Site asked me for captcha, why
akmerlow
Posts: 1,124
in The Commons
I got "One more step Please complete the security check to access" page when entering today, why?
I got "One more step Please complete the security check to access" page when entering today, why?
Comments
the captcha is likely to be from your Browser, unless you were filing a help ticket, in which case you weren't fully logged in
I got that one too. Tried a different computer, and got the same result. So it should not be browser issue. In addition, I could not login to Daz3d.com and cannot login to DIM. Have submitted help ticket but no response so far. I can now login to Dazed.com but still cannot login to DIM or download purchased content. Something very wrong must have happened.
The site issue should be fixed, on DIM please refer to https://www.daz3d.com/forums/discussion/322571/install-manager-problem#latest - we will post any updates we receive to that thread.
The CAPTCHA was because we have seen a massive increase in just bulk login attempts trying to use any of the massive password leak compilations and throwing it against our site to see if anything happens to match.
So while we started with simpler techniques but the attackers have botnets that have spread out far enough that we have had to add CAPTCHA's. Unfortunately I took it a little too far and the CAPTCHA was active on the download stuff as well (which doesn't work well with DIM's / Daz Connect's API handling), I have backed it off a bit to still protect against the bulk login attacks but still allow downloads after you have successfully logged in.
I was getting captcha on both PC (firefox) and tablet (safari) today, even thought if this may be cause of my country?? (you know, some sites completely block it sometimes as they believe only hackers live here.. yikes)
thanks for explanation
Sadly, it is country based so you will probably have to do the CAPTCHA thing more often, my apologies.
There are definitely more purchasers from your country than we have hackers attempting to hack our site, but what these CAPTCHA's are aiming for is the large number of malware-infested machines being controlled by botnets, those zombie-machines definitely outnumber purchasers in a number of countries.
I am researching a better solution, but so far it appears the implementation time will be long, but hopefully in the future we can get the site experience back to normal for you.
I see, thank you for detailed answer.
I still got directed to cloudfare captcha when trying to login to Daz website and after having completed the user name and the password, was told that my PC has malware. I scaned my pc using antivirus program and windows malicious removal tool and my pc is clean. This is getting more and more exasperating. I can only log in to the site using VPN, although it seemed that I can login to DIM and download purchased product through DIM successfully without activating the VPN. Please resolve this issue.
Thanks and regards
I've been directed here for DAZ_Rawb's explanation of the Captcha.
However, I'm one of the select few who get automatically kicked out of the website at random intervals (usually every day or two) with the "Please wait while we sign you out" problem that's been around since at least November 2015 (support requests 204662 and 234416, still unresolved but deemed 'Solved' by DAZ)
So I'm faced with this irritating 'Captcha' more or less every day, and logging into DAZ is beginning to feel like this...
...the drunk test from "The Man With Two Brains"
Still - that thought keeps me smiling !
I usually get it when i switch from my laptop to desktop. Both use firefox, IP should be the same. Idk why.
I bet that would be due to cookies. It is often (not always!) possible to make a server believe two machines are identical, so you could switch without having to relog, but you'd have to first remove all cookies related to the Daz3D site from one machine, and then replace them with all those cookies from the other machine. The cookie you'll especially want to replace is the one that holds your session ID.
You might have to regularly repeat this process, as I noticed the Daz3D site logs me out once or twice a week anyway, even though I visit every day and always from the same computer. So it's probably more hassle than it's worth.
There might be some more trickery involved in the process nowadays, it's been ages since I developed websites, so a trick like this might be no longer possible on server/browser combinations with more recent, more advanced, and more secure software. (This was actually a trick hackers used a few years ago to log into other peoples' accounts: they simply hacked their own cookies for the site, to make the server think they were somebody else)
Indeed, I get that "Please wait while we sign you out" problem quite often, and I only access Daz from one IP/machine.. I figure its somne sort pof perverse AI as it usually on;y happens when I want to post something (happened just now1), but not when just lurking around... :)
Regarding cookies and the auto-logout ... (that post was November last year)
Could well be - Articial Idiocy is very popular nowadays !