If you have this http://www.oxwall.org/store/item/239 Then just use cloudflare.
More details at
Regards,
Steve
Also john if you only have the one question it may not help. Once they discover the answer the bots pass the answer quickly to other bots. You need to have a min of 10 questions (20 is better) and stay way from the number questions as much as you can.
Use questions that only someone looking at the page can answer, such as ask them the color of a logo on the page or how many of something on the page or even spell something backwards.
I agree not to this extreme, but some have days where they do, such as phpbb for instance some days i see complaints of hundreds of spam signups overnight but its no different than any other script, if they find a hole they will exploit it. I have used phpbb for many years and i love it just as i do other scripts but it all comes down to that hole.
And by hole i dont mean just the script, could be server security lacking, could be someone else on the shared server did not protect themselves and they got into that account and into everyones account.
So yes every script needs to have this as an important security issue, but to say its the script is not right either, its everything combined. Every day it is becoming a more and more important issue even with congress.
As companies have to deal with the expendature in time and manpower to handle this, their complaints are heard and maybe not today or tomorrow, but one day it will be much more important and much more of a legal issue to combat the spammers. The more it affects a companies bottom line the more something will happen (its all about the money) and when this becomes such a pain that companies demand action, action will happen.
So its not just Oxwall or any CMS, it is the whole structure from setting up a server to running a web, to everything.
if they find a hole they will exploit it.
I dont get any on but every other site i run gets them.
http://www.phpcaptcha.org/documentation/customizing-securimage/#difficulty
/ow_libraries/securimage/secureimage.php
You could try making the captcha more difficult.
Nice post Paul... i dont know if it can be called hole, but i did hear at one time to take the check mark off of pages dashboard and pofile on the bottom of the page so that members cannot customize those pages, the same with groups settings in installed plugings.
I think that i more of a js issue than an actual hole. But again i say folks as have always said, you cant gripe about free, the door swings both ways ya know... And IMO this is much better than Elgg in many ways.