<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body>
<div style="padding-bottom: 10px; padding-top: 5px;">
<div style="padding:12px; border:1px solid #8D3970; background-color:#F7F9FA; color:#8D3970; font-size:14px; line-height:22px; font-family: Calibri, Arial, Helvetica, sans-serif;">
<strong>CAUTION:</strong> This e-mail originated outside the University of Southampton.
</div>
</div>
<div>
<p><font size="2" face="sans-serif">Hi John</font><br>
<br>
<font size="2" face="sans-serif">thanks a lot for your quick answer. I'll keep an eye on it. Q: Do you store the "</font><font size="3" face="serif">Privacy Agreement"
</font><font size="2" face="sans-serif">click? <br>
</font><br>
<font size="2" face="sans-serif">Of cause we analyse apaches logfiles and feed our badbot list, but unfortunately at the moment of sending the form it's to late ;-)</font><br>
<br>
<font size="2" face="sans-serif">Anybody else doing the same or something different?<br>
<br>
Cheers<br>
Jens</font><br>
<br>
<font size="2" face="sans-serif">-- <br>
Jens Witzel<br>
Zentrale Informatik<br>
Universität Zürich<br>
Stampfenbachstrasse 73<br>
CH-8006 Zürich<br>
<br>
mail: jens.witzel@uzh.ch<br>
phone: +41 44 63 56777<br>
<a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.zi.uzh.ch%2F&data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C030f4a40dee74eaf3a3308d976bd09f2%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637671376552035777%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000&sdata=XLQd996dEwQAFMaP6ncvZwKkyvRLLkI2s9GTcqTUxO4%3D&reserved=0" originalSrc="http://www.zi.uzh.ch/" shash="xc853t4+6Km4msUBxYlpM9YBD15hPk4BjxhvcKnLZBuBNjEniM7E+iLkbjZAfQ94sdXkoaiVbw3rNnKY8bfvZlsS9d9hzRC7mEwF9HNETrv9n3x+jXXwaTv2BiblJqYOzVmiEB2sd1AToYQ3hTJk1PtC1iMFZDpHqnaTt58GWqg=">http://www.zi.uzh.ch</a></font><br>
<br>
<img width="16" height="16" src="cid:1__=4EBB0DDCDFD8CD2A8f9e8a93df938690918c4EBB0DDCDFD8CD2A@lotus.uzh.ch" border="0" alt="Inactive hide details for "John Salter" ---13.09.2021 15:30:46---Hi Jens, We use the recaptcha stuff e.g. https://eprints.white"><font size="2" color="#424282" face="sans-serif">"John
Salter" ---13.09.2021 15:30:46---Hi Jens, We use the recaptcha stuff e.g. <a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Feprints.whiterose.ac.uk%2Fcgi%2Frequest_doc%3Fdocid%3D23483&data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C030f4a40dee74eaf3a3308d976bd09f2%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637671376552045730%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000&sdata=jkmt%2FQLyzByU43H0VK1tDQx9R23iLhpc4yBdOVPFXkw%3D&reserved=0" originalSrc="https://eprints.whiterose.ac.uk/cgi/request_doc?docid=23483" shash="tdeFSZsSp1t9ewHmh404gjFRK64Hf70FZcW1KhaCfHQoHhP0JeWkr7p0iXi6vdltEgQxrAfDHM3RJFNV+BCTlnnYVmzNXNoBphBWG/q9WrnlBVyoQb5n0vLrirb59j0eF84ohM8FwqhVn9UZjg69iBG655dZFA+HzvYcXl8TkrY=">
https://eprints.whiterose.ac.uk/cgi/request_doc?docid=23483</a></font><br>
<br>
<font size="1" color="#5F5F5F" face="sans-serif">Von: </font><font size="1" face="sans-serif">"John Salter" <J.Salter@leeds.ac.uk></font><br>
<font size="1" color="#5F5F5F" face="sans-serif">An: </font><font size="1" face="sans-serif">"eprints-tech@ecs.soton.ac.uk" <eprints-tech@ecs.soton.ac.uk>, "jens.witzel@uzh.ch" <jens.witzel@uzh.ch></font><br>
<font size="1" color="#5F5F5F" face="sans-serif">Datum: </font><font size="1" face="sans-serif">13.09.2021 15:30</font><br>
<font size="1" color="#5F5F5F" face="sans-serif">Betreff: </font><font size="1" face="sans-serif">Re: [EP-tech] Spam to submitter via "Copy request" form</font><br>
</p>
<hr width="100%" size="2" align="left" noshade="" style="color:#8091A5; ">
<br>
<br>
<br>
<font size="3" face="Calibri">Hi Jens,<br>
We use the recaptcha stuff e.g. </font><a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Feprints.whiterose.ac.uk%2Fcgi%2Frequest_doc%3Fdocid%3D2348396&data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C030f4a40dee74eaf3a3308d976bd09f2%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637671376552045730%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000&sdata=2OQWHZ6PVyr3LLoHhbOWrkik0lPcoDwkiB7r6314Mc4%3D&reserved=0" originalSrc="https://eprints.whiterose.ac.uk/cgi/request_doc?docid=2348396" shash="T5hkg5CWcjIh+dMHI6eniK14nKPNQKAGKEBX3YKCG1SiY4GWBndd+kR/OODDMB29MQ6oEPmIGZp+FFbYXmANon+5k2iCzxyaVBzGWly48XvzS1eKBHlir+QgGHFQy2B4KVWrD5B6QPdAUJFQgjayxYOHY2R0GVDq1t0XzDpMJig="><font size="3" color="#0000FF" face="Calibri"><u>https://eprints.whiterose.ac.uk/cgi/request_doc?docid=2348396</u></font></a><font size="3" face="Calibri"> .</font><br>
<font size="3" face="Calibri">The google.com version and recaptcha.net are essentially the same thing - but recaptcha.net isn't blocked in e.g. China, so we use that.</font><br>
<br>
<font size="3" face="Calibri">This does work well for us, and we also use recaptcha.net on our account creation and 'contact us' pages on our eTheses repository.</font><br>
<br>
<font size="3" face="Calibri">As the request details are stored in the EPrints database, you could do some analysis of these spam requests, and see if there are common themes - e.g. links in the request reason, or email addresses supplied?</font><br>
<font size="3" face="Calibri">You could also look at historic Apache logs and see if they all originate from the same place?</font><br>
<br>
<font size="3" face="Calibri">Cheers,</font><br>
<font size="3" face="Calibri">John</font><br>
<br>
<br>
<br>
<hr width="100%" size="2" align="left">
<br>
<font size="2" face="Calibri"><b>From:</b></font><font size="2" face="Calibri"> eprints-tech-bounces@ecs.soton.ac.uk <eprints-tech-bounces@ecs.soton.ac.uk> on behalf of jens.witzel--- via Eprints-tech <eprints-tech@ecs.soton.ac.uk></font><font size="2" face="Calibri"><b><br>
Sent:</b></font><font size="2" face="Calibri"> 13 September 2021 13:34</font><font size="2" face="Calibri"><b><br>
To:</b></font><font size="2" face="Calibri"> eprints-tech@ecs.soton.ac.uk <eprints-tech@ecs.soton.ac.uk></font><font size="2" face="Calibri"><b><br>
Subject:</b></font><font size="2" face="Calibri"> [EP-tech] Spam to submitter via "Copy request" form</font><font size="3" face="serif"> </font><br>
<font size="3" face="serif"> </font><br>
<font size="2" color="#8D3970" face="Calibri"><b>CAUTION:</b></font><font size="2" color="#8D3970" face="Calibri"> This e-mail originated outside the University of Southampton.
</font><br>
<font size="2" face="sans-serif">Hi out there</font><font size="3" face="serif"><br>
</font><font size="2" face="sans-serif"><br>
we have received some feedback regarding spam via the "Copy Request". Lots of emails gone to one submitter. Does anybody use any capture or something else in this direction?</font><font size="3" face="serif"><br>
</font><font size="2" face="sans-serif"><br>
First I found something in /usr/local/eprints/lib/workflows/request/default.xml (line 22ff.) - using googles capture
</font><a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.google.com%2Frecaptcha%2Fabout%2F&data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C030f4a40dee74eaf3a3308d976bd09f2%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637671376552055684%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000&sdata=%2B5KlEI8Zi4UaLPR10hBzZayTmaBkrohnyqOc1zIn9%2Bs%3D&reserved=0" originalSrc="https://www.google.com/recaptcha/about/" shash="KUbA7CTINniJhvZs2I9IrTIoOoAsBPrAi+7jHiQW9LTSSgaOPpXZyxpgvEt8yUNTssqKpCwPWRUaMgypY17T3bun3GUhEk0yjFq/tGxRow8pEs+LbWPIHOJaiFJ+BTTclLM/rsrN4d3XmpAW0sSP6NuxRgmSeD1KQz3u3ecf0aA="><font size="2" color="#0000FF" face="sans-serif"><u>https://www.google.com/recaptcha/about/</u></font></a><font size="2" face="sans-serif"> but
for sure we will have problems with data privacy.</font><font size="3" face="serif"><br>
</font><font size="2" face="sans-serif"><br>
Second i found some hints in the Eprints wiki: A captcha pseudo-field based on </font>
<a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Frecaptcha.net%2F&data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C030f4a40dee74eaf3a3308d976bd09f2%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637671376552055684%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000&sdata=E9TuQslZ9GitH3ObA1yk38HzRZd2ytVuXIpLgZJE9TI%3D&reserved=0" originalSrc="http://recaptcha.net/" shash="VfeVhalHiB8HahZjJ4p7GpKjpb5m632fvdD/4W8HLxo0BETZeGfAukGaroTM1cBqnyoY3wZKBAQHqRMua8DfibaJwl3ovjOe3H+Y9ZQVoty26rEHPBh99uAmRqK3fQXT6hBgvNTv9wXJ2vZwxmvlLyxSaUCVZDp579OVS33YfsE="><font size="2" color="#0000FF" face="sans-serif"><u>http://recaptcha.net/</u></font></a><font size="3" color="#0000FF" face="serif"><u><br>
</u></font><a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.eprints.org%2Fw%2FNew_Features_in_EPrints_3.2&data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C030f4a40dee74eaf3a3308d976bd09f2%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637671376552065644%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000&sdata=QVt6ZguXWIXJw60ssSoVlhJHo3sVsKB71sxxOYysg7c%3D&reserved=0" originalSrc="https://wiki.eprints.org/w/New_Features_in_EPrints_3.2" shash="AVvpmOgy0Mj/8UC/c0DEgqge15YEX/Qx6IG0IiI42CdxlHQQ6rylsOpFquP72g7tFRhyY+q9o+yd87X7nm+Lyc7DNaP9QjFBZqQAQP3hXWqv3q0r4IX25mY6Npm8MF4VLg5jQdxzAyAGEqt3v4ZE6Zws2jrZ0ZDRbDWVz0eSk1A="><font size="2" color="#0000FF" face="sans-serif"><u>https://wiki.eprints.org/w/New_Features_in_EPrints_3.2</u></font></a><font size="3" face="serif"><br>
</font><font size="2" face="sans-serif"><br>
Anything else? Cookies, Perl driven stuff? What do you guys use?</font><font size="3" face="serif"><br>
</font><font size="2" face="sans-serif"><br>
Every hint is welcome<br>
<br>
Jens</font><font size="3" face="serif"><br>
</font><font size="2" face="sans-serif"><br>
-- <br>
Jens Witzel<br>
Zentrale Informatik<br>
Universität Zürich<br>
Stampfenbachstrasse 73<br>
CH-8006 Zürich<br>
<br>
mail: jens.witzel@uzh.ch<br>
phone: +41 44 63 56777</font><font size="2" color="#0000FF" face="sans-serif"><u><br>
</u></font><a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.zi.uzh.ch%2F&data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C030f4a40dee74eaf3a3308d976bd09f2%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637671376552065644%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000&sdata=VYnWAQQZXwwVWbYbP3edZITLw3FeFqt0Jb9GlUp1kA0%3D&reserved=0" originalSrc="http://www.zi.uzh.ch/" shash="iSk9vwu6fSF9KrdHtI8FX2Z4I8tzQI4d62HcayTDKV/i3yHKi684zWTRy3ojxAg4UXoWsDJMFsnvD23fHZY6YENaFWhgyGhinoUYImqvaesZ5JGwJShq6VC8n5czCI3NXaedwy2InSVUjFb7guG5JMj/EksqJIE8G5PeXTLCukA="><font size="2" color="#0000FF" face="sans-serif"><u>http://www.zi.uzh.ch</u></font></a><br>
<br>
</div>
</body>
</html>