a cloudflare issue:
I could post here, but in the same time another subforum was read only, I could not post anything, because I (my IP) was blocked.
 
Old 02-16-2022, 03:26 PM   #28
cynwulf
Senior Member
 
Registered: Apr 2005
Posts: 2,727

Rep: Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367
Well the "one more step" captcha page in the screenshot I attached is a cloudflare thing. And the captcha is the one cloudflare uses (hcaptcha).
 
Old 02-24-2022, 04:34 AM   #29
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Yet another case:
https://www.linuxquestions.org/quest...1/#post6332790
 
Old 02-24-2022, 07:28 AM   #30
boughtonp
Senior Member
 
Registered: Feb 2007
Location: UK
Distribution: Debian
Posts: 3,628

Rep: Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557Reputation: 2557

The "security check" can be bypassed by using the full path, escaping/quoting, or ensuring there's a non-L option first - all of which will maintain the (intended) behaviour:
Code:
/bin/ls -l
\ls -l
"ls" -l
ls -1l
A few more quick tests show that the trigger is likely the regex pattern "\nls\s+-l" - i.e. a newline, then "ls" then any number of spaces/tabs/newlines (at least one) then "-l".

 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Load test, boundary test & stress test for USB EHCI/xHCI driver rama_toshiba Linux - Kernel 5 02-29-2012 02:43 PM
[SOLVED] Silencing the line "echo test > test/test.txt" in a shell script Arenlor Linux - General 2 06-18-2010 01:37 PM
FC4 Test 1 CD Test failes every DISC Jimbo99 Linux - Software 1 03-18-2005 03:16 PM
Core 2 Test 1 --> Core 2 Test 2 sausagejohnson Fedora 3 05-03-2004 11:43 AM

LinuxQuestions.org > Forums > LinuxQuestions.org > LQ Suggestions & Feedback

All times are GMT -5. The time now is 10:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration