Mustlive is at it again. This time he has found 2 methods to bypass Peter’s Anti-Spam plugin.

These are the details as posted to BlogSecurity by Mustlive:

1. Constant values bypass method

Captcha has only 10 values (constant): from antiselect=1 to antiselect=10. So it’s easy for an automated program to find out what code is needed for current captcha parameter value.

2. MustLive CAPTCHA bypass method

For bypassing you need to use the same "securitycode" and "matchthis" values many times (for every post). This is my mine CAPTCHA bypass method. It’s very effective bypass method.

BlogSecurity is currently not aware of a fix. As an interim measure, we suggest you disable the plugin and use another comment anti-spam plugin such as Akismet.

Comment
Name:
Email:
Website:
Message: